Many companies don’t have a disaster recovery plan often there is a desire for a DRP. The level of effort andor cost required to create DRP can cause this project to have a low priority relative to other more immediate projects. A DRP is viewed as “nice to have” or “just insurance that will not be used “, and not as a critical business component. Introduction cont…That is, until there is a failure that causes a significant outage or loss of data (often at a significant cost to the business). It is my opinion that every company could benefit from both a disaster recovery plan and a business continuity plan (BCP)Investing in a DRP and BCP is just as an important for most business in my opinion. Introduction cont…In this presentation I will describe many areas to address during the creation of a DRP. It is not all-inclusive, but is intended to provide insight into the overall process.
So, now that you have decided to go forward with this type of project, what next? Where do you start? What needs to be addressed? How will you know that the plan really works? Do you need to find external expertise for this type of project? If so, exactly what type of expertise is required?Introduction cont…A DRP first need to be created, then tested, and redefines and finally implemented and tested on a periodic basis. Most plans will experience some type of failure during their first execution so it is also important to retest the plan on a periodic basis ideally rotating staff. Using experienced consultants to help develop the process and then later audit and refine the process is usually idea sound investment. Introduction cont…They will often identify gaps or ambiguities that might have been missed with the systems, process, and procedures in use. Find a team that will build plans based on how your business and systems work, and not try to make your business fit into a predefined template. Every business is different, and every system being recovered has its own nuances. (capture the knowledge is critical to success)Introduction cont…When using a DR Facilities provider there are many issues to consider.
There may be availability issues if the company has many customers in a single geographic area. There may be phone and network bandwidth issues if more than one customer declares a disaster at a single time. Introduction cont…Does the company have multiple hot sites that you can use? Where are they located?How long would it take to assemble a recovery team at each site? How often can you test the plan? And how long will you have to test the plan? What is their DR plan? How committed are they to your success? Where do you start? The first step is to create a DR team and this includes an: Executive sponsor. DR coordinator. Team leaders (there will be several groups and possibly subgroups). Team members. Where do you start? cont…This people should be designated as either primary or backup for position, with every position having more than one person assigned this to minimize people as a single point of failure. The goal is to have the expertise to help develop the various recovery procedures, and is committed to success of the overall effort. Where do you start? The next step is to define business goals. The goal should address items such as: What functional areas need to be recovered? What length of time is acceptable for recovery? What amount of data loss is acceptable? This often involves prioritization and a cost-benefit analysis to determine the worth of recovery (i. e. something that may be premature at this phase of the project). Understand the business goals and objectivesTo find out what that really entails you must know: What are the critical systems? What are the key processes and applications? What are the dependencies on other systems?Understand the business goals and objectives cont…
Then documents these processes.
Because there is interaction with dependencies on other systems and user interface, and the sensitivity of the data. Once the systems have been identified, attempt to quantify their impact relative to the overall business goals.
Everyone involve with this effort (including upper management within a company) needs to have a single vision of what success look like, without this you risk wasting time and money on a plan that may be viewed as a failure.
These people may not be part of the DR team, but they are important. (For example who has the authority to declare a disaster?) This list should be maintained both by name and by role; it should be validated and updated frequently.
The overall goal of this step is to mitigate unnecessary risk. The scope of this effort includes people, software, equipment, and infrastructure. It is important to look at the “big picture”, which includes: Impact of the failure. Probability of failure. Estimated incidents (failures). Annualized loss expectancy. Cost of mitigation. Preparing to develop the DRPIt is important to have a document management system in place to: track versions of plans. work in progress. work that is scheduled but not started. This information needs to be backed-up and saved in a format that does not rely on the underlying systems being recovered. For example the banks, like HSBC bank they use secure e-rooms and external vendors for some of their projects, and they recommend that the plans be archived on portable media with copies kept people and various “safe” locations.
The DRP should address 3 main functional areas
Recovery. Restoring / sustaining business operation. Transferring Data back to Production Machines.
In the event of problems that data may help the team make a root cause determination regarding the problem so that it can be corrected. If everything goes right it provides the necessary documentation to support an external validation effort of the DRP exercise. If every thing worked is to know what every thing is. And then to be able to demonstrate that the necessary tasks were completed successfully! Testing and refining the planA common problem that we see is the plans are developed, but they are never tested, or are tested once and forgotten. A plan that is not continuously refined and validated is almost worthless. In order to maximize the chance for success in the event of a real disaster it is essential that the DRP be executed on a regular basis. Specific recovery procedure can generally be tested in-house on a more frequent basis. SummaryThe DRP is a living document that is refined over several iterations and update over time. No matter how good it is it probably will fail during the first execution. The key is to continue to improve the plan so that will work if and when it is ever needed.
This essay has been submitted by a student. This is not an example of the work written by our professional essay writers. You can order our professional work here.