-
So today, we are from Group 10.
-
We will continue to present on Chapter 6
-
under Subtopic 6.5:
-
Disaster Recovery and Business
-
Continuity Planning and Auditing.
-
Assalamu Alaikum,
-
and hi, everyone.
-
We are from BlueTech.
-
In this video, we will present about
-
disaster
-
recovery and business continuity
-
planning and auditing.
-
First, of course, my name is Intan Sanwa
-
Binti Mahasi,
-
matric number 268061, and
-
I'm the first presenter. I will present
-
the definition,
-
purpose, and the main aspects of BRP.
-
Alright, I will proceed for the
-
definition part.
-
Disaster. What is disaster? Disaster is
-
disruptions that cause critical
-
information resources to be inoperative
-
for a period of time.
-
Disaster can be caused because of
-
environmental conditions,
-
system failure, or equipment failure,
-
or disaster can also be man-made. Any
-
incident that can takes more than
-
a suitable amount of time
-
to recover, or if it has more than an
-
acceptable range
-
of consequences, can be called a
-
disaster.
-
The examples of disaster are weather,
-
terrorism, disruption in expected services,
-
human error, and so on.
-
Disaster can be short or may last for a
-
long time,
-
but when an organization is ready for
-
any adversity, it strives hard and survives.
-
Disruption can lead to lost revenue,
-
brain damage,
-
and dissatisfied customers. And the
-
longer the recovery time,
-
the greater the adverse business impact.
-
Therefore, a good disaster recovery plan
-
should enable rapid recovery from
-
disruptions,
-
regardless of the source of the
-
disruptions.
-
The business continuity plan includes,
-
first, the disaster recovery plan, that is
-
generally the plan to be followed
-
by the business units to recover a harmed
-
or demolished
-
facility, or business functionality,
-
or an operational facility. Then, the
-
operation
-
plan, that is to be followed by the
-
business units
-
to get by while recovery is taking place.
-
Everything is the same as in the case of
-
the business continuity planning
-
or disaster recovery plan, with the
-
exception
-
that the continuity of the information
-
system processing is threatened.
-
Information system processing is one
-
operation
-
of many that keeps the organization not
-
only alive but also successful,
-
thus it is of strategic importance.
-
Thus, the event to be controlled is such
-
a disruption, that the objective
-
of the control measure is to survive an
-
interruption of the information system
-
processing.
-
Throughout the planning process of
-
business continuity,
-
the overall plan of the organization
-
should be taken into consideration.
-
All its plans must be consistent with
-
and support the corporate business
-
continuity plan.
-
This means that, especially those
-
information processing systems,
-
must have them more elaborated and ready
-
to start reserve processing facilities
-
that support key operations.
-
Next, the purpose and main aspects of DRP.
-
The purpose of DRP is to enable a business
-
to continue
-
offering critical services in the event
-
of a disruption
-
and to survive even a disastrous
-
interruption of
-
its activities. Next is the main aspects
-
of BRP
-
that business continuity planning has to
-
take into consideration.
-
First, the market and strategic goals of
-
the corporation.
-
Second, the strategic business processes.
-
Third, those key operations that are most
-
necessary to the survival
-
of the organization and the human or
-
material resources supporting them.
-
In the business continuity plan, it
-
includes
-
the disaster recovery plan to recover a
-
facility rendered
-
inoperable, including relocating
-
operations
-
to a new location, and the restoration
-
plan that is used to return operations
-
to normal, whether in a restored or
-
new facility, which is only after
-
mitigating the effect of your disruption
-
by restarting the business applications
-
involved.
-
That's all for my part. I will pause for
-
the next presenter.
-
Thank you.
-
Assalamu Alaikum, my name is Nur Athirah Haziqah Binti Mohd Said
-
and my matric is number is 264828. And I will
-
continue to present the objective of
-
Disaster Recovery Planning.
-
So, the first objective is to minimize
-
interruptions to the normal operations.
-
Which means by having this disaster
-
recovery planning,
-
we can minimize any problems of
-
disruptions that might be happen
-
later on to the normal operations. The
-
second objective is to limit the extent
-
of disruptions and damage.
-
Why limit the extent of disruptions and
-
damage? Because by having this DRP,
-
we can ensure that the disruptions does
-
not spread to any unrelated things,
-
so we can limit it. The third objective
-
is to minimize the economic impact of
-
the interruption.
-
For example, as nowadays, during this
-
COVID-19 pandemic,
-
when a company has this disaster
-
recovery planning, so the company has a
-
backup plan on how the company will
-
operate normally as usual.
-
Maybe in terms of meeting, they can do an
-
online meeting
-
so it can minimize the
-
economic impact due to the interruptions.
-
This is because they can continue
-
operate the company as usual
-
and the economic growth will not be
-
affected. The fourth objective is to
-
establish alternative means of operation
-
in advance.
-
Which means by having this DRP, it can
-
provide a planning with effective medium
-
of solutions globally,
-
if anything happens later on. The fifth
-
one
-
is to train personnel with emergency
-
procedures for example
-
when cyber attacks suddenly happen so
-
when a company applying this drp
-
the personnel know the action to be
-
taken after the cyber attacks happen
-
it's something like early preparation
-
the management also
-
should regularly train the employees
-
about how to prepare
-
for a data breach or to avoid a data
-
bridge in the first place
-
the last one is to provide for smooth
-
and rapid restoration of service
-
so when having this disaster recovery
-
planning it can provide a smooth and rev
-
restoration because this drp continue
-
offering critical services in the event
-
of the
-
offer disruptions and to survive uh
-
even these risers disastrous
-
interruptions
-
uh to its activities so the next one is
-
the components of disaster recovery
-
planning
-
so the next one is the components of
-
disaster recovery planning the first one
-
is
-
create a disaster recovery team this
-
team will be responsible for developing
-
implementing and maintaining the drp all
-
employees should be informed of and
-
understand the
-
disaster recovery planning and their
-
responsibility
-
if any disaster occurs when having
-
this drp team the management will refer
-
straight to this team
-
easily when any disaster occurs as this
-
team will be responsible
-
to inform and give understanding to all
-
employees
-
what action they should be taken when
-
any disasters
-
occurs so the second one identify and
-
access disaster risk
-
the disaster recovery team should
-
identify and assess
-
the risk to organization also assist the
-
team in identifying the recovery
-
strategies and resources
-
required to recover from disasters
-
within a predetermined and acceptable
-
time frame
-
which means after the drp team
-
identified as a series
-
then they will provide a planning with
-
effective medium of solution
-
globally if anything happen later on
-
so the third one is determine critical
-
applications
-
documents and resources the plan should
-
focus on
-
short-term survivability such as
-
generating cash flows and revenues
-
rather than on a long-term solution of
-
restoring the organization's
-
full functioning capacity the
-
organization must recognize
-
some processes that should not be
-
delayed if possible for example like
-
processing of payroll
-
in simple word i can say that when they
-
want to build a grp
-
so it should focus on short-term
-
planning to ensure that the company
-
survive rather than planning a long-term
-
long-term planning all the docu all the
-
important documents must not be delayed
-
such as the processing of payroll
-
the fourth one is specified bake-up and
-
off-site storage procedures
-
all critical equipment applications and
-
documents
-
should not be baked should be backup
-
what need what need to be backup
-
such documents like the latest
-
punishment statements
-
tax returns inventory records customer
-
and vendor listings
-
critical supplies required for daily
-
operations like checks and also the
-
purchase order
-
all critical supplies and a copy of the
-
drp should be stored at
-
at an off-site location which means
-
which
-
locate all the backup data away from the
-
client's main premises
-
so the last one is test and maintain the
-
drp
-
the organization routinely test the drp
-
to evaluate
-
the procedures documented in the plan
-
for effectiveness and appropriateness
-
the recovery team should regularly
-
update the grp
-
to accommodate for changes in business
-
processes
-
technology and evolving disaster risk so
-
basically
-
test of drp is important to establish if
-
the recovery objectives are achievable
-
maybe to improve any recovery processes
-
and to familiarize
-
start with the recovery processes this
-
test will be explained more details by
-
the next presenter
-
assalamualaikum and hi everyone my name
-
is
-
number 259065 so i will continue the
-
presentation regarding the disaster
-
regarding disaster recovery testing okay
-
so the purpose of it disaster
-
recovery testing is to discover flaws in
-
your disaster recovery plan
-
so you can resolve them before they
-
impact your ability to restore
-
operations in other words disaster
-
recovery testing
-
allows you to identify potential errors
-
and issues
-
and develop solutions so that in a real
-
disaster
-
your business will be able to
-
re-establish critical operations
-
okay there are about five types of
-
disaster recovery testing
-
including walk-through test cut of a
-
test paper test
-
simulation and parallel tests let us
-
start with the first one walkthrough
-
test
-
in this test several business and
-
technology experts
-
in the organization will gather to walk
-
through the drp
-
to discuss each step in the drp so that
-
they can
-
identify issues and opportunities for
-
making the
-
drp more accurate and complete
-
next kind of a test a kind of a test is
-
to test fail over recovery systems built
-
to take over the full production
-
workload in case of disaster
-
primary systems are
-
disconnected during the test next paper
-
test
-
in a paper test members of the dr team
-
read
-
and testify recovery plan documents such
-
as
-
vr policies procedures timelines
-
benchmark and checklist a hard copy of
-
documents should
-
be stored in a secure offline
-
environment and a digital copy in the
-
cloud
-
simulation is a simulated disaster in
-
which teams
-
must go through their documented
-
recovery plans to identify where the
-
emergency response
-
plans are educated another idea is to
-
hold the simulation
-
on a day that is not
-
announced ahead of time so that
-
respondents
-
uh possibly be less prepared to respond
-
this is a very real simulation uh
-
because in fact
-
anyone do not know when the catastrophe
-
may
-
occur this is very important actually
-
for the teams
-
to practice the drp in real life to make
-
sure that it's sufficient for it
-
disaster recovery like fire drill
-
for example parallel test in apparel
-
test
-
fall over recovery systems are tested to
-
make sure that in case of disaster they
-
can perform
-
real business transactions supporting
-
key processes and applications
-
meanwhile primary systems continue to
-
run the
-
full production would load
-
okay so next why does a drp require
-
testing
-
the reason is because to exercise the
-
recovery processes and procedures
-
next to familiarize staff with the
-
recovery process
-
and the end documentation verify the
-
effectiveness of the recovery
-
documentation
-
verify the effectiveness of the recovery
-
site
-
establish if the recovery objectives are
-
achievable
-
identify improvements required to the dr
-
strategy
-
infrastructure and recovery processes
-
hi yes america my name is nisha raventi
-
mohammed shui my metric number is 26105
-
i will continue within its sub topics
-
which are recovery time objective
-
rto and recovery point objective rpo
-
i will also explain the differences
-
between these two recovery objectives
-
now let's start with rto
-
so what is recovery time objective
-
recovery time objective
-
rto is the duration of time and a
-
service level
-
within which a business process must be
-
restored
-
after a disaster in order to avoid any
-
unacceptable consequences
-
associated with a break in continuity in
-
other words the rto is the answer to the
-
question
-
how much time did it take to recover
-
after notification of business process
-
disruption in addition rto designates
-
the variable amount of data that will be
-
lost
-
or will have to be re-entered during
-
network downtime
-
rto also decides the amount of real time
-
that
-
can pass before the disruption begins to
-
seriously and
-
acceptably impede the flow of normal
-
business
-
operation
-
for example if rto is 24 hours it means
-
the organization determined that
-
the business can maintain operations for
-
the amount of the time
-
without having its normal data and
-
infrastructure available
-
so if the data and infrastructure are
-
not recovered within 24 hours
-
the business could suffer irreparable
-
harm
-
now let's move to the next recovery
-
objective
-
the next recovery objective is recovery
-
point objective
-
or rpo i will discuss briefly about rpo
-
in the next slides
-
what is rpo rpo is a measurement of the
-
maximum tolerable amount of data to lose
-
in other words rpo measures how much
-
data you can afford to lose
-
as the result of a disaster rpo can help
-
the organization to measure how much
-
time
-
can occur between last data backup and a
-
disaster without
-
causing serious damage to the business
-
on top of that
-
rpo is very useful for an organization
-
to determine how often to perform data
-
backups
-
so most businesses back up data at fixed
-
intervals of time such as
-
once every hour once every day or
-
infrequently as once every week
-
example of rpo is if the last available
-
good copy of data open and out age
-
is from 80 hours ago and the rpo for the
-
business is 20 hours
-
then the organization is still within
-
the parameters of the business
-
continuity plans
-
rpo in other words it answers the
-
question
-
of up to what point in time could a
-
business process
-
recovery proceed tolerably given the
-
volume
-
of data loss during the interval
-
so recovery time objective rto and
-
recovery point objective rpo
-
are two of the most important parameters
-
of a disaster recovery or data
-
protection plan
-
these are objectives that can guide
-
enterprises to choose an optimal cloud
-
backup and disaster
-
recovery plan the rpo or rto along with
-
the business impact analysis
-
provides the basis for identifying and
-
analyzing viable strategies
-
for inclusion in the business continuity
-
plan viable strategy options include any
-
which
-
would enable resumption of a business
-
process
-
in a time frame at or near the rpo or
-
rto
-
at first glance these two terms appear
-
to be quite similar
-
however there are some differences
-
between these two recovery objectives
-
now let's differentiate these two
-
recovery objectives in the next slide
-
the first difference between rto and rpo
-
is
-
rto has a broader purpose as it focuses
-
more on downtime
-
of services applications and process
-
this is because rto sets the boundaries
-
for the whole business
-
continuity management while rpo focuses
-
only on the issue of
-
backup frequency other than that rto
-
concern with applications and systems
-
the measurement includes data recovery
-
but primarily
-
describes time limitations on
-
application downtime
-
on the other hand rpo only corresponds
-
with the amount of data that is lost
-
following a failure event furthermore
-
rto looks forward in time where it
-
focuses on the amount of time the
-
organization need
-
in order to resume the operations while
-
rpo
-
looks back in time where it focuses on
-
the amount of time or data that the
-
organization are willing to lose that's
-
all from me i will pass to the next
-
presenter
-
okay next i'm going to explain on the
-
types of disaster recovery plan
-
they are a variety of disaster recovery
-
plans actually
-
but i'm going to focus on the two types
-
while the other types
-
will be covered by my other teammates
-
letter and the it recovery plan
-
okay the first type that i'm going to
-
cover is called virtualization disaster
-
recovery
-
it is actually a way to decrease the
-
amount of time
-
or reduce the time needed to perform a
-
full
-
restoration after they have been hit by
-
a disaster
-
so what does it mean by virtualization
-
virtualization by definition is the
-
process
-
of creating a virtual version of a
-
system
-
or a software or even an entire working
-
environment rather than creating a
-
physical
-
replica it can eliminate the need to
-
recreate a physical server when
-
something goes wrong
-
how by creating a multiple simulated
-
environments
-
or dedicated resources using a single
-
hardware system
-
it also helps you split a single system
-
into multiple distinct environments
-
called virtual machines
-
the physical system on which the various
-
virtual virtual machines are created is
-
called the host
-
and the virtual machines are called gas
-
okay next is network disaster recovery
-
a network disaster recovery plan is a
-
set of policies and procedures that
-
ensure a network is reinstated to
-
its normal working operations after it
-
goes offline
-
or is disrupted after it after a
-
disastrous event
-
it is a type of a disaster recovery plan
-
that is specifically designed for
-
internet
-
and external natural infrastructure of
-
an organization
-
network disaster recovery plan generally
-
requires
-
listing this tab which should be
-
undertaken in order to restock network
-
connectivity
-
identifying people responsible for
-
conducting natural disaster recovery
-
assessing possible consequences of a
-
natural failure
-
last but not least determining the best
-
strategies to mitigate them
-
the main purpose of network disaster
-
recovery is to ensure that
-
business services can be delivered to
-
customers
-
despite a disruption in network
-
connectivity
-
however disasters come in different
-
forms and sizes
-
which makes it which makes it hard
-
to predict what their impact would be
-
which network
-
components would be affected and how
-
many resources
-
would be required to restore network
-
connectivity
-
therefore the best strategy for ensuring
-
a successful
-
natural disaster recovery is by
-
preparing for the worst case scenarios
-
in advance and finding the ways to
-
mitigate their impact
-
uh possible causes of nature failures
-
include human errors
-
and network attacks human errors we can
-
say that
-
sometimes network connectivity problems
-
might be the result of mistakes made by
-
employees when working with network
-
equipment
-
or manually configuring network
-
components without an educated graph
-
of knowledge while natural attacks
-
is a network services that can get
-
disrupted
-
after a cyber attack whose aim is to
-
prevent the organization
-
to deliver its services by forcing it to
-
shut down
-
the next one is i.t disaster recovery
-
plan
-
so the next one is i.t disaster recovery
-
plan
-
an information technology disaster
-
recovery plan should be developed in
-
conjunction with the business continuity
-
plan
-
business continuity plan is a process a
-
company undergoes to create a prevention
-
and recovery system from potential
-
threats such as natural disasters or
-
cyber attacks
-
bcp is designed to protect personnel and
-
assets
-
and make sure that they function quickly
-
when disaster occurs priorities and
-
recovery time objectives
-
for information technology should be
-
developed during the business impact
-
analysis
-
which means the company must know the
-
reason
-
why they want to develop the disaster
-
recovery plan
-
technology recovery strategies should be
-
developed to restore hardware
-
applications and data in time to meet
-
the needs
-
of the business recovery in the simple
-
word
-
the management must provide a planning
-
with effective strategies or solutions
-
globally if anything happen later on to
-
ensure that the company can
-
run smoothly as normal
-
so the next part is the information
-
technology recovery strategies
-
basically these strategies should be
-
developed for iot systems
-
applications and data i.t resources
-
required to support time-sensitive
-
business functions
-
and processes should also be identified
-
the recovery time for an it resource
-
should match the recovery time
-
objective for the business functions or
-
process
-
that depends on the i.t resource
-
the next one is components what
-
components related to this idea of
-
disaster recovery planning
-
the first one is computer room
-
environment which is
-
secured computer room with climate
-
control if i'm not mistaken
-
climate control is a temperature control
-
which fitted the computer room
-
environment
-
maybe the temperature is not too low and
-
not too high
-
the second one is hardware for example
-
like networks
-
servers desktops laptop computers and
-
also the wireless devices
-
the third one is connectivity to a
-
service provider for example like fiber
-
cable wireless and etc the first one is
-
software applications for example like
-
electronic data interchange electronic
-
mail
-
enterprise resource management and also
-
office productivity
-
the next one is data and restorations
-
data restore is the process of
-
copying backup data from secondary
-
storage
-
and restoring it to its original
-
locations or a new locations so the next
-
part is developing an i.t disaster
-
recovery plan
-
the first one is compiling an inventory
-
of hardware
-
software applications and data which is
-
gathering the hardware like laptop or pc
-
which comes with wi-fi connectivity and
-
also
-
software needed like maybe cloud or any
-
other important software needed
-
the second one is ensure that all
-
critical information
-
is being backup critical information is
-
something like
-
latest financial statements tax returns
-
inventory records
-
customer and vendor listings and also
-
critical supplies that required for
-
daily operations like
-
checks and purchase orders is being
-
makeup by using this
-
i.t disaster recovery plan
-
the third one is identify critical
-
software applications and data
-
and the hardware required to run them
-
maybe in terms of software like
-
maybe in terms of software needed like
-
electronic mail network
-
servers or maybe like wi-fi to ensure
-
that it have connectivity to a service
-
provider
-
the fourth one is using standardized
-
hardware that will help to replicate and
-
re-image
-
new hardware the next one ensure that
-
copies of program software are available
-
to enable
-
re-installations on replacement
-
equipment
-
the next one document the i.t disaster
-
recovery plan
-
as part of the business continuity plan
-
because
-
business business continuity requires a
-
company
-
to keep operations functional during the
-
event
-
and immediately after and immediately
-
after
-
while disaster recovery focuses on how
-
you respond
-
after the event has completed and how a
-
company
-
would return to normal operation
-
the next one test the planet
-
periodically to make sure that it works
-
this test is also to ensure that it work
-
and to identify improvements required
-
to the itdrp strategy infrastructure and
-
recovery processes okay last but not
-
least we're going to talk about iodine
-
program for the rp
-
the objective is to evaluate documented
-
processes and procedures
-
for ic for is disaster preparedness
-
compliance
-
and to ensure the continuance of key
-
business functions in the event of a
-
disruption
-
the scope of this audit included to
-
ascertain the existence and
-
effectiveness of the current is disaster
-
recovery
-
plan and its alignment with the
-
enterprise business continuity plan
-
policies and procedures next to evaluate
-
ies functions preparedness in the event
-
of a process disruption
-
last but not least to determine
-
compliance with applicable federal laws
-
and regulations
-
there are many audit programs for the rp
-
actually but
-
i only listed about five audit programs
-
including audit
-
and validate the adequacy of the backup
-
data
-
well actually it does not matter how
-
good your disaster recovery plan
-
is if your data is out of date if in a
-
location
-
also affected by the disaster or has
-
become corrupted
-
next audit and validate the testing of
-
the disaster recovery plan
-
companies need to make sure the recovery
-
plan actually works
-
in an emergency regularly conduct data
-
fight drills to test
-
every possible scenario from basic power
-
failures
-
to catastrophic events that could result
-
in multiple months of devastation
-
next audit and validate passwords are
-
available to the disaster
-
recovery plan team password protection
-
is a key goal for data security
-
companies need to store
-
system passwords in at least two
-
geographically separate
-
secure locations make sure that more
-
than i.t
-
staff more than one active staff person
-
has access to all password encode
-
change this password promptly if key
-
president leave the company
-
next audit and validate the disaster
-
recovery plan is up to date
-
once a plane once a plan is created it
-
needs to be
-
revised at least
-
on a quarterly basis last but not least
-
audit and validate there is physical
-
documentation of the disaster
-
recovery plan after creating a plan
-
ensure that every process is well
-
documented
-
describe the location of all system
-
resources needed to accomplish the
-
recovery
-
store the documentation at multiple
-
locations
-
paper and electronic and verify that all
-
key personnel have easy access to the
-
manuals
-
so that's all from us thank you