Critical Analysis 2

profileJohn_matt
case_study_1.docx

Critical Analysis needed 1

Introduction

            Disaster recovery (DR) can be defined as a plan that “provides guidance and procedures for actions that must be taken when an incident is severe enough to compromise the organization’s operations” (University of Maryland University College, 2013, p. 7). In other words, disaster recovery plans are designed to restore a company back to operations in the event that a disastrous incident occurs. Furthermore, IT service continuity seeks to ensure that major system failures are restored in an efficient amount of time, and ultimately attempts to increase the company’s resiliency to major incidents that can result in network outages (European Union Agency for Network and Information Security, 2016). This being said, one of the ultimate goals of these plans is to reduce the amount of damage experienced from incidents like fires, floods, and cybersecurity attacks by restoring the company back to operations as soon as possible (Bailey, Brandley, & Kaplan, 2013).

            There are a number of reasons why cybersecurity should be addressed in the company’s DR and IT service continuity strategies and plans. For instance, by having the security team involved, they can perform risk assessments and business impact analysis (BIA) to ensure critical systems are identified and ultimately restored first in the event that there is a loss in availability (Department of Homeland Security, n.d. a). Secondly, involving the security team can ensure that the total time critical systems are unavailable is minimized for the smallest amount of time possible (Bailey et al., 2013). The security team can ensure that processes are in place that guarantee the availability of the data, such as through the implementation of back-up policies and procedures (Velliguette, 2004). When critical systems are left unavailable for extended periods of time, stakeholders will lose confidence in the company, and ultimately lead to increased losses for the company. Another reason to include security in DR planning is that they can ensure than any service level agreements (SLA) between the company and third-party providers contain sections that describe the security controls that will be used to protect the confidentiality, integrity, and availability of company data should the client company need to access the information or services (Klaus & Walch, 2012). Furthermore, hackers are increasingly becoming more successful in their attacks on company’s information systems, and as a result, it is apparent that providing perimeter security alone is not getting the job done. By implementing disaster recovery and IT service continuity plans, the company can ensure that its cybersecurity goals are met by protecting the integrity and availability of data despite a successful breach by a cybercriminal. 

CISO Roles and Responsibilities

Planning

When planning for the integration of cybersecurity into a DR or IT service continuity plan, the CISO and his or her staff has a number of roles, responsibilities, and best practices for which they are responsible. For instance, it is the responsibility of the CISO’s office to conduct a risk assessment that identifies current security vulnerabilities within the company and ultimately identifies the risk associated with each identified asset (Department of Homeland Security, n.d. a). Secondly, the CISO must conduct a business impact analysis (BIA) that ultimately classifies systems in the order in which they need to be restored (Balaouras, 2009). Classifying these systems will ensure that critical systems are brought back to operations in the required amount of time that was identified in the BIA.  Once the risk assessment and the BIA are complete, the CISO must then work with other chief executives to identify each system’s recovery time objective (RTO) and recover point objective (RPO), which are essential for identifying which systems to restore first in the event of a disaster (Bahan, 2003).

Implementation

In addition, the CISO also has a number of roles, responsibilities, and best practices that he or she must follow when implementing a disaster recovery plan. First, the CISO must identify companies that offer services that can be used to recover critical systems in the event of a disaster (Department of Homeland Security, n.d. b). For instance, the CISO could identify companies that provide data-backup or cloud backup services, alternate facilities such as hot sites that can be used to restore critical systems, or products such as a backup power supply or redundant servers. Another item that the CISO must address is to ensure that SLA’s with the identified third-party providers address security concerns such as ensuring that all backed-up data is secured through encryption and other mechanisms or that firewalls are in place that protect the company’s data from unauthorized access (Klaus & Walch, 2012). The ultimate goal of the CISO when implementing security in a DR or IT service continuity plan is to ensure that all existing security policies, procedures, and mechanisms are enforced and working correctly throughout a recovery event (Savage, 2010).

Execution

            Furthermore, the CISO has additional roles, responsibilities, and best practices that must be followed during the execution phase of a DR or IT service continuity plan. When disaster or security event first occurs, the CISO should activate the call tree, which essentially notifies the pre-selected personnel, such as the disaster recovery team or recovery personnel that an event has occurred (Cisco, n.d.). In addition, the CISO should also ensure that the recovery and reconstitution phases are working as planned by monitoring the progress of each team (Swanson, Bowen, Phillips, Gallup, & Lynes, 2010). Furthermore, by analyzing how each team performed and the effectiveness of the current program, the CISO should provide recommendations for ways in which to improve the overall DR program (Department of Homeland Security, n.d. c).

Conclusions

            Disaster recovery and IT service continuity planning are designed to ensure the availability and integrity of critical information and information systems in the event of a disaster or security incident. Although the development of a DR plan may take an enormous amount of time and resources, the implementation of one is essential if the company wants to protect its data and systems from being unrecoverable, and ultimately leading to the company being unable to perform its functions. Through cooperation and participation from the CISO and other chief executives, the development, maintenance, and implementation of a disaster recovery plan will be much more efficient and effective in restoring critical systems after disaster occurs.

References

Bahan, C. (2003). The disaster recovery plan. Retrieved from https://www.sans.org/reading-room/whitepapers/recovery/disaster-recovery-plan-1164

Bailey, T., Brandley, J., & Kaplan, J. (2013, December). How good is your cyberincident-response plan? Retrieved from http://www.mckinsey.com/business-

functions/business-technology/our-insights/how-good-is-your-cyberincident-response-plan

Balaouras, S. (2009, December 16). Four best practices for IT availability and service continuity management. Retrieved from

http://www.cio.com/article/2422019/data-center/four-best-practices-for-it-availability-and-service-continuity-management.html

Cisco. (n.d.). Disaster recovery: best practices. Retrieved from http://www.cisco.com/en/US/technologies/collateral/tk869/tk769/white_paper_c11-

453495.html

Department of Homeland Security. (n.d. a). Planning. Retrieved from https://www.ready.gov/planning

Department of Homeland Security. (n.d. b). IT disaster recovery plan. Retrieved from https://www.ready.gov/business/implementation/IT

Department of Homeland Security. (n.d. c). Program improvement. Retrieved from https://www.ready.gov/business/program

European Union Agency for Network and Information Security. (2016). IT service continuity plan. Retrieved from https://www.enisa.europa.eu/activities/risk-

management/current-risk/bcm-resilience/bc-plan/it-service-continuity-plan

Klaus, J. & Walch, D. (2012). A strategic framework for IT disaster recovery assessments. Retrieved from http://www.isaca.org/Journal/archives/2012/Volume-

6/Documents/jol12v6-A-Strategic.pdf

Savage, M. (2010, December). Disaster recovery and contingency planning security considerations. Retrieved from

http://searchsecurity.techtarget.com/magazineContent/Disaster-recovery-and-contingency-planning-security-considerations

Swanson, M., Bowen, P., Phillips, A. W., Gallup, D., & Lynes, D. (2010, May). NIST special publication 800-34 Rev. 1. Contingency planning guide for federal

information systems. Retrieved from http://csrc.nist.gov/publications/nistpubs/800-34-rev1/sp800-34-rev1_errata-Nov11-2010.pdf

University of Maryland University College. (2013). Module 2: organizations and their security programs. Retrieved from

https://learn.umuc.edu/d2l/le/content/127200/viewContent/5854656/View

Velliquette, D. (2004, November 15). Computer security considerations in disaster recovery planning. Retrieved from https://www.sans.org/reading-

room/whitepapers/recovery/computer-security-considerations-disaster-recovery-planning-1512