Business Continuity Plan Template
Appendix I-3
BUSINESS CONTINUITY PLAN
Version < Date submitted > Submitted to:
Submitted By:
< Facility name> name> < Facility address> address> < Facility address> address> < Facility address>
Business Continuity Plan Appendix 1-3
Table of Contents 1 #
Executie Executie Summa!y""""" Summa!y"""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""""" """""""""""""""1 """"""1 Int!oducti Int!oduction"""""" on""""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """"""""""""""1 """""""1 #"1 Pu!pose""""" Pu!pose"""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """""""""""""""""""""" """"""""""""""""""""""3 """""""3 #"# Scope""""""""" Scope"""""""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""""" """"""""""""""""""""""""""""3 """""""""""""""""""3 #"3 Plan In$o!mation"""" In$o!mation""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""""""3 """"""""""3 3 Business Business Continuity Continuity Plan %e!ie&""""" %e!ie&"""""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""""""""" """""""""""""""""""""""' """""""""""' 3"1 Applicable Applicable P!oisions P!oisions and (i!ecties (i!ecties"""""" """"""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """"""""""""""""""""""""" """"""""""""""""""""""""""""' """"""""""' 3"# %b)ecties"" %b)ecties"""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """"""""""""""""""""""' """""""""""""""' 3"3 %!*ani+ati %!*ani+ation"""""" on"""""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""""" """"""""""""""""""""""""""", """"""""""""""""""", 3"' Contin*ency Contin*ency Pases""""""" Pases"""""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """"""""""""""". """""""". 3"'"1 3"'"1 /espon /esponse se Pase"" Pase""""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """"""" """"""" """""" """"""" """"""" """""""" """""". ". 3"'"# 3"'"# /esump /esumptio tion n Pase"" Pase"""""" """"""" """""" """"""" """"""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """"""" """"""" """""" """"""" """"""" """""" """"""" """""""" """""""". """". 3"'"3 3"'"3 /ecoe! /ecoe!y y Pase"" Pase""""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """"""" """"""" """""" """"""" """""""" """"""""" """"". . 3"'"' 3"'"' /esto! /esto!ati ation on Pase"" Pase""""" """""" """""" """"""" """"""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """""" """""""0 """"0 3", Assumptions Assumptions"""""" """"""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""""""""""""""""0 """"""""""""""""""""0 3" C!itical C!itical Success Success 2acto!s 2acto!s and Issues""""" Issues"""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """"""""""""""""""""" """"""""""""""""""""0 """"""0 3" 4ission 4ission C!itical C!itical Systems5 Systems5Appli Applicatio cations5Se! ns5Se!ices"" ices""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """"""""""""""16 """""""16 3". T!eats""""" T!eats"""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""""" """""""""""""""""""""16 """"""""""""16 3"."1 3"."1 P!obab P!obable le T!eat T!eats"" s"""""" """"""" """""" """"""" """"""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """"""" """""""" """"""""" """"""""" """"""""" """""""""" """"""""""1 """""11 1 ' System System (esc!ipti (esc!iption""""" on"""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""""""""""1# """"""""""""""1# '"1 Pysical Pysical Eni!onment""""" Eni!onment"""""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """"""""""""1# """""1# '"# Tecnica Tecnicall Eni!onment Eni!onment"""""" """"""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """"""""""""" """"""""""""" """"""""""""""""1# """""""""1# , Plan""""""""" Plan"""""""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """""""""""""""""" """""""""""""""""""""""""""1# """"""""""""""""1# ,"1 Plan 4ana*ement"" 4ana*ement"""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""""""" """""""""""""""""""""1# """"""""""1# ,"1"1 ,"1"1 Busine Business ss Contin Continuit uity y Plan Plannin nin* * 7o! 7o!8*! 8*!oups oups"""" """"""" """""" """"""" """"""" """""" """"""" """""""" """"""""" """""""""" """""""""" """""""""1# """"1# ,"1"# ,"1"# Busine Business ss Conti Continui nuity ty Plan Plan Coo!di Coo!dinat nato!" o!"""" """""" """"""" """"""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """""""1 """"1# # ,"1"3 ,"1"3 System System Contin Contin*enc *ency y Coo!di Coo!dinat nato!s o!s"""" """"""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """""" """""""" """""""""" """""""""" """""""""" """"""""13 """13 ,"1"' ,"1"' Incide Incident nt 9oti$i 9oti$icat cation ion"""" """"""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """"""" """"""" """""" """"""" """"""" """""" """"""" """""""" """"""""" """"""""""1 """""13 3 ,"1", ,"1", Inte!n Inte!nal al Pe!sonne Pe!sonnell 9oti$ica 9oti$icatio tion""" n""""""" """"""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """"""" """"""" """"""" """"""""" """"""""13 """13 ,"1" ,"1" Exte!n Exte!nal al Contact Contact 9oti$ 9oti$ica icati tion"" on""""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """"""" """"""" """""" """"""" """"""" """"""" """"""""" """""""""" """"""""""1 """""13 3 ,"1" ,"1" 4edia 4edia /eleas /eleases" es"""" """""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """"""" """"""" """""" """"""" """"""" """""" """"""" """""""" """"""""" """""""""" """""""""" """"""""1' """1' ,"1". ,"1". Alte!n Alte!nate ate Site Site s;""" s;"""""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """"""" """"""""" """""""""" """""""""1' """"1' ,"# Teams""" Teams""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""1' """"""1' ,"#"1 ,"#"1 (ama*e (ama*e Asses Assessm sment ent Team"" eam"""""" """"""" """""" """"""" """"""" """""" """"""" """"""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """"""" """""""1' """1' ,"#"# ,"#"# %pe!at %pe!ation ionss Team"" eam""""" """"""" """"""" """""" """"""" """"""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """"""" """"""" """""" """"""" """"""""" """""""""" """"""""""1 """""1, , ,"#"3 ,"#"3 Commun Communica icati tions ons Team" Team"""" """""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """"""" """"""" """""" """"""" """"""" """""" """""""" """""""""" """""""""" """""""""" """""""""1, """"1, ,"#"' ,"#"' (ata (ata Ent!y Ent!y and and Cont!o Cont!oll Tea Team"" m""""" """"""" """"""" """""" """"""" """"""" """"""" """"""" """""" """"""" """"""" """""" """"""" """""""" """"""""" """""""""" """""""""" """"""""1, """1, ,"#", ,"#", %$$-Si %$$-Site te Sto!a*e Sto!a*e Team" Team""""" """"""" """""" """"""" """"""" """""" """"""" """"""" """"""" """"""" """""" """"""" """"""" """""" """"""" """""""" """"""""" """""""""" """""""""" """""""""" """"""""1, """1, ,"#" ,"#" Admini Administ! st!ati atie e 4ana*em 4ana*ement ent Tea Team"" m"""""" """"""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """"""" """""""" """"""""" """"""1, "1, ,"#" ,"#" P!ocu! P!ocu!eme ement nt Team"" eam"""""" """"""" """""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """"""" """"""" """""" """"""" """"""" """""" """"""" """""""" """"""""" """""""""" """""""""" """"""""1, """1, ,"#". ,"#". Con$i* Con$i*u!a u!atio tion n 4ana 4ana*em *ement ent Team" Team"""" """""" """"""" """"""" """""" """"""" """"""" """"""" """"""" """""" """"""" """"""""" """""""""" """""""""" """""""""" """"""""1 """1 ,"#"0 ,"#"0 2acili 2acilitie tiess Team" Team"""" """""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """""" """"""" """""""" """"""""" """""""""1 """"1 ,"#"16 System System So$t&a!e So$t&a!e Team"""" Team""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""""""""""""""""" """""""""""""""""""""""""""1 """"""1 ,"#"11 Inte!nal Inte!nal Audit Audit Team"""" Team""""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""""""""""""""" """""""""""""""""""""""""1 """"""1
Date
e!sion 1"6
Pa*e i
Business Continuity Plan
,"#"1# =se! Assist Assistance ance Team"""" Team""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """"""""""""""""""""""""" """"""""""""""""""""""1 """"1 ,"3 (ata Communicati Communications""""" ons""""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """"""""""""" """"""""""""" """"""""""""""""" """""""""""""""""""""""""1 """""""""""""""1 ,"' Bac8ups""""""" Bac8ups""""""""""""" """"""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""""""""""""" """""""""""""""""""""""""1 """"""""1 ,"'"1 ,"'"1 ital ital /eco!d /eco!ds5( s5(ocu ocumen mentat tation ion"""" """"""" """""" """"""" """"""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """""" """"""" """"""" """"""" """"""" """""""" """""""1 ""1 ,", %$$ice %$$ice Euipmen Euipment? t? 2u!nitu! 2u!nitu!ee and Supplies"""" Supplies""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """"""""""""" """""""""""""""""""""10 """""""""""""""10 ," /ecommended /ecommended Tes Testin* tin* P!ocedu!es P!ocedu!es""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""10 """10 /ecommended /ecommended St!ate*ies" St!ate*ies"""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """""""""#6 """#6 "1 C!itical C!itical Issues" Issues"""""""" """"""""""""" """"""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""""" """"""""""""""""""""""""""""#6 """""""""""""""""""#6 6 1 1 Po!er"""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""#6 61 61" " Di#e Di#errsi$ si$icat icatiion o$ Conn Connec ectti#ity #ity""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""#6 """"""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""#6 6 1 3 %$$site Bac&up Stora'e""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""#1 Te!ms Te!ms And (e$initions (e$initions"""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""""#1 """"""""#1 . Appendices""" Appendices""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""""" """""""""""""""""""""""""""""" """""""""""""""""""""""""""'1 """""'1 APPE9(I@ A B=SI9ESS C%9TI9=IT PA9 PA9 C%9TACT C%9TACT I92%/4ATI I92%/4ATI%9"" %9"" """ """'# "" "'# APPE9(I@ B E4E/DE9C P/%CE(=/ES""""""""""""""""""""""""""""""""""""""""""""""""""" """"""""""'' APPE9(I@ C TEA4 STA22I9D STA22I9D A9( TASI9DS"""""""""""""""""""""""""""" TASI9DS"""""""""""""""""""""""""""" """"""""""""""""" """"""""" """""""""""""" """"""' ' APPE9(I@ ( ATE/9ATE SITE P/%CE(=/ES"""""""""""""""""""""""""""""""""""""""""""""""""""""'. APPE9(I@ E (%C=4E9TAT (%C=4E9TATI%9 IST""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""" "",6 APPE9(I@ 2 S%2T7A/E S%2T7A/E I9E9T%/""""""""""""""""""""""""""""""""""""""""""""""""" I9E9T%/""""""""""""""""""""""""""""""""""""""""""""""""" """""""""""""""" """""""" """""""""",# "",# APPE9(I@ D FA/(7A/E I9E9T%/"""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""",' APPE9(I@ F C%44=9ICATI%9S /EG=I/E4E9TS"""""""""""""""""""""""""""""""""""""""""""", APPE9(I@ APPE9(I@ I - E9(%/ C%9TACT C%9TACT ISTS"""""""" ISTS""""""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""""""" """"""""""""" """"""""""""" """""""""""""" """""""""",. """,. APPE9(I@ APPE9(I@ H - E@TE/9A E@TE/9A S=PP%/T S=PP%/T AD/EE4 AD/EE4E9TS"""" E9TS""""""""""" """""""""""""""""" """"""""""""""""""""""""""""""""" """""""""""""""""""""""6 "6 APPE9(I@ - (ATA (ATA CE9TE/5C%4P=TE/ /%%4 E4E/DE9C P/%CE(=/ES A9( /EG=I/E4E9TS"""""""""""""""""""""""""""""""""""""""""""""# APPE9(I@ - PA9 4AI9TE9A9CE P/%CE(=/ES""""""""""""""""""""""""""""""""""""""""""" P/%CE(=/ES"""""""""""""""""""""""""""""""""""""""""""""' ""' APPE9(I@ 4 -C%9TI9DE9C %D""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""
Date
e!sion 1"6
Pa*e ii
Business Continuity Plan
E!ECUTIVE SUMMA"Y
7!itten upon completion o$ document" sections"
#
Contains int!oducto!y desc!iptions $!om all
INT"O$UCTION
()is document contains t)e Business Continuity Plan $or t)e *t is intended to ser#e as t)e centrali+ed repository $or t)e in$ormation, tas&s, and procedures t)at !ould e necessary to $acilitate t)e mana'ement.s decisionma&in' process and its timely response to any disrupti#e or extended interruption o$ t)e departments normal usiness operations and ser#ices ()is is especially important i$ t)e cause o$ t)e interruption is suc) t)at a prompt resumption o$ operations cannot e accomplis)ed y employin' only normal daily operatin' procedures *n terms o$ personnel and $inancial resources, t)e in$ormation tas&s and procedures detailed in t)is plan represent t)e mana'ement.s demonstrated commitment to response, resumption, reco#ery, and restoration plannin' ()ere$ore, it is essential t)at t)e in$ormation and action plans in t)is plan remain #iale and e maintained in a state o$ currency in order to ensure t)e accuracy o$ its contents (o t)at end, t)is introduction is intended to introduce and $amiliari+e its readers !it) t)e or'ani+ation o$ t)e plan *t is incument upon e#ery indi#idual !)o is in receipt o$ t)e Business Continuity Plan, or any parts t)ereo$, or !)o )as a role and/or responsiility $or any in$ormation or materials contained in t)e document, to ensure t)at ade0uate and su$$icient attention and resources are committed to t)e maintenance and security o$ t)e document and its contents Since t)e in$ormation contained in t)is document descries mana'ement.s plannin' assumptions and oecti#es, t)e plan s)ould e considered a sensiti#e document All o$ t)e in$ormation and material contents o$ t)is document s)ould e laeled, 2imited %$$icial use4 ()e mana'ement )as reco'ni+ed t)e potential $inancial and operational losses associated !it) ser#ice interruptions and t)e importance o$ maintainin' #iale emer'ency response, resumption, reco#ery and restoration strate'ies ()e Business Continuity Plan is intended to pro#ide a $rame!or& $or constructin' plans to ensure t)e sa$ety o$ employees and t)e resumption o$ time-sensiti#e operations and ser#ices in t)e e#ent o$ an emer'ency 5$ire, po!er or communications lac&out, tornado, )urricane, $lood, eart)0ua&e, ci#il disturance, etc Alt)ou') t)e Business Continuity Plan pro#ides 'uidance and documentation upon !)ic) to ase emer'ency response, resumption, and reco#ery plannin' e$$orts, it is not intended as a sustitute $or in$ormed decision-ma&in' Date
e!sion 1"6
Pa*e 1
Business Continuity Plan
Business process mana'ers and accountale executi#es must identi$y ser#ices $or !)ic) disruption !ill result in si'ni$icant $inancial and/or operational losses Plans s)ould include detailed responsiilities and speci$ic tas&s $or emer'ency response acti#ities and usiness resumption operations ased upon pre-de$ined time $rames Constructin' a plan and presentin' it to senior mana'ement may satis$y t)e immediate need o$ )a#in' a documented plan 7o!e#er, t)is is not enou') i$ t)e 'oal is to )a#e a #iale response, resumption, reco#ery, and restoration capaility *n order to estalis) t)at capaility, plans, and t)e acti#ities associated !it) t)eir maintenance 5ie trainin', re#ision, and exercisin' must ecome an inte'ral part o$ <9ame> operations A Business Continuity Plan is not a one-time commitment and is not a proect !it) an estalis)ed start and end date *nstead, a Business Continuity Plan is an on-'oin', $unded usiness acti#ity ud'eted to pro#ide resources re0uired to8 •
Per$orm acti#ities re0uired to construct plans
•
(rain and retrain employees
•
De#elop and re#ise policies and standards as t)e department c)an'es
•
9xercise strate'ies, procedures, team and resources re0uirements
•
:e-exercise unattained exercise oecti#es
•
:eport on-'oin' continuity plannin' to senior mana'ement
•
:esearc) processes and tec)nolo'ies to impro#e resumption and reco#ery e$$iciency
•
Per$orm plan maintenance acti#ities
De#elopin' a Business Continuity Plan t)at encompasses acti#ities re0uired to maintain a #iale continuity capaility ensures t)at a consistent plannin' met)odolo'y is applied to all o$ t)e Business Continuity Plan elements necessary to create a #iale, repeatale and #eri$iale continuity capaility include8 •
*mplementin' accurate and continuous #ital records, data ac&up, and o$$-site stora'e
•
*mplementin' capailities $or rapid s!itc)in' o$ #oice and data communication circuits to alternate site5s
•
Pro#idin' alternate sites $or usiness operations
•
Constructin' a contin'ency or'ani+ation
Date
e!sion 1"6
Pa*e #
Business Continuity Plan
•
*mplementin' contin'ency strate'ies
#% PU"POSE
()e purpose o$ t)is plan is to enale t)e sustained execution o$ mission critical processes and in$ormation tec)nolo'y systems $or in t)e e#ent o$ an extraordinary e#ent t)at causes t)ese systems to $ail minimum production re0uirements ()e Business Continuity Plan !ill assess t)e needs and re0uirements so t)at may e prepared to respond to t)e e#ent in order to e$$iciently re'ain operation o$ t)e systems t)at are made inoperale $rom t)e e#ent #%# SCOPE
*nsert in$ormation on t)e speci$ic systems, locations, Facility di#isions, tec)nical oundaries and p)ysical oundaries o$ t)e Business Continuity Plan #%& PLAN INFO"MATION
()e Business Continuity Plan contains in$ormation in t!o parts related to t)e $re0uency o$ updates re0uired ()e $irst part contains t)e plan.s static information 5ie t)e in$ormation t)at !ill remain constant and !ill not e suect to $re0uent re#isions ()e second part contains t)e plan.s dynamic information 5ie t)e in$ormation t)at must e maintained re'ularly to ensure t)at t)e plan remains #iale and in a constant state o$ readiness ()is dynamic in$ormation is #ie!ed as t)e action plan ()e action plan s)ould e considered a li#in' document and !ill al!ays re0uire continuin' re#ie! and modi$ication in order to &eep up !it) t)e c)an 'in' <$acility/system> en#ironment ()e static in$ormation part o$ t)e Business Continuity Plan is contained in a ;S-ord $ile and printed as part o$ t)is document ()is static in$ormation s)ould e read and understood y all employees, users, and administrators o$ t)e , or at least y t)ose indi#iduals !)o are in#ol#ed in any p)ase o$ usiness response, resumption, reco#ery, or restoration ()e dynamic in$ormation resides in t)e dataase o$ t)e and !ill e printed as output $or t)e appendixes o$ t)is document By usin' t)e dataase, dynamic in$ormation t)at is #ital to t)e sur#i#al o$ t)e !ill e easy to mana'e and update ()e !e-enaled dataase is desi'ned $or maintenance o$ personnel contact lists, emer'ency procedures, and tec)nical components *t is already in operation $or <=ame> a'encies For ease o$ use and re$erence, t)e static and dynamic in$ormation is maintained separately )ile it is necessary to e $amiliar !it) t)e static in$ormation durin' resumption, it s)ould not e necessary to read t)at in$ormation at t)e time o$ t)e e#ent ()e completed action plan o$ dynamic in$ormation pro#ides all o$ t)e necessary lists, tas&s, and reports used $or response, resumption, or reco#ery Date
e!sion 1"6
Pa*e 3
Business Continuity Plan
&
BUSINESS CONTINUITY PLAN OVE"VIE'
&% APPLICABLE P"OVISIONS AN$ $I"ECTIVES
()e de#elopment o$ t)e Business Continuity Plan is re0uired y executi#e decisions and to meet re'ulatory mandates ()e mana'ement must maintain an in$ormation assurance in$rastructure t)at !ill ensure t)at its in$ormation resources maintain a#ailaility, con$identiality, inte'rity, and nonrepudiation o$ its data Furt)ermore, mana'ement must ensure t)eir strate'ic in$ormation resources mana'ement capailities ()ere$ore, t)e Business Continuity Plan is ein' de#eloped in accordance !it) t)e $ollo!in' executi#e decisions, re'ulatory mandates, pro#isions, and directi#es8 •
•
%$$ice o$ ;ana'ement and Bud'et Circular A13?, :e#ised 5(ransmittal ;emorandum =o @, Appendix ***, Security o$ Federal Automated *n$ormation :esources, =o#emer "??? Computer Security Act o$ 1, Pulic a! 1??-"3, Eanuary 1
•
Presidential Decision Directi#e 63, Critical *n$rastructure Protection, ;ay 1
•
Presidential Decision Directi#e 6, 9ndurin' Constitutional o#ernment and Continuity o$ o#ernment %perations, %ctoer 1
•
9xecuti#e %rder 1"66, Assi'nment o$ 9mer'ency Preparedness :esponsiilities, =o#emer 1
•
Federal *n$ormation Processin' Standards 5F*PS Pulication , uidelines $or ADP Business Continuity Plannin', ;arc) 11
•
D%E %rder "6@?"D, *n$ormation (ec)nolo'y Security, Euly 1", "??1
()e Business Continuity Plan is desi'ned to e in accordance !it) t)e strate'ic intent o$ t)e<=ame> and t)e <=ame>.s $unctional and operational mission &%# OB(ECTIVES
()e is dependent on t)e #ariety o$ systems classi$ied as eneral Support Systems 5SSs, !)ic) pro#ide mission critical $unctions o$ connecti#ity, *nternet access, and email, or ;aor Applications 5;As !)ic) are speci$ic so$t!are pro'rams !ritten to produce output to $ul$ill t)e ser#ice to its customers or enale t)e to operate *n addition t)ese systems pro#ide t)e means to o$$er electronic 'o#ernment 5e-'o#ernment Alt)ou') many t)reats and #ulnerailities can e Date
e!sion 1"6
Pa*e '
Business Continuity Plan
miti'ated, some o$ t)e t)reats cannot e pre#ented ()ere$ore, it is important t)at de#elop Business Continuity Plans and disaster reco#ery plans to ensure t)e uninterrupted existence o$ its usiness $unctions and continued ser#ice to t)e<=ame> and t)e pulic ()e primary $ocus o$ a Business Continuity Plan re#ol#es around t)e protection o$ t)e t!o most important assets o$ any or'ani+ation8 personnel and data All $acets o$ a Business Continuity Plan s)ould address t)e protection and sa$ety o$ personnel and t)e protection and reco#ery o$ data ()e primary oecti#e o$ t)is plan is to estalis) policies and procedures to e used $or in$ormation systems in t)e e#ent o$ a contin'ency to protect and ensure $unctionin' o$ t)ose assets ()is includes estalis)in' an operational capaility to process pre-desi'nated critical applications, reco#erin' data $rom o$$-site ac&up data sets, and restorin' t)e a$$ected systems to normal operational status ()e plan see&s to accomplis) t)e $ollo!in' additional oecti#es8 •
;inimi+e t)e numer o$ decisions !)ic) must e made durin' a contin'ency
•
*denti$y t)e resources needed to execute t)e actions de$ined y t)is plan
•
*denti$y actions to e underta&en y pre-desi'nated teams
•
*denti$y critical data in conunction !it) customers t)at !ill e reco#ered durin' t)e 7ot Site p)ase o$ reco#ery operations
•
De$ine t)e process $or testin' and maintainin' t)is plan and trainin' $or contin'ency teams
&%& O")ANI*ATION
*n t)e e#ent o$ a disaster or ot)er circumstances !)ic) rin' aout t)e need $or contin'ency operations, t)e normal or'ani+ation o$ t)e !ill s)i$t into t)at o$ t)e contin'ency or'ani+ation ()e $ocus o$ t)e !ill s)i$t $rom t)e current structure and $unction o$ 2usiness as usual4 to t)e structure and $unction o$ an !or&in' to!ards t)e resumption o$ time-sensiti#e usiness ope rations *n t)is plan, t)e contin'ency or'ani+ation !ill operate t)rou') p)ases o$ response, resumption, reco#ery, and restoration 9ac) p)ase in#ol#es exercisin' procedures o$ t)e Business Continuity Plan and t)e teams executin' t)ose plans ()e teams associated !it) t)e plan represent $unctions o$ a department or support $unctions de#eloped to respond, resume, reco#er, or restore operations or $acilities o$ t)e and its a$$ected systems 9ac) o$ t)e teams is comprised o$ indi#iduals !it) speci$ic responsiilities or tas&s, !)ic) must e completed to $ully execute t)e plan Primary and alternate team leaders, !)o are responsile to t)e plan o!ner, lead eac) team
Date
e!sion 1"6
Pa*e ,
Business Continuity Plan
9ac) team ecomes a su-unit o$ t)e contin'ency or'ani+ation Coordination teams may e sin'ular $or t)e , !)ereas tec)nical teams !ill li&ely e system speci$ic Fi'ure 3-1, Business Continuity Plannin' %r'ani+ational C)art, s)o!s t)e ase or'ani+ational structure ()e teams are structured to pro#ide dedicated, $ocused support in t)e areas o$ t)eir particular experience and expertise $or speci$ic response, resumption and reco#ery tas&s, responsiilities, and oecti#es A )i') de'ree o$ interaction amon' all teams !ill e re0uired to execute t)e corporate plan 9ac) team.s e#entual 'oal is t)e resumption/reco#ery and t)e return to stale and normal usiness operations and tec)nolo'y en#ironments Status and pro'ress updates !ill e reported y eac) team leader to t)e plan o!ner Close coordination must e maintained !it) and <=ame> mana'ement and eac) o$ t)e teams t)rou')out t)e resumption and reco#ery operations ()e contin'ency or'ani+ation.s primary duties are8 •
(o protect employees and in$ormation assets until normal usiness operations are resumed
•
(o ensure t)at a #iale capaility exists to respond to an incident
•
(o mana'e all response, resumption, reco#ery, and restoration acti#ities
•
(o support and communicate !it) employees, system administrators, security o$$icers, and mana'ers
•
(o accomplis) rapid and e$$icient resumption o$ time-sensiti#e usiness operations, tec)nolo'y, and $unctional support areas
•
(o ensure re'ulatory re0uirements are satis$ied
•
(o exercise resumption and reco#ery expenditure decisions
•
(o streamline t)e reportin' o$ resumption and reco#ery pro'ress et!een t)e teams and mana'ement o$ eac) system
Date
e!sion 1"6
Pa*e
Business Continuity Plan
Business Continuity Plan Coo!dinato!
(ama*e Assessment Team
Administ!atie 4ana*ement Team
System Contin*ency Coo!dinato!
2acilities Team
%pe!ations Team
Communications Team
Con$i*u!ation 4ana*ement Team
(ata Ent!y Cont!ol Team
System So$t&a!e Team
=se! Assistance Team
Inte!nal Audit Team
%$$-Site Sto!a *e Team
P!oc u!em ent Tea m
Fi+,re &- B,siness Contin,it. Plannin+ Or+aniational C0art
Date
e!sion 1"6
Pa*e
Business Continuity Plan
&%1 CONTIN)ENCY P2ASES
Te < Facility/System> Business Continuity Plan Coo!dinato!? in con)unction &it < Facility/System> and <=ame> mana'ement !ill determine !)ic) (eams/(eam memers are responsile $or eac) $unction durin' eac) p)ase As tas&in' is assi'ned, additional responsiilities, teams, and tas& lists need to e created to address speci$ic $unctions durin' a speci$ic p)ase &%1%
"ESPONSE P2ASE •
(o estalis) an immediate and controlled presence at t)e incident site
•
(o conduct a preliminary assessment o$ incident impact, &no!n inuries, extent o$ dama'e, and disruption to t)e ser#ices and usiness operations
•
•
&%1%#
(o pro#ide mana'ement !it) t)e $acts necessary to ma&e in$ormed decisions re'ardin' suse0uent resumption and reco#ery acti#ity"
"ESUMPTION P2ASE
&%1%&
•
(o estalis) and or'ani+e a mana'ement control center and )ead0uarters $or t)e resumption operations
•
(o moili+e and acti#ate t)e support teams necessary to $acilitate and support t)e resumption process
•
(o noti$y and appraise time-sensiti#e usiness operation resumption team leaders o$ t)e situation
•
(o alert employees, #endors and ot)er internal and external indi#iduals and or'ani+ations
"ECOVE"Y P2ASE •
Date
(o $ind and disseminate in$ormation on i$ or !)en access to t)e $acility !ill e allo!ed
(o prepare and implement procedures necessary to $acilitate and support t)e reco#ery o$ time-sensiti#e usiness operations
e!sion 1"6
Pa*e .
Business Continuity Plan
•
•
&%1%1
(o coordinate !it) )i')er )ead0uarters to discern responsiilities t)at !ill $all upon Business %perations :eco#ery (eams and (ec)nolo'y :eco#ery (eams (o coordinate !it) employees, #endors, and ot)er internal and external indi#iduals and or'ani+ations
"ESTO"ATION P2ASE •
(o prepare procedures necessary to $acilitate t)e relocation and mi'ration o$ usiness operations to t)e ne! or repaired $acility
•
*mplement procedures necessary to moili+e operations, support and tec)nolo'y department relocation or mi'ration
•
;ana'e t)e relocation/mi'ration e$$ort as !ell as per$orm employee, #endor, and customer noti$ication e$ore, durin', and a$ter relocation or mi'ration
&%3 ASSUMPTIONS
*nclude any assumptions t)at t)e Business Continuity Plan !ill )in'e on ()is could ran'e $rom asolutely necessary conditions to )elp$ul in$ormation in support o$ t)e Business Continuity Plan p)ases •
(elecommunications connecti#ity and $ier optic calin' !ill e intact and pro#ided y eneral Ser#ices Administration 5SA
•
()at all necessary ;emorandums o$ A'reement 5;%As and ;emorandums o$ Gnderstandin' 5;%Gs )a#e een executed
&%4 C"ITICAL SUCCESS FACTO"S AN$ ISSUES
()is section addresses t)e $actors and issues t)at speci$ically apply to t)e <2acility5System> Business Continuity Plan proect t)at )a#e een identi$ied to e critical to t)e success$ul implementation o$ t)e Business Continuity Plan ()ese $actors are as $ollo!s8 •
Asolute commitment y senior mana'ement to Business Continuity Plannin' and Disaster :eco#ery
•
Bud'etary commitment to Disaster :eco#ery
•
;odi$ications and impro#ements to t)e current sc)edulin' procedures $or t)e retention and transportation o$ ac& up $iles to t)e o$$site stora'e $acility
Date
e!sion 1"6
Pa*e 0
Business Continuity Plan
•
•
De#elopment and execution o$ t)e necessary ;emorandums o$ A'reement 5;%As, ;emorandums o$ Gnderstandin' 5;%Gs, and Ser#ice e#el A'reements 5SAs Completion o$ re0uirement assessment $or, and t)en completion o$ t)e procurement o$ a diesel 'enerated alternate po!er source
&%5 MISSION C"ITICAL SYSTEMS/APPLICATIONS/SE"VICES
()e $ollo!in' essential mission critical systems/applications/ser#ices t)at must e reco#ered at t)e time o$ disaster in t)e $ollo!in' order due to critical interdependencies8
)as identi$ied t)e applications and ser#ices s)o!n in Fi'ure 1" as mission critical8 SYSTEMS AC"ONYM 9xc)an'e ;ail *nternet Connecti#ity
SYSTEM NAME ;icroso$t 9-mail system GG=et
Fi+,re &-# Mission Criti6al S.ste7s
&%8 T2"EATS
)en de#elopin' strate'ies $or a Business Continuity Plan, it is )elp$ul to consider t)e entire ran'e o$ proale and possile t)reats t)at present a ris& to an or'ani+ation From t)at ran'e o$ t)reats, li&ely scenarios can e de#eloped and appropriate strate'ies applied A disaster reco#ery plan s)ould e desi'ned to e $lexile enou') to respond to extended usiness interruptions, as !ell as maor disasters ()e est !ay to ac)ie#e t)is 'oal is to desi'n a Business Continuity Plan t)at could e used to address a maor disaster, ut is di#ided into sections t)at can e used to address extended usiness interruptions )ile eac) o$ t)e identi$ied t)reats could result in a disaster y itsel$, in a maor disaster se#eral o$ t)e t)reats mi')t e present concurrently or occur se0uentially, dependin' on t)e circumstances
Date
e!sion 1"6
Pa*e 16
Business Continuity Plan
As a result, it is ad#isale to de#elop se#eral le#els o$ strate'ies t)at can e applied as needed For example, a locali+ed $ire in t)e computin' center may render some o$ t)at space unusale An appropriate strate'y $or t)at e#ent may e temporary relocation o$ personnel to anot)er o$$ice !it)in <=ame> )ead0uarters or in ot)er suitale local o$$ice space in anot)er o$$ice uildin' or )otel An e#ent t)at re0uired temporary e#acuation o$ t)e computer center, suc) as a truc& accident in t)e tunnel and a c)emical spill t)at may re0uire se#eral days to resol#e, may necessitate s!itc)o#er capailities and possile re'ional mirrored redundancy capailities t)at !ould e transparent to t)e users An e#ent o$ 'reater ma'nitude, suc) as an explosion, may render t)e <=ame o$ )ead0uarters or national o$$ice> unusale $or an extended duration o$ time and mi')t necessitate a strate'y ased on mirrored redundancy as !ell as a secondary strate'y in#ol#in' a commercial )ot site (ime sensiti#ity and mission criticality in conunction !it) ud'etary limitations, le#el o$ t)reat and de'ree o$ ris& !ill e maor $actors in t)e de#elopment o$ recommended strate'ies 5See H 6 $or :ecommended Strate'ies &%8%
P"OBABLE T2"EATS
()e tale depicts t)e t)reats most li&ely to impact t)e and components o$ and t)eir mana'ement ()e speci$ic t)reats t)at are represented y 5II are considered t)e most li&ely to occur !it)in t)e en#ironment P"OBABILITY OF T2"EATS Probabilit. of O66,rren6e9 2i+0 Me:i,7 X Air Con:itionin+ Fail,re Air6raft A66i:ent Bla67ail X Bo7b T0reats X X C0e7i6al S=ills / 2aMat Col: / Frost / Sno; Co77,ni6ations Loss X $ata $estr,6tion X Eart0,aes Fire XX Floo:in+ / 'ater $a7a+e N,6lear Mis0a=s XX Po;er Loss / O,ta+e Sabota+e / Terroris7 X Stor7s / 2,rri6anes Van:alis7 / "iotin+ X
Lo; X
X
X X X
X
Fi+,re &-& < System>9 "is Anal.sis Matri?
Date
e!sion 1"6
Pa*e 11
Business Continuity Plan
1
SYSTEM $ESC"IPTION
In tis section include in$o!mation $o! eac system unde! o&ne!sip o! cont!ollin* auto!ity o$ te <2acility5System>" Controlling authority assumes that a function or mission element of a Facility/System has been contracted to an outside entity that provides the facilities, hardware, and software and personnel required to perform that task and the Facility retain the oversight of that operation and therefore are the controlling activity for that system 1% P2YSICAL ENVI"ONMENT
Include te buildin* location? inte!nal $acilities? ent!y secu!ity measu!es? ala!ms? and access cont!ol" 1%# TEC2NICAL ENVI"ONMENT
Include accu!ate desc!iption o$ a!d&a!e p!ocesso!s? memo!y? media sto!a*e; and system so$t&a!e ope!atin* system? applications;" Include numbe! o$ use!s? inte!connected systems? and ope!ational const!aints" Put speci$ic so$t&a!e and a!d&a!e inento!ies? SAs? endo! contacts in appendixes"
3
PLAN
3% PLAN MANA)EMENT 3%%
BUSINESS CONTINUITY PLANNIN) 'O"@)"OUPS
()e de#elopment o$ reco#ery strate'ies and !or&-arounds re0uire tec)nical input, creati#ity, and pra'matism ()e est !ay to create !or&ale strate'ies and co)esi#e teams t)at le#era'e out-o$-t)e-ox t)in&in' is to in#ol#e mana'ement and in$ormation resource mana'ement personnel in an on'oin' in$ormati#e dialo'ue ()e mana'ement )as de#eloped and is $acilitatin' Business Continuity Plannin' !or&'roups to assist in t)e de#elopment and re#ie! o$ strate'ies, teams, and tas&s 3%%#
BUSINESS CONTINUITY PLAN COO"$INATO"
A coordinator and an alternate s)ould e appointed y mana'ement and system o!ners to monitor and coordinate t)e Business Continuity Plan, trainin' and a!areness, exercises, and testin' Additionally, t)is person !ill coordinate strate'y de#elopment !it) Business Continuity Plannin' or&'roups, System Contin'ency Coordinator, (eam eaders, Business Process %!ners, and ;ana'ement ()e Business Continuity Plannin' Coordinator s)ould !or& closely !it) system tec)nical mana'ers to ensure t)e #iaility o$ t)e Business Continuity Plan ()e Business Continuity Plan Coordinator !ill mana'e contin'ency teams t)at are not system speci$ic 5see section " *t is recommended t)at t)e indi#idual5s appointment5s Date
e!sion 1"6
Pa*e 1#
Business Continuity Plan
e documented in !ritin', and t)at speci$ic responsiilities e identi$ied and included in t)eir o descriptions 3%%&
SYSTEM CONTIN)ENCY COO"$INATO"S
A coordinator and an alternate s)ould e appointed $or 9AC7 SJS(9; under o!ners)ip or controllin' aut)ority o$ t)e y mana'ement and system o!ners ()eir primary tas& !ill e to monitor and coordinate t)e Business Continuity Plannin', trainin' and a!areness, exercises, and testin' Additionally, t)is person !ill mana'e contin'ency teams 5see Section " t)at are assi'ned speci$ically to t)eir system and report directly to t)e Business Continuity Plan Coordinator *t is recommended t)at t)e indi#idual5s appointment5s e documented in !ritin', and t)at speci$ic responsiilities e identi$ied and included in t)eir o descriptions 3%%1
INCI$ENT NOTIFICATION
()e $acilities mana'ers $or t)e locations !)ere t)e critical components o$ t)e systems are located s)ould e pro#ided !it) t)e telep)one numers o$ 9mer'ency :esponse (eam memers Gpon noti$ication, t)e team !ill meet in 5(BD $or t)e purpose o$ conductin' initial incident assessment and issuin' ad#isory reports o$ status to t)e and <=ame> mana'ement *$ t)e $acilities mana'er, emer'ency response personnel, or 9mer'ency :esponse (eam eader )as determined t)at t)e uildin' cannot e entered, t)e alternate meetin' place !ill e t)e 5(BD 3%%3
INTE"NAL PE"SONNEL NOTIFICATION
()e 29mer'ency =oti$ication4 procedure, or a modi$ied #ersion t)ereo$, s)ould e de#eloped and used $or noti$ication o$ t)e Crisis ;ana'ement (eam and ot)er Disaster :eco#ery (eams re'ardin' speci$ic response actions ta&en durin' response operations it)in t)e 2personal contact4 dataase, a sin'le source personal in$ormation tale s)ould readily a#ailale t)at includes )ome addresses, contact telep)one p)one numers, and emer'ency contact in$ormation *n t)e e#ent o$ a disaster, a lac& o$ speci$ic personal data, includin' )ome addresses, cell p)one numers, pa'er numers, and alternate contact in$ormation, could result in t)e inaility to locate and contact &ey personnel and team memers ()is automated personnel dataase s)ould e maintained and updated continuously ()is dataase may e maintained internally or some!)ere else !it)in t)e department, as lon' as t)e in$ormation contained t)erein remains current and accessile 3%%4
E!TE"NAL CONTACT NOTIFICATION
()e 29mer'ency =oti$ication4 procedure, or a modi$ied #ersion t)ereo$, s)ould e de#eloped and used $or noti$ication o$ its Business Continuity Plan ser#ice pro#iders, <=ame> a'encies, external contacts, #endors, suppliers, etc
Date
e!sion 1"6
Pa*e 13
Business Continuity Plan
3%%5
ME$IA " ELEASES
All incident related in$ormation 5printed or spo&en, concernin' t)e <9ame> !ill e coordinated and issued t)rou') t)e Department or Component %$$ice o$ Pulic A$$airs 5%PA 3%%8
ALTE"NATE SITE S
*nclude location o$ pre-positioned *n$ormation (ec)nolo'y Assets $or acti#ation in a contin'ency operation mode *t is su''ested t)at local sites $or $acility-/system-speci$ic contin'encies e maintained, suc) as a 2(ec) 7otel,4 !)ere t)e Business Continuity Planner rents space and in$ormation tec)nolo'y e0uipment Additional local alte!naties could be in te $o!m o$ !ecip!ocatin* 4%As and5o! 4%=s &it <=ame> o! ote! 2ede!al a*encies $o! te utili+ation o$ space $o! te installation o$ euipment? connectiity in$!ast!uctu!e and pe!sonnel accommodations sould te need a!ise" An alternate site !it) a distance o$ at least 1?? miles s)ould e considered S)ould a re'ional e#ent ta&e place t)at renders Facility systems ine$$ecti#e and t)e inaility $or p)ysical access, a relocation site !ould ser#e t)e needs $or contin'ency operations 3%# TEAMS
()e $ollo!in' are su''ested teams t)at !ill e assi'ned to execute t)e Business Continuity Plan8 Some teams may not be necessary depending on the system "f this is the case you should simply remove the heading and table Certain teams will be replicated for each system and placed under the System Contingency Coordinator given the vast differences in hardware, software, and e#ternal communications for each system $ach team will have a roster and task list of actions and responsibilities generated by the "%S database to be included in an appendi# 3%#%
$AMA)E ASSESSMENT TEAM
()e Dama'e Assessment (eam is a tec)nical 'roup responsile $or assessin' dama'e to t)e Facility/System and its components *t is composed o$ personnel !it) a t)orou') understandin' o$ )ard!are and e0uipment and t)e aut)ority to ma&e decisions re'ardin' t)e procurement and disposition o$ )ard!are and ot)er assets ()is team is primarily responsile $or initial dama'e assessment, accountin' o$ dama'e assessment, loss minimi+ation, sal#a'e and procurement o$ necessary replacement e0uipment and inter$aces ()is team s)ould include #endor representati#es ()e Dama'e Assessment (eam !ill enter t)e $acility as soon as t)ey )a#e recei#ed permission to do so $rom emer'ency ser#ices A !ritten detailed account s)ould e made o$ t)e 'eneral status o$ t)e !or& area, !it) speci$ic attention to t)e condition o$ )ard!are, so$t!are, $urnis)in's, and $ixtures :ecommendations s)ould e made t)at all dama'ed e0uipment, media, and documentation e routed immediately to disaster Date
e!sion 1"6
Pa*e 1'
Business Continuity Plan
reco#ery and restoration experts $or a determination as to its aility to e sal#a'ed or restored 3%#%#
OPE"ATIONS TEAM
()e %perations (eam consists o$ operators responsile $or runnin' emer'ency production $or critical systems, coordinatin' !it) Bac&up (eam to ensure t)at applications system data and operatin' instructions are correct, and !it) t)e iaison (eam to ad#ise o$ t)e production status and any unusual prolems re0uirin' assistance Data *nput/Control (eams could e separate 'roups or su'roups o$ t)e %perations (eam Also, t)e PC Support (eam under t)e %perations :eco#ery (eam is responsile $or re-estalis)in' microcomputer operations at t)e ac&up site or remote sites and $or assistin' !it) reinstatin' PC applications 3%#%&
COMMUNICATIONS TEAM
()e Communications (eam is composed o$ communications specialists responsile $or restorin' #oice, data, and #ideo communications lin&s et!een users and t)e computers, re'ardless o$ location in t)e e#ent o$ a loss or outa'e Communication #endor 5carrier input in desi'nin' and implementin' t)e reco#ery plan is #ery important *n$luential $actors in de#elopin' reco#ery procedures $or t)is team include8 t)e type o$ net!or&, t)e time re0uirement $or restoration, percenta'e o$ t)e net!or& to e reco#ered, and ud'et considerations 3%#%1
$ATA ENT"Y AN$ CONT"OL TEAM
()e Data 9ntry and Control (eam is responsile $or enterin' data as it is restored ()ey ensure t)at t)e data is t)e est a#ailale ac&up and meets #alidation $or t)e system 3%#%3
OFF-SITE STO"A)E TEAM
()e %$$-site Stora'e (eam is responsile $or retrie#in' ac&up copies o$ operatin' systems applications, systems, applications data, and ensurin' security o$ t)e data, ac&up $acilities, and ori'inal $acilities ()e team is composed o$ memers o$ $amiliar !it) #ital records arc)i#al and retrie#al 3%#%4
A$MINIST"ATIVE MANA)EMENT TEAM
()e Administrati#e ;ana'ement (eam coordinates Primary and Alternate Site security and speciali+ed clerical and administrati#e support $or t)e Business Continuity Plan Coordinator and all ot)er teams durin' disaster contin'ency proceedin's ()e Administrati#e (eam may also assist 'roups outside t)e in$ormation resources area as needed ()e Administrati#e (eam is responsile $or reassemlin' all documentation $or standards, procedures, applications, pro'rams, systems, and $orms, as re0uired at t)e ac&up site ()e Administrati#e (eam is responsile $or arran'in' $or transportation o$ sta$$, e0uipment, supplies, and ot)er necessary items et!een sites 3%#%5
P"OCU"EMENT TEAM
()e Procurement (eam consists o$ persons &no!led'eale o$ t)e in$ormation resources and supplies in#entory and t)e ud'etary, $undin', and ac0uisition processes responsile $or expeditin' ac0uisition o$ necessary resources Date
e!sion 1"6
Pa*e 1,
Business Continuity Plan
3%#%8
CONFI)U"ATION MANA)EMENT TEAM
()e Con$i'uration ;ana'ement (eam is composed o$ indi#iduals !it) teleprocessin' s&ills ()ey !or& closely !it) t)e Communications (eams in estalis)in' #oice and data communication capailities 3%#%
FACILITIES TEAM
()e Facilities (eam is responsile $or arran'in' $or t)e primary and ac&up $acilities and all components 3%#%D SYSTEM SOFT'A"E TEAM
()e System So$t!are (eam consists o$ system so$t!are pro'rammers responsile $or pro#idin' t)e system so$t!are support necessary $or production o$ critical applications systems durin' reco#ery 3%#% INTE"NAL AU$IT TEAM
()e *nternal Audit (eam is responsile $or oser#ation and o#ersi')t participation in t)e reco#ery e$$ort 3%#%# USE" ASSISTANCE TEAM
()e Gser Assistance team is composed o$ indi#iduals !it) application use &no!led'e ()e team is made up o$ maor user area mana'ers, production control, and applications lead analysts responsile $or coordination and liaison, !it) t)e in$ormation resources sta$$ $or applications reco#ery and restoration o$ data $iles and dataases Gnder t)e 'eneral leaders)ip o$ t)e Gser Assistance (eam, tec)nical applications specialist and dataase administration su-teams per$orm necessary application restoration acti#ities Settin' priorities $or applications reco#ery is a primary in$luence on procedures $or t)is team and its su'roups 3%& $ATA COMMUNICATIONS
Dependin' on t)e location o$ t)e calin', a cale cut y a ac&)oe could render an and associated uildin's !it)out connecti#ity %$tentimes, 2redundant calin'4 can mean t!o $ier optic cales laid in t)e same trenc) $or $ailo#er connecti#ity )ile t)is may e ade0uate $or routine telecommunication interruptions, it represents a sin'le point o$ $ailure $or communications and connecti#ity ()e le#el o$ data connecti#ity re0uired !ill e determined pendin' t)e $inal decision re'ardin' t)e disaster declaration Data communications speci$ications s)ould e documented in APP9=D*I <7> , Communication :e0uirements, in t)is plan and s)ould e stored in t)e secure o$$site stora'e location or <=ame> , in t)e e#ent t)at a permanent replacement $acility is re0uired 3%1 BAC@UPS
()e most important p)ysical asset in any Facility/System is its data and in$ormation Data and in$ormation processin' are a maor reason $or t)e existence o$ <=ame> ;oreo#er, all o$ t)e <=ame> systems are dependent on t)e preser#ation o$ data, Date
e!sion 1"6
Pa*e 1
Business Continuity Plan
includin' so$t!are manuals and documentation *n order to minimi+e t)e impact o$ a disaster, it is extremely important to protect t)e sensiti#ity or con$identiality o$ dataK to preser#e t)e aut)enticity and accuracy o$ data, and to maintain t)e a#ailaility o$ data ()ese t)ree 'oals are commonly de$ined as 2Con$identiality, *nte'rity, and A#ailaility4 ()e protection o$ t)e con$identiality, inte'rity, and a#ailaility o$ data is o$ sin'ular importance in in$ormation security and disaster reco#ery plannin' Con$identiality, inte'rity, and a#ailaility o$ data are intrinsic to disaster reco#ery plannin' 9$$ecti#e procedures to per$orm $ull data ac& ups on a re'ular !ee&ly asis must e implemented A copy o$ t)e !ee&ly ac& ups s)ould e securely transported on a !ee&ly asis and stored o$$ site in an en#ironmentally controlled stora'e $acility, pre$eraly outside t)e immediate re'ional area Fre0uent ac&ups s)ould e implemented to ensure t)e reco#ery o$ t)e most current data #ersion and to increase t)e li&eli)ood o$ usale media in a post-e#ent scenario 3%1%
VITAL " ECO"$S/$OCUMENTATION
Lital records and important documentation s)ould e ac&ed up and stored o$$ site Lital records are any documents or documentation t)at is essential to t)e operations o$ an or'ani+ation, suc) as personnel records, so$t!are documentation, le'al documentation, le'islati#e documentation, ene$its documentation, etc Documentation o$ all aspects o$ computer support and operations is important to ensure continuity and consistency Formali+in' operational practices and procedures in detail )elps to eliminate security lapses and o#ersi')ts, 'i#es ne! personnel detailed instructions on )o! to operate e0uipment or do a particular tas&, and pro#ides a 0uality assurance $unction to )elp ensure t)at operations !ill e per$ormed correctly and e$$iciently e#ery time Security documentation s)ould e de#eloped to $ul$ill t)e needs o$ t)ose !)o use it For t)is reason, many or'ani+ations separate documentation into policy and procedures $or eac) user le#el For example, a $unctional security procedures manual s)ould e !ritten to in$orm end users )o! to do t)eir os securely !)ile a tec)nical and operational security procedures manual s)ould e !ritten $or systems operations and support sta$$ $ocusin' on system administrations concerns in considerale detail ()ere s)ould e at least t!o copies o$ current system security documentation %ne copy s)ould e stored on site and e immediately accessile A ac& up copy must e stored o$$ site and s)ould include documents suc) as system security plans 5SSP, Business Continuity Plans, ris& analyses, and security policies and procedures Additional copies may e necessary $or some documentation, suc) as Business Continuity Plans, !)ic) s)ould e easily accessile in t)e e#ent o$ a disaster *t is recommended t)at copies o$ t)e Business Continuity Plan e distriuted to t)e Business Continuity Plan Coordinator, 9xecuti#e ;ana'ement, and (eam eaders $or sa$e&eepin'
Date
e!sion 1"6
Pa*e 1
Business Continuity Plan
Documentation s)ould e duplicated eit)er in )ard copy or compatile media $ormat and stored at t)e o$$-site stora'e or t)e 5reco#ery site location ()e ori'inal primary on-site unit retains t)e ori'inal copies o$ all in$ormation Gpdates to documentation s)ould e rotated on an as-re0uired asis, under t)e control o$ t)e responsile team %$$-site documentation s)ould include tec)nical and operational documentation %any of the below listed documents may be found in the completed certification and accreditation package &the System Security 'uthori(ation 'greement &SS'') and 'ppendices) "f the information is in the SS'', keep it current and maintain a copy off* site
()e $ollo!in' documentation s)ould e maintained o$$ site8 •
Security related *n$ormation (ec)nolo'y 5*( policy M procedure memorandum, circulars, pulications
•
Department or component mission statement
•
etters o$ dele'ation $or &ey *n$ormation System security personnel
•
Complete )ard!are and so$t!are listin's
•
*nternal security, *n$ormation System audits
•
Detailed *( arc)itecture sc)ematics 5lo'ical/p)ysical, net!or&, de#ices
•
=et!or& cale routin' sc)ematics 5on $loor o#erlay
•
•
•
•
•
•
•
•
System testin' plans/procedures :e#ie! and appro#al o$ plans/procedures System Con$i'uration :e#ie! and appro#al o$ proposed con$i'uration C)an'es made to t)e system con$i'uration 9#aluation o$ c)an'es $or security implications (ec)nical standards $or system desi'n, testin' and maintenance to re$lect security oecti#es Business Continuity Plans $or incident response procedures and ac&up operations
Date
e!sion 1"6
Pa*e 1.
Business Continuity Plan
•
Data ac&up/restoration procedures and procedures $or stora'e, transportation and )andlin' o$ ac&up tapes
•
:eports o$ security related incidents
•
•
•
Sensiti#ity and criticality determination Baseline security c)ec&list $or eac) system So$t!are licensin' in$ormation
Additionally, it is recommended t)at mana'ement personnel de#elop detailed procedural manuals speci$yin' )o! t)eir $unctional responsiilities are to e disc)ar'ed in t)e e#ent o$ t)eir una#ailaility ()is is especially important $or &ey personnel Copies o$ t)ese manuals s)ould e &ept o$$-site !it) ot)er documentation 3%3 OFFICE EUIPMENT FU"NITU"E AN$ SUPPLIES
Alt)ou') t)e current strate'y is $or o$$ice e0uipment, $urniture, and supplies to e ordered on an 2emer'ency as re0uired4 asis at t)e time o$ t)e disaster, it is recommended t)at mana'ement re#ie! supply needs and coordinate !it) t)e local procurement o$$ice to de#elop a re#ol#in' emer'ency in#entory o$ !or&space and sur#i#al supplies $or immediate use in t)e e#ent o$ a disaster ()e re#ol#in' in#entory o$ !or&space supplies s)ould include not only asic essential !or&space supplies li&e pens, pencils, note pads, and paper, ut also speci$ic $orms and templates Additionally, a re#ol#in' in#entory o$ sur#i#al supplies s)ould e maintained, includin' ottled drin&in' !ater, personal products, and $ood rations, in t)e e#ent personnel cannot e e#acuated or are temporarily pre#ented $rom lea#in' t)e con$ines o$ t)e uildin' due to !eat)er conditions 3%4 "ECOMMEN$E$ TESTIN) P"OCE$U"ES
()e Business Continuity Plan s)ould e maintained routinely and exercised/tested at least annually Contin'ency procedures must e tested periodically to ensure t)e e$$ecti#eness o$ t)e plan ()e scope, oecti#e, and measurement criteria o$ eac) exercise !ill e determined and coordinated y t)e Business Continuity Plan Coordinator on a 2per e#ent4 asis ()e purpose o$ exercisin' and testin' t)e plan is to continually re$ine resumption and reco#ery procedures to reduce t)e potential $or $ailure ()ere are t!o cate'ories o$ testin'8 announced and unannounced *n an announced test, personnel are instructed !)en testin' !ill occur, !)at t)e oecti#es o$ t)e test are, and !)at t)e scenario !ill e $or t)e test Announced testin' is )elp$ul $or t)e initial test o$ procedures *t 'i#es teams t)e time to prepare $or t)e test and allo!s t)em to practice t)eir s&ills %nce t)e team )as )ad an opportunity to run t)rou') t)e procedures, practice, and coordinate t)eir s&ills, unannounced testin' may e used to test t)e Date
e!sion 1"6
Pa*e 10
Business Continuity Plan
completeness o$ t)e procedures and s)arpen t)e team.s ailities Gnannounced testin' consists o$ testin' !it)out prior noti$ication ()e use o$ unannounced testin' is extremely )elp$ul in preparin' a team $or disaster preparation ecause it $ocuses on t)e ade0uacy o$ in-place procedures and t)e readiness o$ t)e team Gnannounced testin', comined !it) closely monitored restrictions, !ill )elp to create a simulated scenario t)at mi')t exist in a disaster ()is more closely measures t)e teams. aility to $unction under t)e pressure and limitations o$ a disaster %nce it )as een determined !)et)er a test !ill e announced or unannounced, t)e actual oecti#e5s o$ t)e test must e determined ()ere are se#eral di$$erent types o$ tests t)at are use$ul $or measurin' di$$erent oecti#es A recommended sc)edule $or testin' is as $ollo!s8 •
Des&top testin' on a 0uarterly asis
•
%ne structured !al&-t)rou') per year
•
%ne inte'rated usiness operations/in$ormation systems exercise per year
()e Business Continuity Plan Coordinator, Contin'ency System Coordinators, and (eam eaders, to'et)er !it) t)e %$$ice ;ana'ement and , !ill determine end-user participation
4
"ECOMMEN$E$ ST"ATE)IES
()e $ollo!in' in$ormation represents potential recommendations to t)e Director, and ot)er tec)nical mana'ement positions as appropriate ()ese s)ould e considered as solutions t)at potentially may assist in t)e continued de#elopment o$ t)eir reco#ery capailities in a post-disaster situation 4% C"ITICAL ISSUES 6.1.1
POWER
()e tec)nolo'y director s)ould !or& to de#elop po!er re0uirements necessary to pro#ide uninterrupted ser#ice $or t)e data center A$ter t)e determination o$ po!er re0uirements )as een de#eloped $or t)e continuous operaility o$ t)e t)e s)ould $ollo! t)e standard procurement process to otain, install, test, and maintain suc) a system *t s)ould e noted t)at t)e standard li$e cycle $or t)e amorti+ation o$ a diesel po!ered ac&up 'enerator is "? years 6.1.2
D IVERSIFI!"IO# OF O##E"IVI"$
As it stands, t)e current connecti#ity con$i'uration represents a sin'le point o$ $ailure to t)e entire ()e dedicated connecti#ity $rom all t)e re'ional o$$ices con#er'es Date
e!sion 1"6
Pa*e #6
Business Continuity Plan
in t)e data center A sin'le occurrence o$ $ire, po!er $ailure, terrorist act, or ci#il unrest could completely disrupt email and *nternet ased connecti#ity et!een t)e uildin' and t)e re'ions Additionally, users rely upon *nternet connecti#ity to pro#ide outside email a#ailaility to t)e Department and t)e re'ions t)ere$ore, ased upon any o$ t)e a$orementioned scenarios t)at $unction, !ould also cease to $unction 6.1.%
OFFSI"E & !'(P S "OR!)E
()e current sc)edule implemented $or t)e trans$er o$ ac&up tapes to t)e o$$site stora'e $acility is inconsistent !it) t)e oecti#es o$ Business Continuity Plannin' ()e sc)edule )as t)e sta$$ maintainin' t)e most current ac&up tapes onsite in t)e uildin' $or a 3? day period prior to trans$er to t)e o$$site stora'e $acility ()us, all data extracted $rom o$$ice ac&up tapes !ill e more t)an 3? days old *n today.s data intensi#e en#ironment t)is pro#ides stale in$ormation to t)e end users ()is is especially critical in #ie! o$ t)e $act t)at t)e only time a sta$$ must rely on t)e o$$site ac&up media is !)en t)e system )as $ailed and any incremental ac&ups are ine$$ecti#e and/or ine$$icient to resol#e t)e situation ()e loss o$ t)irty 53? days o$ !or& and data ased on t)e impact o$ a disaster is not acceptale ()e sc)edule controllin' t)is process s)ould e re-#isited and modi$ied to re$lect a more $re0uent trans$er timeline ()e accepted standard is t)e trans$er o$ ac&up media to t)e o$$site stora'e on a !ee&ly asis to estalis) a co ntinuously current $lo! o$ data into t)e ac&up copies ()is !ill allo! t)e sta$$ to execute restorations utili+in' t)e most updated in$ormation a#ailale ()is is particularly true re'ardin' t)e e-mail systems
5
TE"MS AN$ $EFINITIONS
Te $ollo&in* is a comp!eensie list o$ te!ms tat a!e impo!tant in Business Continuity Plannin* and !ecoe!y ope!ations" Add any 2acility speci$ic and system speci$ic te!ms &it de$initions !eleant to te Business Continuity Plan in te app!op!iate alpabetical positions" ABC Fire E?tin+,is0er - Cemically based deices used to eliminate o!dina!y combustible? $lammable liuid? and elect!ical $i!es" A66e=table LeGel of "is - typically !e$e!s to te point at &ic te leel o$ !is8 is mo!e acceptable tan te cost to miti*ate te !is8 in dolla!s o! a$$ect on compute! system $unction;" A66ess - te ability to do sometin* &it a compute! !esou!ce" Tis usually !e$e!s to a tecnical ability e"*"? !ead? c!eate? modi$y? o! delete a $ile? execute a p!o*!am? o! use an exte!nal connection;J admissionJ ent!ance" A66ess 6ontrol - te p!ocess o$ limitin* access to te !esou!ces o$ an IT system only to auto!i+ed use!s? p!o*!ams? p!ocesses? o! ote! IT systems" A66o,ntabilit. - te p!ope!ty tat enables actiities on a system to be t!aced to indiiduals? &o may ten be eld !esponsible $o! tei! actions" Date
e!sion 1"6
Pa*e #1
Business Continuity Plan
A6t,ator - A mecanical assembly tat positions te !ead5&!ite ead assembly oe! te app!op!iate t!ac8s" A6tiGation - 7en all o! a po!tion o$ te !ecoe!y plan as been put into motion" A:e,ate se6,rit. - secu!ity commensu!ate &it te !is8 and ma*nitude o$ te a!m !esultin* $!om te loss? misuse? o! unauto!i+ed access to? o! modi$ication o$ in$o!mation" Tis includes assu!in* tat systems and applications used by <=ame> ope!ate e$$ectiely and p!oide app!op!iate con$identiality? inte*!ity? and aailability? t!ou* te use o$ coste$$ectie mana*ement? pe!sonnel? ope!ational? and tecnical cont!ols" Alert - 9oti$ication tat a disaste! situation as occu!!ed - stand by $o! possible actiation o$ disaste! !ecoe!y plan" Alternate Site - A location? ote! tan te no!mal $acility? used to p!ocess data and5o! conduct c!itical business $unctions in te eent o$ a disaste!" Similar (erms8 Alternate Processin' Facility, Alternate %$$ice Facility, Alternate Communication Facility A==li6ation - te use o$ in$o!mation !esou!ces in$o!mation and in$o!mation tecnolo*y; to satis$y speci$ic set o$ use! !eui!ements" A==li6ation =ro+ra7 - A so$t&a!e p!o*!am comp!isin* a set o$ statements? de$inin* ce!tain tas8s" A==li6ation "e6oGer. - Te component o$ (isaste! /ecoe!y tat deals speci$ically &it te !esto!ation o$ business system so$t&a!e and data? a$te! te p!ocessin* plat$o!m as been !esto!ed o! !eplaced" Simila! Te!ms: Business System /ecoe!y" Arra. - An a!!an*ement o$ t&o o! mo!e dis8 d!ies: may be in /edundant A!!ay o$ Inexpensie (is8s /AI(; o! daisy-cain $asion" Asset a alue placed on *oods o&ned by an o!*ani+ation Ass,7=tions - Basic unde!standin*s about un8no&n disaste! situations tat te disaste! !ecoe!y plan is based on" Ass,ran6e - a measu!e o$ con$idence tat te secu!ity $eatu!es and a!citectu!e o$ an automated in$o!mation system accu!ately mediate and en$o!ce te secu!ity policy" As.n60rono,s Transfer Mo:e ATM - A net&o!8 a!citectu!e tat diides messa*es into $ixed-si+e units cells; and establises a s&itced connection bet&een te o!i*inatin* and !eceiin* stationsJ enables t!ansmission o$ a!ious types o$ data ideo? audio? etc"; oe! te same line &itout one data type dominatin* te t!ansmission A,:it s.ste7 - an independent !eie&? examination o$ te !eco!ds? and actiities to access te adeuacy o$ system cont!olsJ to ensu!e compliance &it establised policies and ope!ational p!ocedu!es" Te audit system is an essential tool $o! te dete!mination and !ecommendation o$ necessa!y can*es in cont!ols? policies? o! p!ocedu!es" A,:it trail - a se!ies o$ !eco!ds o$ compute! eents about an ope!atin* system? an application? o! use! actiities" A,:itin+ - te !eie& and analysis o$ mana*ement? ope!ational? and tecnical cont!ols" A,t0enti6ation - p!oin* to some !easonable de*!ee; a use!Ks identity" It can also be a measu!e desi*ned to p!oide p!otection a*ainst $!audulent t!ansmission by establisin* te alidity o$ a t!ansmission? messa*e? station? o! o!i*inato!" A,t0oriation - te pe!mission to use a compute! !esou!ce" Pe!mission is *!anted? di!ectly o! indi!ectly? by te application o! system o&ne!" A,to7ate: means compute!i+ed $o! te pu!pose o$ tis document" AGailabilit. - te p!ope!ty o$ bein* accessible and usable? upon demand by an auto!i+ed entity? to complete a $unction" Te in$o!mation tecnolo*y system o! installation Date
e!sion 1"6
Pa*e ##
Business Continuity Plan
contains in$o!mation o! p!oides se!ices tat must be aailable on a timely basis? to meet mission !eui!ements o! to aoid substantial losses" Cont!ols to p!otect te aailability o$ in$o!mation a!e !eui!ed? i$ te in$o!mation is c!itical to te <=ame>Ks actiityKs $unctions" Access to some in$o!mation !eui!es <=ame> to ensu!e te aailability o$ tat in$o!mation &itin a so!t pe!iod o$ time" Ba6 Offi6e Lo6ation - An o$$ice o! buildin*? used by te o!*ani+ation to conduct suppo!t actiities? tat is not located &itin an o!*ani+ationLs eadua!te!s o! main location" Ba6bone - te unde!lyin* net&o!8 communication conduit o! line by &ic all main se!e!s and deices a!e connectedJ bac8bone deices a!e typically se!e!s? !oute!s? ubs? and b!id*esJ client compute!s a!e not connected di!ectly to te bac8bone" Ba6,= - means eite! p!ocedu!es o! standby euipment tat a!e aailable $o! use in te eent o$ a $ailu!e o! inaccessibility o$ no!mally used euipment o! p!ocedu!es o! to ma8e a copy o$ data o! a p!o*!am in case te o!i*inal is lost? dama*ed? o! ote!&ise unaailable" Ba6,= A+ree7ent - A cont!act to p!oide a se!ice tat includes te metod o$ pe!$o!mance? te $ees? te du!ation? te se!ices p!oided? and te extent o$ secu!ity and con$identiality maintained" Ba6,= Position Listin+ - A list o$ alte!natie pe!sonnel &o can $ill a !ecoe!y team position &en te p!ima!y pe!son is not aailable" Ba6,= Strate+ies "e6oGer. Strate+ies - Alte!natie ope!atin* metod i"e"? plat$o!m? location? etc"; $o! $acilities and system ope!ations in te eent o$ a disaste!" Ban:;i:t0 - te amount o$ data tat can be t!ansmitted ia a *ien communications cannel e"*"? bet&een a a!d d!ie and te ost PC; in a *ien unit o$ time" Blo6 - a po!tion o$ a olume usually ,1# bytes in si+eJ o$ten !e$e!!ed to as a Mlo*ical bloc8"M B,rst 7o:e - a tempo!a!y? i*-speed data t!ans$e! mode tat can t!ans$e! data at si*ni$icantly i*e! !ates tan &ould no!mally be acieed &it non-bu!st tecnolo*yJ te maximum t!ou*put a deice is capable o$ t!ans$e!!in* data" B,s - te main communication aenue in a compute!J an elect!ical pat&ay alon* &ic si*nals a!e sent $!om one pa!t o$ te compute! to anote!" B,siness Contin,it. Plannin+ BCP9 An all encompassin*? Mumb!ellaM te!m coe!in* bot disaste! !ecoe!y plannin* and business !esumption plannin*" Also see disaster reco#ery plannin' and usiness resumption plannin' B,siness I7=a6t Anal.sis BIA - Te p!ocess o$ analy+in* all business $unctions and te e$$ect tat a speci$ic disaste! may ae upo n tem" B,siness Interr,=tion - Any eent? &ete! anticipated i"e"? public se!ice st!i8e; o! unanticipated i"e"? blac8out; &ic dis!upts te no!mal cou!se o$ business ope!ations at a co!po!ate location" B,siness Interr,=tion Costs - Te costs o! lost !eenue associated &it an inte!!uption in no!mal business ope!ations" B,siness "e6oGer. Coor:inator - See Disaster :eco#ery Coordinator B,siness "e6oGer. Pro6ess - Te common c!itical pat tat all companies $ollo& du!in* a !ecoe!y e$$o!t" Te!e a!e ma)o! nodes alon* te pat tat a!e $ollo&ed !e*a!dless o$ te o!*ani+ation" Te p!ocess as seen sta*es: 1; Immediate !esponse? #; Eni!onmental
Date
e!sion 1"6
Pa*e #3
Business Continuity Plan
!esto!ation? 3; 2unctional !esto!ation? '; (ata sync!oni+ation? ,; /esto!e business $unctions? ; Inte!im site? and ; /etu!n ome" B,siness "e6oGer. Tea7 - A *!oup o$ indiiduals !esponsible $o! maintainin* and coo!dinatin* te !ecoe!y p!ocess" Similar (erms8 :eco#ery (eam B,siness "es,7=tion Plannin+ B"P9 Te ope!ations piece o$ business continuity plannin*" Also see8 Disaster :eco#ery Plannin' B,siness Unit "e6oGer. - Te component o$ (isaste! /ecoe!y &ic deals speci$ically &it te !elocation o$ 8ey o!*ani+ation pe!sonnel in te eent o$ a disaste!? and te p!oision o$ essential !eco!ds? euipment supplies? &o!8 space? communication $acilities? compute! p!ocessin* capability? etc" Similar (erms8 or& roup :eco#ery B.te - Te $undamental data unit $o! pe!sonal compute!s? comp!isin* . conti*uous bits" Ca60e - A la!*e ban8 o$ !andom access memo!y used $o! tempo!a!y sto!a*e o$ in$o!mation" Co7=,ter-Ai:e: $esi+n CA$ - J te use o$ a compute! in indust!ial desi*n applications suc as a!citectu!e? en*inee!in*? and manu$actu!in*" Call ba6 - a p!ocedu!e $o! identi$yin* a !emote te!minal" In a call bac8? te ost system disconnects te calle! and ten dials te auto!i+ed telepone numbe! o$ te !emote te!minal to !eestablis te connection" Synonymous &it dial bac8" Central Offi6e - a secu!e? sel$-contained telecommunications euipment buildin* tat ouses se!e!s? sto!a*e systems? s&itcin* euipment? eme!*ency po&e! systems? and !elated deices tat a!e used to !un telepone systems" Certifie: $isaster "e6oGer. Planner C$"P9 C(/PLs a!e ce!ti$ied by te (isaste! /ecoe!y Institute? a not-$o!-p!o$it co!po!ation? &ic p!omotes te c!edibility and p!o$essionalism in te (/ indust!y" C0e6list Test - A metod used to test a completed disaste! !ecoe!y plan" Tis test is used to dete!mine i$ te in$o!mation suc as pone numbe!s? manuals? euipment? etc" in te plan is accu!ate and cu!!ent" Cl,stere: serGers - Te concept o$ combinin* multiple ost compute!s to*ete! t!ou* a p!iate communication line? suc as Ete!net bac8bone? to $o!m a !in* o$ ost compute!sJ tis !in* o$ ost compute!s act as a sin*le entity? capable o$ pe!$o!min* multiple complex inst!uctions by dist!ibutin* te &o!8load ac!oss all membe!s o$ te !in*" Cl,stere: stora+e - te concept o$ combinin* multiple sto!a*e se!e!s to*ete! to $o!m a !edundant !in* o$ sto!a*e deicesJ cluste!ed sto!a*e systems typically pe!$o!m multiple !ead and &!ite !euests t!ou* pa!allel access lines to te !euestin* compute!" Col: Site - An alte!nate $acility tat is oid o$ any !esou!ces o! euipment except ai!conditionin* and !aised $loo!in*" Euipment and !esou!ces must be installed in suc a $acility to duplicate te c!itical business $unctions o$ an o!*ani+ation" Cold-sites ae many a!iations dependin* on tei! communication $acilities? =ninte!!uptible Po&e! Sou!ce =PS; systems? o! mobility /elocatable-Sell;" Similar (erms8 S)ell-siteK Bac&up siteK :eco#ery siteK Alternati#e site Co77an: An:/Or Control Center CAC/CNC/CCC - A cent!ally located $acility ain* adeuate pone lines to be*in !ecoe!y ope!ations" Typically it is a tempo!a!y $acility used by te mana*ement team to be*in coo!dinatin* te !ecoe!y p!ocess and used until te alte!nate sites a!e $unctional"
Date
e!sion 1"6
Pa*e #'
Business Continuity Plan
Co77er6e serGi6e =roGi:er CSP - A company tat p!oides e-comme!ce solutions $o! !etaile!s" Co7=etitiGe lo6al e?60an+e 6arrier CLEC - a lon* distance ca!!ie!? cable company? o! small sta!tup local excan*e ca!!ie! tat competes $o! business in a local telepone ma!8etJ many CECs also o$$e! Inte!net se!ices" Co7=,ter Gir,s - A p!o*!am tat Nin$ectsO compute! systems in muc te same &ay? as a biolo*ical i!us in$ects umans" Te typical i!us N!ep!oducesO by ma8in* copies o$ itsel$ and inse!tin* tem into te code o$ ote! p!o*!amseite! in systems so$t&a!e o! in application p!o*!ams" Co77,ni6ations Fail,re - An unplanned inte!!uption in elect!onic communication bet&een a te!minal and a compute! p!ocesso!? o! bet&een p!ocesso!s? as a !esult o$ a $ailu!e o$ any o$ te a!d&a!e? so$t&a!e? o! telecommunications components comp!isin* te lin8" Also !e$e! to 9et&o!8 %uta*e"; Co77,ni6ations "e6oGer. - Te component o$ (isaste! /ecoe!y &ic deals &it te !esto!ation o! !e!outin* o$ an o!*ani+ationLs telecommunication net&o!8? o! its components? in te eent o$ loss" Similar (erms8 5(elecommunication :eco#ery, Data Communications :eco#ery Co7=,ter "e6oGer. Tea7 C"T - A *!oup o$ indiiduals !esponsible $o! assessin* dama*e to te o!i*inal system? p!ocessin* data in te inte!im? and settin* up te ne& system" Confi:entialit. - te assu!ance tat in$o!mation is not disclosed to unauto!i+ed entities o! p!ocesses" Te in$o!mation tecnolo*y system o! installation contains in$o!mation tat !eui!es p!otection $!om unauto!i+ed o! inapp!op!iate disclosu!e" Some in$o!mation must be p!otected $!om unauto!i+ed o! accidental disclosu!e" <=ame> is !eui!ed to p!eent some in$o!mation $!om !elease to pe!sons &itout te p!ope! uali$ications" In$o!mation !eui!in* p!otection $!om unauto!i+ed disclosu!e includes classi$ied in$o!mation? in$o!mation !elated to milita!y ope!ations and euipment? con$idential comme!cial business in$o!mation? con$idential <=ame> business in$o!mation? P!iacy Act in$o!mation? la& en$o!cement con$idential in$o!mation? p!ocu!ement-sensitie in$o!mation? bud*eta!y in$o!mation p!io! to %4B !elease? and in$o!mation exempt $!om disclosu!e unde! te 2!eedom o$ In$o!mation Act 2%IA;" Confi+,ration 6ontrol - te p!ocess o$ cont!ollin* modi$ications to te systemKs a!d&a!e? so$t&a!e? and documentation tat p!oide su$$icient assu!ance tat te system is p!otected a*ainst te int!oduction o$ imp!ope! modi$ications be$o!e? du!in*? and a$te! system implementation" Confi+,ration 7ana+e7ent CM - Te mana*ement o$ can*es made to a systemKs a!d&a!e? so$t&a!e? $i!m&a!e? documentation? tests? test $ixtu!es? and test documentation t!ou*out te deelopment and ope!ational li$e o$ te system" Consorti,7 A+ree7ent - An a*!eement made by a *!oup o$ o!*ani+ations to sa!e p!ocessin* $acilities and5o! o$$ice $acilities? i$ one membe! o$ te *!oup su$$e!s a disaste!" Similar (erms8 :eciprocal A'reement B,siness Contin,it. Plan - a plan $o! eme!*ency !esponse? bac8-up ope!ations? and post-disaste! !ecoe!y $o! in$o!mation tecnolo*y systems and installations in te eent no!mal ope!ations a!e inte!!upted" Te Business Continuity Plan sould ensu!e minimal impact upon data p!ocessin* ope!ations in te eent te in$o!mation tecnolo*y system o! $acility is dama*ed o! dest!oyed" Date
e!sion 1"6
Pa*e #,
Business Continuity Plan
B,siness Contin,it. Plannin+ - a plan tat add!esses o& to 8eep an o!*ani+ationKs c!itical $unctions ope!atin* in te eent o$ any 8ind o$ dis!uptions" See Disaster :eco#ery Plan B,siness Contin,it. Plannin+ - See also Disaster :eco#ery Plannin' Controller - a unit o! ci!cuit!y tat mana*es te in$o!mation $lo& bet&een sto!a*e dis8s and te compute!" Coo=eratiGe 2ot sites - A ot site o&ned by a *!oup o$ o!*ani+ations aailable to a *!oup membe! sould a disaste! st!i8e" Also See 7ot-Site Cost Benefit Anal.sis - te assessment o$ te costs o$ p!oidin* data p!otection $o! a system e!sus te cost o$ losin* o! comp!omisin* a system" Cost of o;ners0i= - te pu!case p!ice o$ euipment plus te cost o$ ope!atin* tis euipment oe! its p!o)ected li$e span" Co77er6ial Off-t0e-S0elf COTS - J Comme!cially aailable p!oducts tat can be pu!cased and inte*!ated &it little o! no customi+ation? tus $acilitatin* custome! in$!ast!uctu!e expansion and !educin* costs" Co,nter7eas,re - any action? deice? p!ocedu!e? tecniue? o! ote! measu!e tat !educes te ulne!ability o$? o! t!eat to a system" Crate H S0i= - A st!ate*y $o! p!oidin* alte!nate p!ocessin* capability in a disaste!? ia cont!actual a!!an*ements &it an euipment supplie! to sip !eplacement a!d&a!e &itin a speci$ied time pe!iod" Similar (erms8 uaranteed :eplacement, Nuic& S)ip Crisis - A c!itical eent? &ic? i$ not andled in an app!op!iate manne!? may d!amatically impact an o!*ani+ationLs p!o$itability? !eputation? o! ability to ope!ate" Crisis Mana+e7ent - Te oe!all coo!dination o$ an o!*ani+ationLs !esponse to a c!isis? in an e$$ectie? timely manne!? &it te *oal o$ aoidin* o! minimi+in* dama*e to te o!*ani+ationLs p!o$itability? !eputation? o! ability to ope!ate" Crisis Si7,lation - Te p!ocess o$ testin* an o!*ani+ationLs ability to !espond to a c!isis in a coo!dinated? timely? and e$$ectie manne!? by simulatin* te occu!!ence o$ a speci$ic c!isis" Criti6al F,n6tions - Business actiities o! in$o!mation? &ic could not be inte!!upted o! unaailable $o! see!al business days &itout si*ni$icantly )eopa!di+in* ope!ation o$ te o!*ani+ation" Criti6al "e6or:s - /eco!ds o! documents? &ic? i$ dama*ed o! dest!oyed? &ould cause conside!able inconenience and5o! !eui!e !eplacement o! !ec!eation at conside!able expense" Cr.=to+ra=0. - te p!inciples? means? and metods $o! !ende!in* in$o!mation unintelli*ible and $o! !esto!in* enc!ypted in$o!mation to intelli*ible $o!m" Co7=,ter Tele=0on. Inte+ration CTI - P!oidin* a lin8 bet&een telepone systems and compute!s to $acilitate incomin* and out*oin* call andlin* and cont!olJ te pysical lin8 bet&een a telepone and se!e!" $i+ital A,:io Ta=e $AT ; - A di*ital ma*netic tape $o!mat o!i*inally deeloped $o! audio !eco!din* and no& used $o! compute! bac8up tapeJ te latest (AT sto!a*e $o!mat is ((S (i*ital (ata Sto!a*e;" $a7a+e Assess7ent - Te p!ocess o$ assessin* dama*e? $ollo&in* a disaste!? to compute! a!d&a!e? ital !eco!ds? o$$ice $acilities? etc" and dete!minin* &at can be sala*ed o! !esto!ed and &at must be !eplaced" $ata Center "e6oGer. - Te component o$ (isaste! /ecoe!y tat deals &it te Date
e!sion 1"6
Pa*e #
Business Continuity Plan
!esto!ation? at an alte!nate location? o$ data cente!s se!ices and compute! p!ocessin* capabilities" Similar (erms8 ;ain$rame :eco#ery $ata Center "elo6ation - Te !elocation o$ an o!*ani+ationLs enti!e data p!ocessin* ope!ation" $e6laration Fee - A one-time $ee? ca!*ed by an Alte!nate 2acility p!oide!? to a custome! &o decla!es a disaste!" Similar (erms8 =oti$ication Fee =%(98 Some reco#ery #endors apply t)e declaration $ee a'ainst t)e $irst $e! days o$ reco#ery $e6r.=tion - te p!ocess o$ ta8in* an enc!ypted $ile and !econst!uctin* te o!i*inal $ile" Tis is te opposite o$ enc!yption" $e:i6ate: Line - A p!e-establised point-to-point communication lin8 bet&een compute! te!minals and a compute! p!ocesso!? o! bet&een dist!ibuted p!ocesso!s? tat does not !eui!e dial-up access" $e=art7ental "e6oGer. Tea7 - A *!oup o$ indiiduals !esponsible $o! pe!$o!min* !ecoe!y p!ocedu!es speci$ic to tei! depa!tment" $.na7i6 )ro;t0 an: "e6onfi+,ration $)" - A (ot Fill tecnolo*y tat allo&s te system administ!ato! to uic8ly and easily add capacity o! can*e /AI( leels &ile te system is in use" $ial Ba6,= - Te use o$ dial-up communication lines as a bac8up to dedicated lines" $ial-U= Line - A communication lin8 bet&een compute! te!minals and a compute! p!ocesso!? &ic is establised on demand by dialin* a speci$ic telepone numbe!" $isaster - Any eent tat c!eates an inability on an o!*ani+ations pa!t to p!oide c!itical business $unctions $o! some p!edete!mined pe!iod o$ time" Similar (erms8 Business *nterruptionK %uta'eK Catastrop)e $isaster PreGention - 4easu!es employed to p!eent? detect? o! contain incidents tat? i$ uncec8ed? could !esult in disaste!" $isaster PreGention C0e6list - A uestionnai!e used to assess p!eentatie measu!es in a!eas o$ ope!ations suc as oe!all secu!ity? so$t&a!e? data $iles? data ent!y !epo!ts? mic!ocompute!s? and pe!sonnel" $isaster "e6oGer. - Te ability to !espond to an inte!!uption in se!ices by implementin* a disaste! !ecoe!y plan to !esto!e an o!*ani+ationLs c!itical business $unctions" $isaster "e6oGer. A:7inistrator - Te indiidual !esponsible $o! documentin* !ecoe!y actiities and t!ac8in* !ecoe!y p!o*!ess" $isaster "e6oGer. Coor:inator - Te (isaste! /ecoe!y Coo!dinato! may be !esponsible $o! oe!all !ecoe!y o$ an o!*ani+ation o! units;" Similar (erms8 Business :eco#ery Coordinator $isaster "e6oGer. Perio: - Te time pe!iod bet&een a disaste! and a !etu!n to no!mal $unctions? du!in* &ic te disaste! !ecoe!y plan is employed" $isaster "e6oGer. Plan $"P - Te document tat de$ines te !esou!ces? actions? tas8s and data !eui!ed to mana*e te business !ecoe!y p!ocess in te eent o$ a business inte!!uption" Te plan is desi*ned to assist in !esto!in* te business p!ocess &itin te stated disaste! !ecoe!y *oals" $isaster "e6oGer. Plannin+ - Te tecnolo*ical aspect o$ business continuity plannin*" Te adance plannin* and p!epa!ations tat a!e necessa!y to minimi+e loss and ensu!e continuity o$ te c!itical business $unctions o$ an o!*ani+ation in te eent o$ disaste!"
Date
e!sion 1"6
Pa*e #
Business Continuity Plan
Similar (erms8 Business Continuity Plannin'K usiness resumption plannin'K corporate Business Continuity Plannin'K usiness interruption plannin'K disaster preparedness $isaster "e6oGer. Soft;are - An application p!o*!am deeloped to assist an o!*ani+ation in &!itin* a comp!eensie disaste! !ecoe!y plan" $isaster "e6oGer. Tea7s B,siness "e6oGer. Tea7s9 A st!uctu!ed *!oup o$ teams !eady to ta8e cont!ol o$ te !ecoe!y ope!ations i$ a disaste! sould occu!" $is arra. see arra. - an a!!an*ement o$ t&o o! mo!e a!d dis8s? in /AI( o! daisycain con$i*u!ation? o!*ani+ed to imp!oe speed and p!oide p!otection o$ data a*ainst loss" $istrib,te: 6o7=,tin+ enGiron7ent - A set o$ middle&a!e standa!ds tat de$ines te metod o$ communication bet&een clients and se!e!s in a c!oss-plat$o!m computin* eni!onmentJ enables a client p!o*!am to initiate a !euest tat can be p!ocessed by a p!o*!am &!itten in a di$$e!ent compute! lan*ua*e and oused on a di$$e!ent compute! plat$o!m" $i+ital Linear Ta=e $LT - A se!pentine tecnolo*y $i!st int!oduced by (i*ital Euipment Co!po!ation and late! deeloped by Guantum $o! tape bac8up5a!cie o$ net&o!8s and se!e!sJ (T tecnolo*y add!esses mid!an*e to i*-end tape bac8up !eui!ements" Ele6troni6 In:,stries Asso6iation EIA - A t!ade association tat establises elect!ical and elect!onics-o!iented standa!ds" Ele6troni6 Va,ltin+ - T!ans$e! o$ data to an o$$site sto!a*e $acility ia a communication lin8 !ate! tan ia po!table media" Typically used $o! batc5)ou!naled updates to c!itical $iles to supplement $ull bac8ups ta8en pe!iodically" E7er+en6. - A sudden? unexpected eent !eui!in* immediate action due to potential t!eat to ealt and sa$ety? te eni!onment? o! p!ope!ty" E7er+en6. Pre=are:ness - Te discipline &ic ensu!es an o!*ani+ation? o! communityLs !eadiness to !espond to an eme!*ency in a coo!dinated? timely? and e$$ectie manne!" E7er+en6. Pro6e:,res - A plan o$ action to commence immediately to p!eent te loss o$ li$e and minimi+e in)u!y and p!ope!ty dama*e" Ele6tro Ma+neti6 Interferen6e EMI J 7at occu!s &en elect!oma*netic $ields $!om one deice inte!$e!e &it te ope!ation o$ some ote! deice" E7=lo.ee "elief Center E"C - A p!edete!mined location $o! employees and tei! $amilies to obtain $ood? supplies? $inancial assistance? etc"? in te eent o$ a catast!opic disaste!" En6r.=tion - Te p!ocess o$ codin* a messa*e to ma8e it unintelli*ible" Enter=rise stora+e net;or ESN - an inte*!ated suite o$ p!oducts and se!ices desi*ned to maximi+e ete!o*eneous connectiity and mana*ement o$ ente!p!ise sto!a*e deices and se!e!sJ a dedicated? i*-speed net&o!8 connected to te ente!p!iseLs sto!a*e systems? enablin* $iles and data to be t!ans$e!!ed bet&een sto!a*e deices and client main$!ames and se!e!s" EnGiron7ent - te a**!e*ate o$ exte!nal p!ocedu!es? conditions? and ob)ects tat a$$ect te deelopment? ope!ation? and maintenance o$ a system" Et0ernet - a local a!ea net&o!8 standa!d $o! a!d&a!e? communication? and cablin*" E?ten:e: O,ta+e - A len*ty? unplanned inte!!uption in system aailability due to compute! a!d&a!e o! so$t&a!e p!oblems? o! communication $ailu!es" Date
e!sion 1"6
Pa*e #.
Business Continuity Plan
E?tra E?=ense CoGera+e - Insu!ance coe!a*e $o! disaste! !elated expenses tat may be incu!!ed until ope!ations a!e $ully !ecoe!ed a$te! a disaste!" Fa6ilities - A location containin* te euipment? supplies? oice and data communication lines? to conduct t!ansactions !eui!ed to conduct business unde! no!mal conditions" Similar (erms8 Primary Site, Primary Processin' Facility, Primary %$$ice Facility FailoGer - te t!ans$e! o$ ope!ation $!om a $ailed component e"*"? cont!olle!? dis8 d!ie; to a simila!? !edundant component to ensu!e uninte!!upted data $lo& and ope!ability" Fa,lt toleran6e - te ability o$ a system to cope &it inte!nal a!d&a!e p!oblems e"*"? a dis8 d!ie $ailu!e; and still continue to ope!ate &it minimal impact? suc as by b!in*in* a bac8up system online" Fiber C0annel-Arbitrate: Loo= FC-AL - A $ast se!ial bus inte!$ace standa!d intended to !eplace SCSI on i*-end se!e!s" A 2ib!e Cannel implementation in &ic use!s a!e attaced to a net&o!8 ia a one-&ay !in* loop; cablin* sceme" Fiber C0annel Co77,nit. FCC - J An inte!national non-p!o$it o!*ani+ation &ose membe!s include manu$actu!e!s o$ se!e!s? dis8 d!ies? /AI( sto!a*e systems? s&itces? ubs? adapte! ca!ds? test euipment? cables and connecto!s? and so$t&a!e solutions" Fiber C0annel - A i*-speed sto!a*e5net&o!8in* inte!$ace tat o$$e!s i*e! pe!$o!mance? *!eate! capacity and cablin* distance? inc!eased system con$i*u!ation $lexibility and scalability? and simpli$ied cablin*" Fiber $istrib,te: $ata Interfa6e F$$I - A 166 4bit5s A9SI standa!d A9 a!citectu!e? de$ined in @3T0"," Te unde!lyin* medium is optical $ibe! tou* it can be coppe! cable? in &ic case it may be called C((I; and te topolo*y is a dual-attaced? counte!-!otatin* to8en !in*" File Ba6,= - Te p!actice o$ dumpin* copyin*; a $ile sto!ed on dis8 o! tape to anote! dis8 o! tape" Tis is done $o! p!otection case te actie $ile *ets dama*ed" File "e6oGer. - Te !esto!ation o$ compute! $iles usin* bac8up copies" File SerGer - Te cent!al !eposito!y o$ sa!ed $iles and applications in a compute! net&o!8 A9;" Foot=rint - te amount o$ $loo! space tat a piece o$ euipment e"*"? a !ac8mount enclosu!e; occupies" For7 fa6tor - te pysical si+e and sape o$ a deiceJ o$ten used to desc!ibe te si+e o$ dis8 a!!ays in a !ac8 mount enclosu!e" For;ar: "e6oGer. - Te p!ocess o$ !ecoe!in* a data base to te point o$ $ailu!e by applyin* actie )ou!nal o! lo* data to te cu!!ent bac8up $iles o$ te database" F,ll "e6oGer. Test An exe!cise in &ic all !ecoe!y p!ocedu!es and st!ate*ies a!e tested as opposed to a Pa!tial /ecoe!y Test"; )enerator - An independent sou!ce o$ po&e! usually $ueled by diesel o! natu!al *as" )i+ab.te - app!oximately one billion bytes? 1?6#' me*abytes" 2ost B,s A:a=ter 2BA - J a a!d&a!e ca!d tat !esides on te PC bus and p!oides an inte!$ace connection bet&een a SCSI deice suc as a a!d d!ie; and te ost PC" 2alon - A *as used to extin*uis $i!es e$$ectie only in closed a!eas" 2i+0 Priorit. Tass - Actiities ital to te ope!ation o$ te o!*ani+ation" Cu!!ently bein* pased out due to eni!onmental conce!ns" Similar (erms8 Critical Functions 2o7e =a+e - Te main pa*e on a 7eb site tat se!es as te p!ima!y point o$ ent!y to !elated pa*es &itin te site and may ae lin8s to ote! sites as &ell"
Date
e!sion 1"6
Pa*e #0
Business Continuity Plan
2ost-atta60e: stora+e - A sto!a*e system tat is connected di!ectly to te net&o!8 se!e!J also !e$e!!ed to as se!e!-attaced sto!a*e" 2ot site -An alte!nate $acility tat as te euipment and !esou!ces to !ecoe! te business $unctions a$$ected by te occu!!ence o$ a disaste!" Fot-sites may a!y in type o$ $acilities o$$e!ed suc as data p!ocessin*? communication? o! any ote! c!itical business $unctions needin* duplication;" ocation and si+e o$ te ot-site &ill be p!opo!tional to te euipment and !esou!ces needed" Similar (erms8 Bac&up siteK :eco#ery siteK :eco#ery CenterK Alternate processin' site 2ot s=are - a bac8up component e"*"? dis8 o! cont!olle!; tat is online and aailable sould te p!ima!y component *o do&n" 2ot s;a==able - te ability to !eplace a component e"*"? dis8 d!ie? cont!olle!? $an? po&e! sou!ce; &ile te system is on line? &itout ain* to po&e! do&nJ also !e$e!!ed to as ot-plu* !emoable" 2ierar60i6al Stora+e Mana+e7ent 2SM - J a sto!a*e system in &ic ne&? $!euently used data is sto!ed on te $astest? most accessible and *ene!ally mo!e expensie; media e"*"? /AI(; and olde!? less $!euently used data is sto!ed on slo&e! less expensie; media e"*"? tape;" 2,b - A deice tat splits one net&o!8 cable into a set o$ sepa!ate cables? eac connectin* to a di$$e!ent compute!J used in a local a!ea net&o!8 to c!eate a small-scale net&o!8 by connectin* see!al compute!s to*ete!" 2,7an T0reats - Possible dis!uptions in ope!ations !esultin* $!om uman actions i"e"? dis*!untled employee? te!!o!ism? etc";" 2eat Ventilation an: Air Con:itionin+ 2VAC Te system tat p!oides and maintains a cont!olled eni!onment &it conditions conducie to continuous and uninte!!upted compute! ope!ations" I:entifi6ation - Te p!ocess tat enables? *ene!ally by te use o$ uniue macine!eadable names? !eco*nition o$ use!s o! !esou!ces? as indistin*uisable? to tose p!eiously desc!ibed to te automated in$o!mation system" Instit,te of Ele6tri6al an: Ele6troni6s En+ineers IEEE - Te la!*est tecnical society in te &o!ld? consistin* o$ en*inee!s? scientists? and studentsJ as decla!ed standa!ds $o! compute!s and communications" Initiator- A Small Compute! System Inte!$ace SCSI; deice tat !euests anote! SCSI deice a ta!*et; to pe!$o!m an ope!ationJ usually a ost compute! acts as an initiato! and a pe!ipe!al deice acts as a ta!*et" Infor7ation s.ste7 - Te o!*ani+ed collection? p!ocessin*? t!ansmission? and dissemination o$ in$o!mation in acco!dance &it de$ined p!ocedu!es? &ete! automated o! manual" Infor7ation te60nolo+. s.ste7 - an in$o!mation system tat is automated o! is an assembly o$ compute! a!d&a!e and so$t&a!e con$i*u!ed $o! te pu!pose o$ classi$yin*? so!tin*? calculatin*? computin*? summa!i+in*? t!ansmittin* and !eceiin*? sto!in* and !et!iein* data &it a minimum o$ uman inte!ention" Te te!m includes sin*le application p!o*!ams? &ic ope!ate independently o$ ote! p!o*!am applications" A Nsensitie in$o!mation tecnolo*y systemO means an in$o!mation tecnolo*y system tat contains sensitie in$o!mation" Infor7ation te60nolo+. installation - one o! mo!e compute! o! o$$ice automation systems? includin* !elated telecommunications? pe!ipe!al and sto!a*e units? cent!al Date
e!sion 1"6
Pa*e 36
Business Continuity Plan
p!ocessin* units? and ope!atin* and suppo!t system so$t&a!e" In$o!mation tecnolo*y installations may !an*e $!om in$o!mation tecnolo*y installations? suc as la!*e cent!ali+ed compute! cente!s? to indiidual stand-alone mic!op!ocesso!s? suc as pe!sonal compute!s" A Nsensitie in$o!mation tecnolo*y installationO means an in$o!mation tecnolo*y installation? &ic contains o! p!oides p!ocessin* $o! a sensitie in$o!mation tecnolo*y system" Infrastr,6t,re 1; te pysical euipment compute!s? cases? !ac8s? cablin*? etc"; tat comp!ises a compute! systemJ #; te $oundational basis tat suppo!ts te in$o!mation mana*ement capabilities? includin* te telecommunications and net&o!8 connectiity" Inte+rit. :ata - Tat att!ibute o$ data !elatin* to te p!ese!ation o$ 1; its meanin* and completeness? #; te consistency o$ its !ep!esentations;? and 3; its co!!espondence to &at it !ep!esents" Te in$o!mation tecnolo*y system o! installation contains in$o!mation tat must be p!otected $!om unauto!i+ed? unanticipated? o! unintentional modi$ication o! dest!uction? includin* detection o$ suc actiities" Inte*!ity is impo!tant to all in$o!mation because inaccu!acy comp!omises te alue o$ te in$o!mation system" a& en$o!cement? mission and li$e c!itical? and $inancial in$o!mation a!e examples o$ in$o!mation !eui!in* p!otection to p!ese!e inte*!ity" Inte+rit. s.ste7 - Tat att!ibute o$ a system &en it pe!$o!ms its intended $unction in an unimpai!ed manne!? $!ee $!om delibe!ate o! inade!tent unauto!i+ed manipulation o$ te system" InterFa6ilit. B,siness Contin,it. Plannin+ "e+,lation A !e*ulation &!itten and imposed by te 2ede!al 2inancial Institutions Examination Council conce!nin* te need $o! $inancial institutions to maintain a &o!8in* disaste! !ecoe!y plan" Interfa6e - A connection bet&een a!d&a!e deices? applications? o! di$$e!ent sections o$ a compute! net&o!8" Interi7 Or+aniational Str,6t,re - An alte!nate o!*ani+ation st!uctu!e tat &ill be used du!in* !ecoe!y $!om a disaste!" Tis tempo!a!y st!uctu!e &ill typically st!eamline cains o$ command and inc!ease decision-ma8in* autonomy" Internal 2ot sites - A $ully euipped alte!nate p!ocessin* site o&ned and ope!ated by te o!*ani+ation" Internet - A &o!ld&ide system o$ lin8ed compute! net&o!8s" Internet SerGi6e ProGi:er ISP - A company tat p!oides Inte!net access se!ices to consume!s and businessesJ ISPs lease connections $!om Inte!net bac8bone p!oide!sJ &ile most ISPs a!e small companies tat se!ice a local a!ea? te!e a!e also !e*ional and national ISPs suc as Ame!ica %nline;" Intero=erabilit. - Te ability o$ one compute! system to cont!ol anote!? een tou* te t&o systems a!e made by di$$e!ent manu$actu!e!s" Interr,=tion - An outa*e caused by te $ailu!e o$ one o! mo!e communications lin8s &it entities outside o$ te local $acility" Intranet - a compute! net&o!8? based on Inte!net tecnolo*y? &ic is desi*ned to meet te inte!nal needs $o! sa!in* in$o!mation &itin a sin*le o!*ani+ation o! company" In=,t/O,t=,t I/O - J /eception !ead; o! t!ansmission &!ite; o$ compute! si*nalsJ te enti!e connection pat bet&een te CP= bus and te dis8 d!ies" I/Os Per Se6on: IOPS - A measu!e o$ pe!$o!mance $o! a ost-attaced sto!a*e deice o! /AI( cont!olle!" (,st A B,n60 Of $iss (BO$ - A dis8 a!!ay &itout a cont!olle!" Date
e!sion 1"6
Pa*e 31
Business Continuity Plan
@ernel - Te co!e o$ an ope!atin* system suc as 7indo&s 0.? 7indo&s 9T? 4ac %S o! =nixJ p!oides basic se!ices $o! te ote! pa!ts o$ te ope!atin* system? ma8in* it possible $o! it to !un see!al p!o*!ams at once multitas8in*;? !ead and &!ite $iles and connect to net&o!8s and pe!ipe!als" Lo6al Area Net;or LAN - A A9 consists o$ pe!sonal compute!s tat a!e connected to*ete! t!ou* a!ious means? so tat tey can communicate &it eac ote!" A net&o!8 o$ compute!s? &itin a limited a!ea e"*"? a company o! o!*ani+ation;J Computin* euipment? in close p!oximity to eac ote!? connected to a se!e! &ic ouses so$t&a!e tat can be access by te use!s" Tis metod does not utili+e a public ca!!ie!" See Also A= LAN "e6oGer. - Te component o$ (isaste! /ecoe!y &ic deals speci$ically &it te !eplacement o$ A9 euipment in te eent o$ a disaste!? and te !esto!ation o$ essential data and so$t&a!e Similar (erms8 Client/Ser#er :eco#ery Lease: Line - =sually synonymous &it dedicated line" Le+a6. - A compute!? system? o! so$t&a!e tat &as c!eated $o! a speci$ic pu!pose but is no& outdatedJ anytin* le$t oe! $!om a p!eious e!sion o$ te a!d&a!e o! so$t&a!e" Line "ero,tin+ - A se!ice o$$e!ed by many !e*ional telepone companies allo&in* te compute! cente! to uic8ly !e!oute te net&o!8 o$ dedicated lines to a bac8up site" Line Volta+e "e+,lators - Also 8no&n as su!*e p!otecto!s" Tese p!otecto!s5!e*ulato!s dist!ibute elect!icity eenly" Lo+i6 Bo7b - A compute! code tat is p!eset to cause a mal$unction? at a late! time? &en a speci$ied set o$ lo*ical conditions occu!s" 2o! example? a speci$ic social secu!ity numbe! in a pay!oll system is p!ocessed and te lo*ic bomb is actiated? causin* an imp!ope! amount o$ money to be p!inted on te cec8" Loss - Te un!ecoe!able business !esou!ces tat a!e !edi!ected o! !emoed as a !esult o$ a disaste!" Suc losses may be loss o$ li$e? !eenue? ma!8et sa!e? competitie statu!e? public ima*e? $acilities? o! ope!ational capability" Loss "e:,6tion - Te tecniue o$ institutin* mecanisms to lessen te exposu!e to a pa!ticula! !is8" oss !eduction is intended to !eact to an eent and limit its e$$ect" Examples o$ oss /eduction include sp!in8le! systems" Linear Ta=e O=en LTO - J A ne& standa!d tape $o!mat deeloped by FP? IB4? and Sea*ateJ expected aailability in #666" Lo+i6al Unit N,7ber LUN - An add!essin* sceme used to de$ine SCSI deices on a sin*le SCSI bus" Ma60ine-rea:able Me:ia - 4edia tat can coney data to a *ien sensin* deice? e"*"? dis8ettes? dis8s? tapes? compute! memo!y" Mainfra7e Co7=,ter - A i*-end compute! p!ocesso!? &it !elated pe!ipe!al deices? capable o$ suppo!tin* la!*e olumes o$ batc p!ocessin*? i* pe!$o!mance on-line t!ansaction p!ocessin* systems? and extensie data sto!a*e and !et!ieal" Similar (erms8 7ost Computer Mali6io,s Soft;are - Any o$ a $amily o$ compute! p!o*!ams deeloped &it te sole pu!pose o$ doin* a!m" 4alicious code is usually embedded in so$t&a!e p!o*!ams tat appea! to p!oide use$ul $unctions but? &en actiated by a use!? cause undesi!able !esults" Me:ia Trans=ortation CoGera+e - An insu!ance policy desi*ned to coe! t!anspo!tation o$ items to and $!om an E(P cente!? te cost o$ !econst!uction and te t!acin* o$ lost Date
e!sion 1"6
Pa*e 3#
Business Continuity Plan
items" Coe!a*e is usually extended to t!anspo!tation and disonesty o! collusion by delie!y employees" Me+ab.te - App!oximately one million bytes? 1?6#' 8ilobytes Ma+neti6 In C0ara6ter "ea:er MIC" E,i=7ent - Euipment used to imp!int macine-!eadable code" Dene!ally? $inancial institutions use tis euipment to p!epa!e pape! data $o! p!ocessin*? encodin* imp!intin*; items suc as !outin* and t!ansit numbe!s? account numbe!s? and dolla! amounts" Mirrorin+ - A metod o$ sto!a*e in &ic data $!om one dis8 is duplicated on anote! dis8 so tat bot d!ies contain te same in$o!mation? tus p!oidin* data !edundancy" Mission 6riti6al - Any compute! p!ocess tat cannot $ail du!in* no!mal business ou!sJ some compute! p!ocesses e"*"? telepone systems; must !un all day lon* and !eui!e 166 pe!cent uptime" Mobile 2ot Site - A la!*e t!aile! containin* bac8up euipment and pe!ipe!al deices delie!ed to te scene o$ te disaste!" It is ten oo8ed up to existin* communication lines" Mo:,lator $e7o:,lator Unit MO$EM - (eice tat cone!ts data $!om analo* to di*ital and bac8 a*ain" Monitorin+ - An on*oin* actiity tat cec8s on te system? its use!s? o! te eni!onment" Mean S;a=s Bet;een Fail,re MSBF - A statistical calculation used to p!edict te ae!a*e use$ulness o$ a !obotic deice e"*"? a tape lib!a!y; &it any inte!!uption o$ se!ice" Mean Ti7e Bet;een Fail,re MTBF - A statistical calculation used to p!edict te ae!a*e use$ulness o$ a deice &itout any inte!!uption o$ se!ice" Mean Ti7e To "e=air MTT" - Te ae!a*e amount o$ time !eui!ed to !esole most a!d&a!e o! so$t&a!e p!oblems &it a *ien de ice" M,lti-=latfor7 - "Te ability o$ a p!oduct o! net&o!8 to suppo!t a a!iety o$ compute! plat$o!ms e"*" IB4? Sun? 4acintos;J also !e$e!!ed to as c!oss-plat$o!m" Nat,ral T0reats - Eents caused by natu!e causin* dis!uptions to an o!*ani+ation" Net;or - Te %pen Systems Inte!connect %SI; seen-laye! model attempts to p!oide a &ay o$ pa!titionin* any compute! net&o!8 into independent modules $!om te lo&est pysical; laye! to te i*est application; laye!" 4any di$$e!ent speci$ications exist at eac o$ tese laye!s" Te net&o!8 is composed o$ a communications medium and all components attaced to tat medium &ose !esponsibility is te t!ans$e!ence o$ in$o!mation" Net;or Ar60ite6t,re - Te basic layout o$ a compute! and its attaced systems? suc as te!minals and te pats bet&een tem" Net;or-Atta60e: Stora+e NAS - A dis8 a!!ay sto!a*e system tat is attaced di!ectly to a net&o!8 !ate! tan to te net&o!8 se!e! i"e"? ost attaced;J $unctions as a se!e! in a client5se!e! !elationsip? as a p!ocesso!? an ope!atin* system o! mic!o-8e!nel? and p!ocesses $ile I5% p!otocols suc as S4B and 92S" Net;or SerGi6e ProGi:er NSP - a company tat p!oides te national o! inte!national pac8et-s&itcin* net&o!8s tat ca!!y Inte!net t!a$$icJ also called a bac8bone ope!ato!" Net;or O,ta+e - An inte!!uption in system aailability as a !esult o$ a communication $ailu!e a$$ectin* a net&o!8 o$ compute! te!minals? p!ocesso!s? o! &o!8stations"
Date
e!sion 1"6
Pa*e 33
Business Continuity Plan
No:e or net;or no:e - Any deice tat is di!ectly connected to te net&o!8? usually t!ou* Ete!net cableJ nodes include $ile se!e!s and sa!ed pe!ipe!alsJ te name used to desi*nate a pa!t o$ a net&o!8" Tis may be used to desc!ibe one o$ te lin8s in te net&o!8? o! a type o$ lin8 in te net&o!8 $o! example? Fost 9ode o! Inte!cept 9ode;" Nonessential F,n6tion/$ata - Business actiities o! in$o!mation tat could be inte!!upted o! unaailable inde$initely &itout si*ni$icantly )eopa!di+in* c!itical $unctions o$ an o!*ani+ation" Nonessential "e6or:s - /eco!ds o! documents? &ic? i$ i!!et!ieably lost o! dama*ed? &ill not mate!ially impai! te o!*ani+ationLs ability to conduct business" NT Mi6rosoft 'in:o;s NT - An ope!atin* system deeloped by 4ic!oso$t $o! i* pe!$o!mance p!ocesso!s and net&o!8ed systems" Ori+inal E,i=7ent Man,fa6t,rer OEM - A company tat manu$actu!es a *ien piece o$ a!d&a!e unli8e a alue-added !eselle!? &ic can*es and !epac8a*es te a!d&a!e;" Off-2ost Pro6essin+ - A bac8up mode o$ ope!ation in &ic p!ocessin* can continue t!ou*out a net&o!8 despite loss o$ communication &it te main$!ame compute!" Off-Line Pro6essin+ - A bac8up mode o$ ope!ation in &ic p!ocessin* can continue manually o! in batc mode i$ te on-line systems a!e unaailable" Off-Site Stora+e Fa6ilit. - A secu!e location? !emote $!om te p!ima!y location? at &ic bac8up a!d&a!e? so$t&a!e? data $iles? documents? euipment? o! supplies a!e sto!ed" On-Line S.ste7s - An inte!actie compute! system suppo!tin* use!s oe! a net&o!8 o$ compute! te!minals" O=en s.ste7s net;or - A net&o!8 comp!ised o$ euipment tat con$o!ms to indust!y standa!ds o$ inte!ope!ability bet&een di$$e!ent ope!atin* systems e"*"? =nix? 7indo&s 9T;" O=eratin+ Soft;are - A type o$ system so$t&a!e supe!isin* and di!ectin* all o$ te ote! so$t&a!e components plus te compute! a!d&a!e" O=eratin+ S.ste7 - Te maste! cont!ol p!o*!am e"*"? 7indo&s; tat mana*es a compute!Ls inte!nal $unctions and p!oides a means o$ cont!ol to te compute!Ls ope!ations and $ile system" Or+aniation C0art - A dia*!am !ep!esentatie o$ te ie!a!cy o$ an o!*ani+ationLs pe!sonnel" Or+aniation-'i:e - A policy o! $unction applicable to te enti!e o!*ani+ation" O,ta+e - See Systems %uta'e O,tso,r6in+ - Te t!ans$e! o$ data p!ocessin* $unctions to an indepen dent ti!d pa!ty" O;ner - Te indiidual desi*nated as bein* !esponsible $o! te p!otection o$ IT !esou!ces" Te o&ne! *ene!ally $alls into t&o b!oad cate*o!ies: custodial and o&ne!" 2o! example? te No&ne!O o$ te !esou!ces? may be te mana*e! o$ tat $acility" /esou!ces located &itin use! a!eas may be No&nedO by te mana*e! o$ tose a!eas" To assist &it te dete!mination o$ o&ne!sip? indiidual system bounda!ies must be establised" A system is identi$ied by lo*ical bounda!ies bein* d!a&n a!ound te a!ious p!ocessin*? communications? sto!a*e? and !elated !esou!ces" Tey must be unde! te same di!ect mana*ement cont!ol &it essentially te same $unction? !eside in te same eni!onment? and ae te same ca!acte!istics and secu!ity needs" %&ne!sip o$ in$o!mation and5o! in$o!mation p!ocessin* !esou!ces may be assi*ned to an o!*ani+ation? subo!dinate $unctional element? a position? o! a speci$ic indiidual" 7en o&ne!sip is assi*ned to an Date
e!sion 1"6
Pa*e 3'
Business Continuity Plan
o!*ani+ational o! $unctional element? te ead o$ te unit so desi*nated &ill be conside!ed te !esou!ce o&ne!" Some? but not necessa!ily all $acto!s to be conside!ed in te dete!mination o$ o&ne!sip a!e: %Te o!i*inato! o! c!eato! o$ data" #%Te o!*ani+ation o! indiidual &it te *!eatest $unctional inte!est" &%Pysical possession o$ te !esou!ce" Parallel Test- A test o$ !ecoe!y p!ocedu!es in &ic te ob)ectie is to pa!allel an actual business cycle" Parit. :ata - A bloc8 o$ in$o!mation matematically c!eated $!om see!al bloc8s o$ use! data to allo& !ecoe!y o$ use! data contained on a d!ie tat as $ailed in an a!!ayJ used in /AI( leels 3 and ," Pass;or: - A st!in* o$ alpanume!ic ca!acte!s cosen by an indiidual to elp ensu!e tat tei! compute! access is p!otected" Pass&o!ds a!e can*ed $!euently to minimi+e te !is8 o$ unauto!i+ed disclosu!e" Additional pass&o!ds may be assi*ned by te use! to pa!ticula! $iles o! data sets" Personal Co7=,ter Inter6onne6t PCI - An indust!y-standa!d bus used in se!e!s? &o!8stations? and PCs" Peri=0eral E,i=7ent- (eices connected to a compute! p!ocesso! tat pe!$o!m suc auxilia!y $unctions as communications? data sto!a*e? p!intin*? etc" Petab.te - 1?6#' te!abytes" P0.si6al Safe+,ar:s - Pysical measu!es ta8en to p!eent a disaste!? suc as $i!e supp!ession systems? ala!m systems? po&e! bac8up and conditionin* systems? access cont!ol systems? etc" Platfor7 - A a!d&a!e standa!d? suc as IB4? Sun? o! 4acintos" Portable S0ell - An eni!onmentally p!otected and !eadied st!uctu!e tat can be t!anspo!ted to a disaste! site so euipment can be obtained and installed nea! te o!i*inal location" Pro6e:,ral Safe+,ar:s - P!ocedu!al measu!es ta8en to p!eent a disaste!? suc as sa$ety inspections? $i!e d!ills? secu!ity a&a!eness p!o*!ams? !eco!ds !etention p!o*!ams? etc" Pro=rietar. - P!iately deeloped and o&ned tecnolo*y" Proto6ol - A standa!d tat speci$ies te $o!mat o$ data and !ules to be $ollo&ed in data communication and net&o!8 eni!onments" "AI$ A:Gisor. Boar: "AB - J an o!*ani+ation o$ sto!a*e system manu$actu!e!s and inte*!ato!s dedicated to adancin* te use and a&a!eness o$ /AI( and associated sto!a*e tecnolo*iesJ sta!ted in 100#? /AB states its main *oals as education? standa!di+ation and ce!ti$ication" "a67o,nt - Te cabinet tat ouses a se!e!5sto!a*e &o!8station also !e$e!!ed to as a se!e! !ac8;J to mount euipment into a cabinet" "e:,n:ant Arra. of In:e=en:ent or ine?=ensiGe $iss "AI$ - A collection o$ sto!a*e dis8s &it a cont!olle! o! cont!olle!s; to mana*e te sto!a*e o$ data on te dis8s" "e:,n:ant $ata Pat0 "$P - (ot FillLs so$t&a!e tecnolo*y tat c!eates an alte!nate data pat bet&een te se!e! and te sto!a*e system in te eent o$ system component $ailu!es to ensu!e continuous access to data" "eal-ti7e - Immediate p!ocessin* o$ input o! noti$ication o$ status"
Date
e!sion 1"6
Pa*e 3,
Business Continuity Plan
"e6i=ro6al A+ree7ent - An a*!eement bet&een t&o o!*ani+ations &it compatible compute! con$i*u!ations allo&in* eite! o!*ani+ation to utili+e te ote!Ls excess p!ocessin* capacity in te eent o$ a disaste!" "e6or: "etention - Sto!in* isto!ical documentation $o! a set pe!iod o$ time? usually mandated by state and $ede!al la& o! te Inte!nal /eenue Se!ice" "e6oGer. A6tion Plan - Te comp!eensie set o$ documented tas8s to be ca!!ied out du!in* !ecoe!y ope!ations" "e6oGer. AlternatiGe - Te metod selected to !ecoe! te c!itical business $unctions $ollo&in* a disaste!" In data p!ocessin*? some possible alte!naties &ould be manual p!ocessin*? use o$ se!ice bu!eaus? o! a bac8up site ot o! cold-site;" A !ecoe!y alte!natie is usually selected $ollo&in* a /is8 Analysis? Business Impact Analysis? o! bot" Similar (erms8 Bac&up site, ac&up alternati#e "e6oGer. Ca=abilit. - Tis de$ines all o$ te components necessa!y to pe!$o!m !ecoe!y" Tese components can include a plan? an alte!nate site? can*e cont!ol p!ocess? net&o!8 !e!outin*? and ote!s" "e6oGer. Mana+e7ent Tea7 - A *!oup o$ indiiduals !esponsible $o! di!ectin* te deelopment and on-*oin* maintenance o$ a disaste! !ecoe!y plan" Also !esponsible $o! decla!in* a disaste! and p!oidin* di!ection du!in* te !ecoe!y p!ocess" "e6oGer. Plannin+ Tea7 - A *!oup o$ indiiduals appointed to oe!see te de elopment and implementation o$ a disaste! !ecoe!y plan" "e6oGer. Point ObJe6tiGe "PO - Te point in time to &ic data must be !esto!ed in o!de! to !esume p!ocessin* t!ansactions" /P% is te basis on &ic a data p!o)ection st!ate*y is deeloped" "e6oGer. Tea7 - See Business :eco#ery (eam "e6oGer. Ti7e - Te pe!iod $!om te disaste! decla!ation to te !ecoe!y o$ te c!itical $unctions" "elo6atable S0ell - See Portale S)ell "e6oGer. =ro6e:,res - te actions necessa!y to !esto!e a systemKs p!ocessin* capability and data $iles a$te! a system $ailu!e" "is - A combination o$ te li8eliood tat a t!eat &ill occu!? te li8eliood tat a t!eat occu!!ence &ill !esult in an ade!se impact? and te see!ity o$ te !esultin* ade!se impact" "is anal.sis - A $o!mal systematic app!oac to assessin* te ulne!ability o$ an in$o!mation tecnolo*y system o! installation" /is8 analysis is te p!ocess o$ analy+in* t!eats to and ulne!abilities o$ an in$o!mation system to dete!mine te !is8s potential $o! losses;" Te !esultin* data is ten analy+ed" Te analysis is used as a basis $o! identi$yin* app!op!iate and cost-e$$ectie measu!es to counte! te identi$ied t!eats and ulne!abilities" Te !is8 analysis identi$ies t!eats? uanti$ies te potential losses $!om t!eat !eali+ation? examines te cost bene$it o$ applyin* alte!natie measu!es to counte! te identi$ied t!eats and !educes potential loss? and de$ines o! documents te de*!ee o$ acceptable !is8" Similar (erms8 :is& assessmentK impact assessmentK corporate loss analysisK ris& identi$icationK exposure analysisK exposure assessment "is 7ana+e7ent - Te p!ocess o$ te identi$ication? measu!ement? cont!ol? and minimi+ation o$ secu!ity !is8 in in$o!mation systems" Also? it means to assess !is8? ta8e actions to !educe !is8 to an acceptable leel? and maintain !is8 at tat leel" Ine!ent in
Date
e!sion 1"6
Pa*e 3
Business Continuity Plan
tis de$inition a!e te concepts tat !is8 cannot be completely eliminated and te most secu!e compute! system is te one tat no one uses" "o,ter - An elect!onic deice tat connects t&o o! mo!e net&o!8s and !outes incomin* data pac8ets to te app!op!iate net&o!8" Safe+,ar:s - Te p!otectie measu!es and cont!ols tat a!e p!esc!ibed to meet te secu!ity !eui!ements speci$ied $o! a system" SalGa+e H "estoration - Te p!ocess o$ !eclaimin* o! !e$u!bisin* compute! a!d&a!e? ital !eco!ds? o$$ice $acilities? etc" $ollo&in* a disaste!" SalGa+e Pro6e:,res - Speci$ied p!ocedu!es to be actiated i$ euipment o! a $acility sould su$$e! any dest!uction" Sa7=le Plan - A *ene!ic disaste! !ecoe!y plan tat can be tailo!ed to $it a pa!ticula! o!*ani+ation" Stora+e Area Net;or SAN - A net&o!8 in$!ast!uctu!e o$ sa!ed multi-ost sto!a*e? lin8in* all sto!a*e deices as &ell as inte!connectin* !emote sites" Satellite Co77,ni6ation - (ata communications ia satellite" 2o! *eo*!apically dispe!sed o!*ani+ations? may be iable alte!natie to *!ound-based communications in te eent o$ a disaste!" S6alable - Te ability o$ a p!oduct o! net&o!8 to accommodate *!o&t" S6an - To examine compute! codin*5p!o*!ams seuentially? pa!t by pa!t" 2o! i!uses? scans a!e made $o! i!us si*natu!es o! potentially unsa$e p!actices" E"*"? can*es to an executable $ile? di!ect &!ites to speci$ic dis8 secto!s? et al";" S6o=e - P!ede$ined a!eas o$ ope!ation $o! &ic a disaste! !ecoe!y plan is deeloped" S7all Co7=,ter S.ste7 Interfa6e SCSI - An inte!$ace tat se!es as an expansion bus tat can be used to connect a!d dis8 d!ies? tape d!ies? and ote! a!d&a!e components" Se6,re - In te!minolo*y? suc as e"*"? secu!e A9 o! secu!e deice? means tat te !outin* add!esses on te net&o!8 a!e monito!ed and allo&ed to p!oceed only $o! auto!i+ed use!s" Tis net&o!8 t!a$$ic monito!in* and auto!i+ation p!ocess is !e$e!!ed to as <=ame>Ks N$i!e&allsO" Systems and deices? not bein* monito!ed? a!e !e$e!!ed to as bein* outside o$ <=ame>Ks secu!e $i!e&all and te te!m Nnon-secu!eO is applied" Se6,rit. feat,res - A!e cont!ols tat p!otect a*ainst te identi$ied ulne!abilities? i"e" $i!e and &ate! ala!ms? pass&o!ds and ote! access p!otection? use o$ !emoable media $o! data sto!a*e? data alidation cont!ols? audit t!ails? un-inte!!uptible po&e! sou!ces =PS; to p!otect a*ainst elect!ical outa*es? pe!sonnel sc!eenin*? compute! secu!ity a&a!eness t!ainin* o$ use!s? etc" Se6,rit. infra6tion - Te $ailu!e to $ollo& applicable la&s and !e*ulations and establised <=ame> policies and p!ocedu!es pe!tainin* to te p!otection o$ <=ame> in$o!mation and compute! !esou!ces" Fence$o!t? in$!action and iolation a!e to be used inte!can*eably t!ou*out tis document" Se6,rit. =oli6. - Te set o$ la&s? !ules? and p!actices tat !e*ulate o& an o!*ani+ation mana*es? p!otects? and dist!ibutes sensitie in$o!mation" Se6,rit. s=e6ifi6ation - A detailed desc!iption o$ te secu!ity !eui!ements and speci$ications necessa!y to p!otect an in$o!mation tecnolo*y system o! installation" SensitiGe infor7ation - In$o!mation tat !eui!es a de*!ee o$ p!otection due to its natu!e? ma*nitude o$ loss? o! a!m tat could !esult $!om inade!tent o! delibe!ate disclosu!e? modi$ication? o! dest!uction" Tis includes in$o!mation tat is Date
e!sion 1"6
Pa*e 3
Business Continuity Plan
%4ission c!itical i"e"? loss o! a!m &ould be suc tat an <=ame> o$$ice could not pe!$o!m essential $unctions;" #%Sould not be disclosed unde! te 2!eedom o$ In$o!mation Act? suc as p!op!ieta!y data and economic $o!ecasts" P!op!ieta!y data includes t!ade sec!ets? comme!cial? o! $inancial data obtained in te cou!se o$ Doe!nment business? $!om o! !elatin* to a pe!son o! pe!sons outside te *oe!nment? not *ene!ally aailable to te public? and &ic is p!iile*ed? &ould cause competitie a!m i$ !eleased? o! impai! te ability o$ te *oe!nment to obtain data in te $utu!e" &%Complies &it %4B Ci!cula! A-1# 2inancial 4ana*ement Systems" 1%Complies &it te P!iacy Act o$ 10'" (ata? &ic pe!tains to a speci$ic indiidual by name? Social Secu!ity 9umbe! o! by some ote! identi$yin* means? and is pa!t o$ a system o$ !eco!ds as de$ined in te P!iacy Act o$ 10'" 3%Classi$ied" SerGer - A compute! tat sto!es application and data $iles $o! all &o!8stations on a net&o!8J also !e$e!!ed to as a $ile se!e!" S0a:o; File Pro6essin+ - An app!oac to data bac8up in &ic !eal-time duplicates o$ c!itical $iles a!e maintained at a !emote p!ocessin* site" Similar (erms8 :emote ;irrorin' Si7,lation Test - A test o$ !ecoe!y p!ocedu!es unde! conditions app!oximatin* a speci$ic disaste! scena!io" Tis may inole desi*nated units o$ te o!*ani+ation actually ceasin* no!mal ope!ations &ile exe!cisin* tei! p!ocedu!es" Sills InGentor. - A listin* o$ employees tat lists tei! s8ills tat apply to !ecoe!y" S=in:le - 4ecanism inside a a!d dis8 d!ie tat moes te eads into placeJ te axle on &ic a dis8 tu!ns" Serial Stora+e Ar60ite6t,re SSA - A i*-speed metod o$ connectin* dis8? tape? and C(-/%4 d!ies? p!inte!s? scanne!s? and ote! deices to a compute!" Stan:-Alone Pro6essin+ - P!ocessin*? typically on a PC o! mid-!an*e compute!? &ic does not !eui!e any communication lin8 &it a main$!ame o! ote! p!ocesso!" Stri=in+ - A metod o$ sto!a*e in &ic a unit o$ data is dist!ibuted and sto!ed ac!oss see!al a!d dis8s? &ic imp!oes access speed b ut does not p!oide !edundancy" Str,6t,re: 'al-T0ro,+0 Test - Team membe!s &al8 t!ou* te plan to identi$y and co!!ect &ea8nesses" S,bs6ri=tion - Cont!act commitment p!oidin* an o!*ani+ation &it te !i*t to utili+e a endo! !ecoe!y $acility $o! !ecoe!y o$ tei! main$!ame p!ocessin* capability" S,=er-,ser - A system account tat as $ull system-&ide administ!atie p!iile*es" 4ost =9I@ macines ae a lo* on account called NrootO? &ic acts as te supe!-use!" S,staine: 7o:e - Te measu!ed t!ans$e! !ate o$ a *ien deice du!in* no!mal ope!ation" S;it60 - A net&o!8 t!a$$ic-monito!in* deice tat cont!ols te $lo& o$ t!a$$ic bet&een multiple net&o!8 nodes" S.ste7 - A *ene!ic te!m used $o! its b!eity to mean eite! a ma)o! application o! a *ene!al suppo!t system" A system is identi$ied by lo*ical bounda!ies d!a&n a!ound te a!ious p!ocessin* communications? sto!a*e? and !elated !esou!ces" Tey must be unde! same di!ect mana*ement cont!ol not !esponsibility;? pe!$o!m essentially te same $unction? !eside in te same eni!onment? and ae te same ca!acte!istics and secu!ity needs" A system does not ae to be pysically connected"
Date
e!sion 1"6
Pa*e 3.
Business Continuity Plan
S.ste7s $o;nti7e - A planned inte!!uption in system aailability $o! sceduled system maintenance" S.ste7s inte+rator - An indiidual o! company tat combines a!ious components and p!o*!ams into a $unctionin* system? customi+ed $o! a pa!ticula! custome!Ls needs" S.ste7 O,ta+e - An unplanned inte!!uption in system aailability as a !esult o$ compute! a!d&a!e o! so$t&a!e p!oblems? o! ope!ational p!oblems" S.ste7 Se6,rit. Plan SSP - A plan to be deeloped by <=ame> in acco!dance &it %4B and 9IST *uidelines implementin* te Compute! Secu!ity Act o$ 10.? to sa$e*ua!d te secu!ity o$ its in$o!mation tecnolo*y systems and installations" Tar+et - a SCSI deice tat pe!$o!ms an ope!ation !euested by an initiato!" TC - Ta* command ueuin*J a $eatu!e int!oduced in te SCSI-# speci$ication tat pe!mits eac initiato! to issue commands accompanied by inst!uctions $o! o& te ta!*et sould andle te commandJ te initiato! can eite! !euest te command to be executed at te $i!st aailable oppo!tunity? in te o!de! in &ic te command &as !eceied? o! at a time deemed app!op!iate by te ta!*et" Te60ni6al T0reats - A disaste! causin* eent tat may occu! !e*a!dless o$ any uman elements" Tel6o - Abb!eiation $o! a Mtelecommunications company"M Te7=orar. O=eratin+ Pro6e:,res - P!edete!mined p!ocedu!es? &ic st!eamline ope!ations &ile maintainin* an acceptable leel o$ cont!ol and auditability du!in* a disaste! situation" Terab.te - App!oximately one t!illion bytes? 1?6#' *i*abytes" Test Plan - Te !ecoe!y plans and p!ocedu!es tat a!e used in a systems test to ensu!e iability" A test plan is desi*ned to exe!cise speci$ic action tas8s and p!ocedu!es tat &ould be encounte!ed in a !eal disaste!" Test s6enarios - A!e desc!iptions o$ te tests to be pe!$o!med to cec8 te e$$ectieness o$ te secu!ity $eatu!es" Tey may include alidation o$ pass&o!d const!aints? suc as len*t and composition o$ te pass&o!d? ent!y o$ e!!oneous data to cec8 data alidation cont!ols? !eie& o$ audit in$o!mation p!oduced by te system? !eie& o$ Business Continuity Plans and !is8 analyses? etc" T0reat - Any ci!cumstance o! eent &it te potential to cause a!m to a system in te dest!uction? disclosu!e? modi$ication o$ data? and5o! denial o$ se!ice" T0ro,+0=,t - 4easu!es te numbe! o$ se!ice !euests on te I5% cannel pe! unit o$ time" Ti7e Bo7b - Compute! code tat is p!eset to cause a late! mal$unction a$te! a speci$ic date? time? o! a speci$ic numbe! o$ ope!ations" Te N2!iday te 13tO compute! i!us is an example" Tis i!us in$ects te system see!al days o! een monts be$o!e and lies do!mant until te date !eaces 2!iday te 13t" To=olo+. - Deomet!ic a!!an*ement o$ nodes and cable lin8s in a local a!ea net&o!8J may be eite! cent!ali+ed o! decent!ali+ed" Transfer rate - Te numbe! o$ me*abytes o$ data tat can be t!ans$e!!ed $!om te !ead5&!ite eads to te dis8 cont!olle! in one second" Tra= $oor - A set o$ inst!uction codes embedded in a compute! ope!atin* system tat pe!mits access? &ile bypassin* secu!ity cont!ols" TroJan 2orse - A p!o*!am tat causes unexpected and usually undesi!able; e$$ects &en &illin*ly installed o! !un by an unsuspectin* use!" A T!o)an o!se is commonly dis*uised Date
e!sion 1"6
Pa*e 30
Business Continuity Plan
as a *ame? a utility? o! an application" A pe!son can eite! c!eate o! *ain access to te sou!ce code o$ a common? $!euently used p!o*!am and ten add code? so tat te p!o*!am pe!$o!ms a a!m$ul $unction? in addition to its no!mal $unction" Tese p!o*!ams a!e *ene!ally deeply bu!ied in te code o$ te ta!*et p!o*!am? lie do!mant $o! a p!eselected pe!iod? and a!e t!i**e!ed in te same manne! as a lo*ic bomb" A T!o)an o!se can alte!? dest!oy? disclose data? o! delete $iles" T,rne. - A p!oduct o! system tat can be plu**ed in? tu!ned on? and ope!ated &it little o! no additional con$i*u!in*" Uninterr,=tible Po;er S,==l. UPS - A bac8up po&e! supply &it enou* po&e! to allo& a sa$e and o!de!ly sutdo&n o$ te cent!al p!ocessin* unit sould te!e be a dis!uption o! sutdo&n o$ elect!icity" UNI! - An ope!atin* system tat suppo!ts multitas8in* and is ideally suited to multi-use! applications suc as net&o!8s;" U=loa:in+ - Connectin* to anote! compute! and sendin* a copy o$ p!o*!am o! $ile to tat compute!" S99 AS% Do!nloadin' Usef,l "e6or:s - /eco!ds tat a!e elp$ul but not !eui!ed on a daily basis $o! continued ope!ations" User - A pe!son o! a p!ocess accessin* an automated in$o!mation system? eite! by di!ect o! indi!ect connection" User Contin+en6. Pro6e:,res - 4anual p!ocedu!es to be implemented du!in* a compute! system outa*e" User I$ - A *!oup o$ ca!acte!s and5o! numbe!s tat uniuely identi$y an indiidual and a!e used to *ain alid access to a compute! system" A use! id is no!mally coupled &it a pass&o!d tat is set by te o&ne! o$ te use! id" Val,e-A::e: "eseller VA" - A business tat !epac8a*es and imp!oes a!d&a!e manu$actu!ed by an o!i*inal euipment manu$actu!e!" Vir,s - A code se*ment tat !eplicates by attacin* copies o$ itsel$ to existin* executable p!o*!ams" Tis is usually done in suc a manne! tat te copies &ill be executed &en te $ile is loaded into memo!y? allo&in* tem to in$ect still ote! $iles? and so on" Te ne& copy o$ te i!us is executed &en a use! executes te ne& ost p!o*!am" Te i!us may include any additional NpayloadO tat is t!i**e!ed &en speci$ic conditions a!e met" 2o! example? some i!uses display a text st!in* on a pa!ticula! date" Te!e a!e many types o$ i!uses includin* a!iants? oe!&!itin*? !esident? stealt? and polymo!pic" i!uses o$ten ae dama*in* side e$$ects? sometimes intentionally? sometimes not" Vir,s :ete6tion soft;are - So$t&a!e &!itten to scan macine-!eadable media on compute! systems" Te!e a!e a *!o&in* numbe! o$ !eputable so$t&a!e pac8a*es aailable tat a!e desi*ned to detect and5o! !emoe i!uses" In addition? many utility p!o*!ams can sea!c text $iles $o! i!us si*natu!es o! potentially unsa$e p!actices" Vir,s si+nat,re - A uniue set o$ ca!acte!s? &ic identi$y a pa!ticula! i!us" Tis may also be !e$e!!ed to as a i!us ma!8e!" Vital "e6or:s - /eco!ds o! documents? $o! le*al? !e*ulato!y? o! ope!ational !easons? cannot be i!!et!ieably lost o! dama*ed &itout mate!ially impai!in* te o!*ani+ationLs ability to conduct business" Voi6e "e6oGer. - Te !esto!ation o$ an o!*ani+ationLs oice communications system" V,lnerabilit. - A &ea8ness in an in$o!mation system o! component e"*"? secu!ity p!ocedu!es? a!d&a!e desi*n? inte!nal cont!ols; tat could be exploited? attac8ed o! $ail" Date
e!sion 1"6
Pa*e '6
Business Continuity Plan
ulne!abilities include susceptibility to pysical dan*e!s? suc as $i!e o! &ate!? unauto!i+ed access to sensitie data? ent!y o$ e!!oneous data? denial o$ timely se!ice? $!aud? etc" 'i:e Area Net;or 'AN - A net&o!8 tat uses i*-speed? lon*-distance communications tecnolo*y e"*"? pone lines and satellites; to connect compute!s oe! lon* distances" Simila! to a A9? except tat pa!ts o$ a 7A9 a!e *eo*!apically dispe!sed? possible in di$$e!ent cities o! een on di$$e!ent continents" Public ca!!ie!s li8e telecommunications ca!!ie!s a!e included in most 7A9sJ e!y la!*e 7A9s may ae inco!po!ate satellite stations o! mic!o&ae to&e!s" 'ar7 Site - An alte!nate p!ocessin* site &ic is only pa!tially euipped As compa!ed to Fot Site &ic is $ully euipped;" 'eb 6a60e - A 7eb cace $ills !euests $!om te 7eb se!e!? sto!es te !euested in$o!mation locally? and sends te in$o!mation to te clientJ te next time te &eb cace *ets a !euest $o! te same in$o!mation? it simply !etu!ns te locally caced data instead o$ sea!cin* oe! te Inte!net? tus !educin* Inte!net t!a$$ic and !esponse time" 'eb site - A location on te 7o!ld 7ide 7eb tat is o&ned and mana*ed by an indiidual? company o! o!*ani+ationJ usually contains a ome pa*e and additional pa*es tat include in$o!mation p!oided by te siteLs o&ne!? and may include lin8s to ote! !eleant sites" 'orl: 'i:e 'eb ''' - A *lobal ype!text system ope!atin* on te Inte!net tat enables elect!onic communication o$ text? *!apics? audio? and ideo" 'or7 - A complete p!o*!am tat p!opa*ates itsel$ $!om system to system? usually t!ou* a net&o!8 o! ote! communication $acility" A &o!m is simila! to a i!us" It is able to in$ect ote! systems and p!o*!ams usually by spa&nin* copies o$ itsel$ in eac compute!Ks memo!y" A &o!m di$$e!s $!om a i!us? in tat a i!us !eplicates itsel$? &ile a &o!m does not" A &o!m copies itsel$ to a pe!sonKs &o!8station oe! a net&o!8 o! t!ou* a ost compute! and ten sp!eads to ote! &o!8stations" A &o!m mi*t duplicate itsel$ in one compute! so o$ten tat it causes te compute! to c!as" Sometimes &!itten in sepa!ate se*ments? a &o!m is int!oduced su!!eptitiously into a ost system? eite! $o! $un o! &it intent to dama*e o! dest!oy in$o!mation" It can easily ta8e oe! a net&o!8? as te Ninte!netO &o!m did" Te Ninte!netO &o!m &as intentionally !eleased into te A/PA9ET p!edecesso! to te inte!net; by /obe!t 4o!!is in 10? as an expe!iment" =nli8e a t!o)an o!se? a &o!m ente!s a system uninited" !O" en+ine9 P!ocess o! set o$ inst!uctions tat calculates data bit !elationsips in a /AI( subsystem"
8
APPEN$ICES
All te items in tis section sould !eceie a sepa!ate appendix" In many cases in$o!mation &ill be *ene!ated $!om te I4S database" 2!euent updates and !eie&s sould be made $o! tis data" A p!inted copy sould be made $o! inclusion in te Business Continuity Plan" Fo&ee!? as tis is te dynamic in$o!mation? te o$$icial !eco!d sould be te I4S" Access to te I4S sould be aailable $!om outside te < Facility.s> no!mal ope!ation location" I4S data sould be sto!ed in a location *eo*!apically sepa!ate $!om < Facility.s> o$$ices" A means to access tis data $!om alte!nate locations sould be in place and tested" Date
e!sion 1"6
Pa*e '1
Business Continuity Plan
Date
e!sion 1"6
Pa*e '#
Business Continuity Plan
APPEN$I! A BUSINESS CONTINUITY PLAN CONTACT INFO"MATION
Date
e!sion 1"6
Pa*e '3
Business Continuity Plan
Tis appendix sould include all points o$ contact o$ positions desc!ibed in te Business Continuity Plan and 8ey o!*ani+ational pe!sonnel" Include ome and mobile telepone numbe!s" Include eme!*ency location assi*nments" Include a telepone t!ee? &ic lists te o!de! o$ contact &en a contin*ency situation o! disaste! is decla!ed" Te contact list sould indicate te system and o!*ani+ation &itin te tat eac indiidual is associated &it" A !e$e!ence list o$ eme!*ency se!ices and public utilities sould be included"
Date
e!sion 1"6
Pa*e ''
Business Continuity Plan
APPEN$I! B EME")ENCY P"OCE$U"ES
Date
e!sion 1"6
Pa*e ',
Business Continuity Plan
Include Eme!*ency P!ocedu!es $o! <=ame> <=ame> and and te 2acility" 2acility" (esc!ibe actions to to be ta8en by employees empasi+in* pe!sonnel sa$ety" sa$ety" Add!ess potential potential scena!ios includin* $i!e? bomb t!eat o! eent? and ciil ciil diso!de!s" Include eacuation p!ocedu!es"
Date
e!sion 1"6
Pa*e '
Business Continuity Plan
APPEN$I! C TEAM STAFFIN) STAFFIN) AN$ TAS@IN)S TAS@IN)S
Date
e!sion 1"6
Pa*e '
Business Continuity Plan
Incl Includ udee a !ost !oste! e! and and list list o$ acti action onss and and !esp !espon onsi sibi bili liti ties es $o! $o! eac eac team team c!ea c!eate ted d by < Facility Facility> > in Section ,"#" Te $ollo&in* is an example o$ t&o tables $o! eac team: Ro*e Business Continuity Plan Coordinator Coordinator 5(eam 5(eam eader Facilities :epresentati#e :epresentati#e 5(o coordinate closely !it) Facility 9n'ineer (ec)nical :epresentati#e 5s
#ame
Pre+ontin,ency Pre+ontin ,ency
Action 1 Action " Disaster ontin,ency ontin,ency Immediate Immediate Res-onse Res-onse
Action 1 Action " Post+ontin,ency Post+ontin ,ency
Action 1 Action "
Date
e!sion 1"6
Pa*e '.
Business Continuity Plan
APPEN$I! $ ALTE"NATE SITE P"OCE$U"ES
Date
e!sion 1"6
Pa*e '0
Business Continuity Plan
Tis appendix sould include detailed p!ocedu!es on standin* up te selected alte!nate sites;" Include contact indiiduals and numbe!s? maps $o! !eacin* te $acility? euipment on site tat sould be b!ou*t on line? euipment !eui!ed $o! p!ocu!ement? telecommunications p!oide!s $o! contact" Te!e sould be sepa!ate p!ocedu!es based on te < Facility.s> maintained aailability o$ a ot site and a cold site"
Date
e!sion 1"6
Pa*e ,6
Business Continuity Plan
APPEN$I! E $OCUMENTATION LIST
Date
e!sion 1"6
Pa*e ,1
Business Continuity Plan
Include a list o$ all <=ame>? , and system documentation pe!tinent to te ope!ation and maintenance o$ eac system" Tis list sould include but is not limited to system a!citectu!e? ope!atin* manuals? system secu!ity plans? !is8 assessments? 4%=s? 4%As? SAs? testin* p!ocedu!es and !esults? system inte!dependencies? asset inento!y? a!d&a!e inento!y? so$t&a!e inento!y? bac8up p!ocedu!es? con$i*u!ation *uidelines? alte!nate site status and inento!y? and standa!d ope!atin* p!ocedu!es" (ocumentation must be deeloped? updated and5o! modi$ied to !e$lect te most cu!!ent in$o!mation and ten ente!ed into an automated (/P !elational database" A copy sould ten be sto!ed at te o$$site sto!a*e $acility" Tis data sould be !eie&ed and modi$ied as can*es occu! &itin te eni!onment"
Date
e!sion 1"6
Pa*e ,#
Business Continuity Plan
APPEN$I! F SOFT'A"E INVENTO"Y
Date
e!sion 1"6
Pa*e ,3
Business Continuity Plan
Tis appendix sould be populated &it te most cu!!ent data tat di!ectly !e$lects te cu!!ent so$t&a!e? bein* tested and ealuated? ope!ational in te acceptance eni!onment pendin* $inal !eie&? implemented in p!oduction? o&ned &ete! onsite o! o$$site ?and deployed by te < Facility>" Tis sould include te licensin* a*!eements" A copy o$ tis data sould be sto!ed at te o$$site sto!a*e $acility alon* &it te Business Continuity Plan" An automated tool could assist &it te deelopment and implementation o$ tis type o$ p!oduct"
Date
e!sion 1"6
Pa*e ,'
Business Continuity Plan
APPEN$I! ) 2A"$'A"E INVENTO"Y
Date
e!sion 1"6
Pa*e ,,
Business Continuity Plan
Tis appendix sould be populated &it te most accu!ate data !e$lectie o$ te a!d&a!e assets cu!!ently o&ned and deployed by te < Facility>" In addition te inento!y o$ te alte!nate site a!d&a!e assets sould be included as &ell" Te pu!case and implementation o$ an automated tool could assist in tis e$$o!t"
Date
e!sion 1"6
Pa*e ,
Business Continuity Plan
APPEN$I! 2 COMMUNICATIONS "EUI"EMENTS
Date
e!sion 1"6
Pa*e ,
Business Continuity Plan
Tis appendix sould include te most accu!ate data associated &it te data and oice communications in place $o! " It sould include an inento!y o$ all communications euipment? dia*!ams and uniuely identi$ied data 7A9 and A9 ci!cuits? data net&o!8 bac8up alte!naties? and oice net&o!8 speci$ications"
Date
e!sion 1"6
Pa*e ,.
Business Continuity Plan
APPEN$I! I -VEN$O" CONTACT LISTS
Date
e!sion 1"6
Pa*e ,0
Business Continuity Plan
Tis appendix sould be populated &it te listin* o$ all endo!s and cont!acto!s tat cu!!ently p!oide suppo!t o! &ill p!oide suppo!t in a post-disaste! eni!onment" Additionally? any Se!ice eel A*!eements SAs; tat ae been executed and all subseuent modi$ications sould be included &it accu!ate Points o$ Contact P%Cs; and eme!*ency contact in$o!mation"
Date
e!sion 1"6
Pa*e 6
Business Continuity Plan
APPEN$I! ( - E!TE"NAL SUPPO"T A)"EEMENTS
Date
e!sion 1"6
Pa*e 1
Business Continuity Plan
Tis appendix sould include documentation $o! se!ice and eme!*ency maintenance a*!eements &it manu$actu!e!s? data sto!a*e $acilities? telecommunications p!oide!s? and sta$$ t!anspo!tation p!oide!s" It sould include points o$ contact and auto!i+ation p!ocedu!es $o! delie!y o$ se!ices"
Date
e!sion 1"6
Pa*e #
Business Continuity Plan
APPEN$I! @ - $ATA CENTE"/COMPUTE" "OOM EME")ENCY P"OCE$U"ES AN$ "EUI"EMENTS
Date
e!sion 1"6
Pa*e 3
Business Continuity Plan
Tis appendix sould include additional eme!*ency p!ocedu!es $o! all secu!ed data cente! o! compute! !oom $acilities ostin* systems" In$o!mation on $i!e? smo8e? &ate!? and int!usion ala!ms sould be included" Po&e! do&n p!ocedu!es sould be included" 2acility layout? po&e! !eui!ements? cable dia*!ams? and media connection outlets sould be included" A (ata Cente! inento!y sould be ext!acted $!om Appendixes 2? D? and F and included in tis appendix"
Date
e!sion 1"6
Pa*e '
Business Continuity Plan
APPEN$I! L - PLAN MAINTENANCE P"OCE$U"ES
Date
e!sion 1"6
Pa*e ,
Business Continuity Plan
Tis appendix sould include te $!euency o$ !eie& $o! te plan" It can be diided into static in$o!mation and dynamic in$o!mation" Tis !esponsibility sould be assi*ned to an indiidual associated &it te Business Continuity Plan and included in tei! o$$icial )ob desc!iption"
Date
e!sion 1"6
Pa*e
Business Continuity Plan
APPEN$I! M - CONTIN)ENCY LO)
Date
e!sion 1"6
Pa*e