Disaster Recovery (DR) and Business Continuity (BC)

Although often used together, disaster recovery (DR) and business continuity (BC) are distinct processes.

8 slides · 4 min read · Domain 6

Slide 1

Security process data related to BC and DR will be of great interest to control assessors, as well as others engaged in supporting and improving business processes.

Compliance Requirements

The broad standards expect organizations to conduct appropriate BC and DR planning. This is a risk-driven process and requires formal risk assessment and planning processes to be applied in the development of an organization's plans.

Several well-established bodies of practice exist to support organizations in developing institutional resilience. NIST Special Publication 800-34, "Contingency Planning Guide for Federal Information Systems," provides a roadmap for BC and DR planning in the U.S. government. ISO 27301, Business Continuity Information Systems, is among several different ISO publications addressing continuity planning for information systems.

It aligns with the broad ISO 22301, Business Continuity Management Systems, which established good practice for the larger business implications and activities of resilience.

Many industry sectors also have specific compliance expectations for their industry. Industry sectors such as financial services, nuclear power, aviation and other critical infrastructure operators place very high resilience expectations on the regulated entities. In most of the critical infrastructure environments, a full-scale demonstration of the resilience of the infrastructure is required on a regular basis, with the documented results being included as part of the organization's auditing and licensure activities.

BC/DR Testing and Training Processes

As with backup processes, BC and DR practices vary greatly depending on the industry and systems being protected. However, the performance of BC and DR testing and training activities are of particular interest to the security assessor. The documentation of these activities | is another type of the security process data on which an organization will base its continual process improvement activities and demonstrate to assessors and auditors the effectiveness of its security controls.

Once the organization has identified its compliance objectives and business goals for resilience, it will establish an organizational resilience practice.

This may be done under a variety of different names, but the overarching goal is to minimize the impact of business disruption and return the organization to an acceptable state of performance following a disaster.

The subsequent planning and resourcing of the BC and DR activities is the responsibility of the respective information systems owners, as they are the ones ultimately accountable for these assets. Based on the results of the business impact analysis of the individual systems, continuity activities will be performed to decrease the likelihood and consequence of system failure, and separately, recover the systems) from a disaster.

The plan, as an artifact, is certainly useful to demonstrate organizational commitment, but the true test of the plan is showing that the organization can actually execute the plan.

Complicating the challenge is a well-established dictum of BC and DR: The disaster you get is never the disaster you plan for.

Consequently, training the organization's team in the conduct of recovery is essential to success.

The BC plan must establish a training program that addresses the organization's obligations and goals, its current and target states of resilience, and the methods and schedules of the training to be conducted. The training activities should be conducted with progressive complexity and organizational breadth.

This allows the evaluation of the organization's performance as it completes one event to shape and improve the subsequent events.

Training Event

Desk check

Walk-through

Tabletop Exercise

Simulation Activities

Review operational documentation, rosters, personal availability and version of DR plan

Using desk manuals, have DR teams explain their roles and activities

Team leaders across the organization are presented with a disaster scenario and discuss their response

A disaster event is simulated outside the production environment. DR activities are performed within the simulation to recover organizational capabilities

Expected Results

All staff has current plan and documentation

Concurrence in the DR teams that they understand their role relative to each other, and deconflict any overlapping roles

Deconfliction of team roles and responsibilities. Identification of major plan weaknesses

Demonstration of the

recovery capabilities within the context of the scenario

Parallel

Full Cutover A disaster event is simulated while production activities are ongoing.

A disaster event is invoked which will affect the production environment.

Demonstration of the full recovery capabilities without disruption of the production environment

Recovery of the production environment within established organizational parameters

Progressively Complex Training Activities

Test this domain