CBK#8 Business Continuity Planning & Disaster Recovery Planning

Page 3

CBK#8 BCP & DRP - Page 1 2 3 4

    - Cold site
Is ready for equipment to be brought in during emergency, but no hardware resides at the site.
Advantages is low cost.
Disadvantage is that it may not work when a disaster strikes.

- Multiple centers:
The processing is spread over operations centers, creating a distributed approach to redundancy and sharing of available resources.
Advantage is low cost.
Disadvantage is that a major disaster could easily overtake the processing capability of the sites.

- Service bureaus:
Contract with a service bureau to provide all alternate backup processing services.
Advantage is quick response and availability
Disadvantage is the expense and resource contention during a large emergency.

- Other data center backup alternatives:
    - Rolling/mobile backup sites
    - In-house or external supply of hardware replacements
    - Prefabricated buildings

Three concepts used to create a level of fault tolerance and redundancy in transition processing:
- Electronic vaulting:
Refers to the transfer of backup data to an off-site location. This is primarily a batch process of dumping the data through communications lines to a server at an alternative location.
- Remote journaling:
Refers to the parallel processing of transactions to an alternate site. A communication line is used to transmit live data as it occurs.
- Database shadowing:
Uses the live processing of remote journaling but creates even more redundancy by duplicating the database sets to multiple servers.

Data Recovery Plan Maintenance:
Keeping the plans up-to-date and relevant.

Testing the DRP / Disaster Recovery Plan:
Types of test types -
- Checklist:
Copies of plan are distributed to management for review.
- Structured Walk-Through:
Business unit management meets to review the plan.
- Simulation Test:
All support personnel meet in a practice execution session.
- Parallel Test:
Critical systems are run at an alternate site.
- Full-Interruption Test:
Normal production shut down, with real disaster recovery processes.

CBK#8 BCP & DRP - Page 1 2 3 4

CISSP Summary 2002Related links | References

CBK#1 Access Control Systems & Methodology | CBK#2 Telecommunications & Network Security | CBK#3 Security Management Practices | CBK#4 Applications & Systems Development Security | CBK#5 Cryptography | CBK#6 Security Architecture & Models | CBK#7 Operations Security | CBK#8 Business Continuity Planning & Disaster Recovery Planning | CBK#9 Law, Investigations & Ethics | CBK#10 Physical Security

Contact:

E-mail: john.wallhoff@mailbox.swipnet.se
Written by: J.Wallhoff January - April 2002
Updated by: J.Wallhoff April 2002