CBK#8 Business Continuity Planning & Disaster Recovery Planning

CBK#8 BCP & DRP - Page 1 2 3 4

BCP / Business Continuity Planning
Prime elements:
- Scope and Plan Initiation
- Business Impact Assessment
- Business Continuity Plan Development
- Plan Approval and Implementation

Scope and Plan Initiation:
Marks the beginning of the BCP process
It entails creating the scope for the plan.

Roles and Responsibilities -
The BCP Commitee:
Should be formed and given the responsibility to create, implement and test the plan.
Is made up of representatives from senior management, all functional business units, information systems and security administrator.
Senior Management's Role:
Is ultimate responsible for all four phases of the plan.

BIA / Business Impact Assessment:
Is a process used to help business units understand the impact of a disruptive event.
The impact may be financial (quantitative) or operational (qualitative, such as the inability to respond to customer)
A vulnerability assessment is often a part of the BIA process.
It identifies the company's critical systems needed for survival and estimates the outage time that can be tolerated by the company as a result of a disaster or disruption.

Three main primary goals of BIA -
- Criticality Prioritization:
Every critical business unit process must be identified and prioritized and the impact of a disruptive event must be evaluated.
- Downtime Estimation:
Estimates the MTB / Maximum Tolerable Downtime that the business can tolerate and still remain a viable company.
- Resource Requirements:
The resource requirements for the critical processes are also identified at this time, with the most time-sensitive processes receiving the most resource allocation.

Four steps of BIA -
- Gathering the needed assessment materials:
Identifying which business units is critical to continuing an acceptable level of operations.
- Performing the vulnerability assessment:
Is smaller than a full risk assessment and is focused on providing information that is used solely for the BCP or DRP.
A function is to conduct a loss impact analysis.
Critical support areas must be defined.
- Analyzing the information compiled:

CBK#8 BCP & DRP - Page 1 2 3 4

CISSP Summary 2002Related links | References

CBK#1 Access Control Systems & Methodology | CBK#2 Telecommunications & Network Security | CBK#3 Security Management Practices | CBK#4 Applications & Systems Development Security | CBK#5 Cryptography | CBK#6 Security Architecture & Models | CBK#7 Operations Security | CBK#8 Business Continuity Planning & Disaster Recovery Planning | CBK#9 Law, Investigations & Ethics | CBK#10 Physical Security

Contact:

E-mail: john.wallhoff@mailbox.swipnet.se
Written by: J.Wallhoff January - April 2002
Updated by: J.Wallhoff April 2002