What is a Disaster Recovery Plan? It is a stand-alone document that “contains all procedures and detailed equipment recovery scripts, written to a level sufficient to achieve a successful recovery by technically competent IT personnel and outside contractors.” (Tipton, Nozaki, 2007). The potential for disasters, natural or malicious is a constant threat to business processes that can not be put on hold. It is clear that any disruption in services can negatively impact each of our departments. As such, it is critical that the Disaster Recovery (DR) team members have a clear understanding of the cybersecurity functions and responsibilities of the Office of the Chief Information Security Officer. The Office contains various functional areas, however this review will discuss the best practices as they apply to implementing a Disaster Recovery / IT Service Continuity plan. “Every year, thousands of businesses are affected by floods, fires, tornadoes, terrorist attacks, vandalism, and other disastrous events. The companies that survive these trauma are the ones that thought ahead, planned for the worst, estimated the possible damages that could occur, and put the necessary controls in place to protect themselves.” (Harris, 2013). Only through excellent collaboration and focused effort can the products of a disaster recovery team provide a competitive edge post disaster to capture a greater market share (Brunetto, Harris, 2001).
CISO Staff Functions Overview
The Chief Information Security Officer (CISO) and staff are responsible for several areas which area critical to a successful DR/BCP. These areas are Planning & Forecasting, Coordinating, Controlling, Organizing, and Directing the many moving parts in the organization that contribute to the mechanics of an effective cybersecurity program. In the Planning & Forecasting stage the CISO staff will assist team members in developing a DR/BCP planning statement which provides guidance and authority to support the project. This stage also includes conducting the business impact analysis, developing recovery strategies, contingency plans, and test and review cycles for the DR/BCP. Forecasting specifically identifies possible changes to the DR/BCP due to the dynamic nature of the external security threat surface.
In the Coordinating stage, the staff will work to ensure existing security controls and processes are carried over to the DR/BCP. Early coordination promotes early buy-in, which can address challenges across each department, streamlining processes, and leveraging scalable technology to reduce cost. The Controlling stage measures the effectiveness of the program using metrics identified in the Planning stage. An example would be scheduled audits to ensure access controls have been implemented at a Continuity of Operations site in accordance with the company's cybersecurity strategy. Finally Directing, is the CSO’s responsibility which gives security direction the the team ensuring unified security efforts, in line with the organization's strategic goals.
Best Practices
As every company is different, each of their Disaster Recovery/Business Continuity Plans will be different. However, there are common practices among successful plans. A “DR program with strong governance tends to be resilient” (Klaus, Walch, 2012). Information Systems Audit and Control Association (ISACA) describes three tiers of a DR program. The first and single most important practice is, incorporating IT Governance Frameworks such as CobiT (Control Objectives for Information and related Technology), published by ITGI, and ITIL (Information Organization for Standardization Technology Infrastructure Library) published by the UK government, and ISO/IEC 27002 (International Standards Organization) into your DR/BCP. The second and third are IT “Management” and “Technical Operations of Disaster Recovery Infrastructure” (Klaus, Walch, 2012). Although both CobiT and ITIL provide best practice guidance, CobiT is used to provide a higher level governance framework while ITIL’s framework defines service management aspects. Kozina (2009). In addition to these management and process frameworks, ISO 27002 provides an access control security framework of best practices. It focuses on improving information security through areas such as asset, operations, compliance and organizational security management.
When integrating these frameworks into a DR/BCP the first step is “Tailoring”. This is a dynamic process that begins during the “Planning & forecasting” and is where each organization applies specific framework standards and practices based on their individual requirements. Although the CISO is the single point of developing a DR/BCP, there are many interdepartmental dependencies that can make implementations costly if not organized properly. As such, the second best practice is “Prioritizing” which is a critical process through each of the CISO functions, especially in the “Coordinating” stage. The C suite involvement and buy-in is imperative at this point. The organization needs an effective and realistic plan based on resources and skill levels, otherwise the plan risks becoming shelf ware.
Third is an effective information campaign that aims at creating a common language supporting CobiT, ITIL, and ISO 27002. “Regardless of methodology, the goal of IT Governance is to improve an organization's competitive advantage, optimize operation and mitigate tasks.” (Orakzai, 2014).
References
Brunetto, G., & Harris, N. L. (2001). Disaster recovery. How will your company survive?. Strategic Finance, 82(9), 57-61.
Harris, Shon. (2013). Cissp all-in-one exam guide, sixth edition. [Books24x7 version] Available from http://common.books24x7.com.ezproxy.umuc.edu/toc.aspx?bookid=50527.
Klaus, J., & Walch, D. (2012). JOnline: A Strategic Framework for IT Disaster Recovery Assessments . ISACA JournalOnline, 6(12), 1-1.
Kozina, M. (2009). COBIT - ITIL mapping for business process continuity management. Proceedings of the 20th Central European Conference on Information and Intelligent Systems, 113-119.
Orakzai, T. (2014). COBIT, ITIL and ISO 27002 Alignment for information security governance in modern organisations. SSRN Electronic Journal SSRN Journal.
Tipton, H., & Nozaki, M. (2007). Contingency planning best practices and program maturity. In Information Security Management Handbook (6th ed., Vol. 1, p. 431). Hoboken, NJ: CRC Press.
University of Maryland University College. (2015). Module 02: Organizations and their security programs. In Cybersecurity in Business and Industry: Summer 2015 [Class lecture slide]. Retrieved from https://learn.umuc.edu/