Planning Factors for Business Continuity and Disaster Recovery
Creating a business continuity and disaster recovery plan involves identifying critical operations, assessing risks, defining recovery strategies, and establishing procedures to maintain or quickly resume essential services.
5 slides · 4 min read · Domain 1
The business impact analysis
To properly provide the correct assets for dealing with contingency situations, (BIA) provides the foundation to the organization must determine several determine the overall scope and essential elements first:
extent of the business continuity and disaster recovery (BCDR) plans. • What is the critical path? From one perspective, these plans must protect assets on critical paths of critical business functions, or provide access to temporary replacements, substitutes, or workarounds for their period of nonavailability. These plans are used to prepare for a selected set of contingencies, but they are not the procedures that instruct the organization how to start responding to these contingencies and begin continuity operations.
- How long can the organization survive an interruption of that critical path?
- How much data can the organization lose and remain viable?
All of these are driven by one central idea:
be identified. The RTO is the target time how much damage, downtime, or loss of set for recovering from any interruptionfunction the organization's senior leaders the RTO must necessarily be less than the are willing to tolerate. MAD. Senior management must set the RTO, based on their expert knowledge Keep in mind that as thresholds, of the needs of the organization, and all BCDR strategy and plans must support these are often set by analysis, achieving the desired RTO. The term modeling, experience, and
"recovery" in the context of the RTO is not
perceptions about the marketplace
a return to normal operations, but it is in which the organization instead a goal for recovering availability of participates.
the critical path of functional capabilities and services. This is a temporary state
Risk appetite or risk tolerance are other that the organization will endure until it is ways of expressing this concept. The result feasible to return to regular status.
of senior management's deliberations should be to provide to the designers and
- The recovery point objective (RPO)
builders of the BCDR plans the three control is a measure of how much data the parameters that follow: organization can lose before it constitutes an unacceptable disruption to the
- The maximum allowable downtime (MAD),
organization's mission or business. The also referred to as the maximum tolerable
RPO is usually measured not in storage downtime (MTD) or maximum allowable amounts (gigabytes, terabytes, or outage (MAO), is the amount of time that petabytes), but instead in units of timethe mission or business process can be minutes, hours, days-depending on disrupted without causing significant or the nature of the organization. This is unacceptable harm to the organization's generally measured as the amount of mission.
time between the last good backup and when the disruption event occurs. Senior
- Obviously, returning to operations close to
management will also set the RPO that the MAD is also not advised, which is why will be used along with the RTO to inform the recovery time objective (RTO) must
BCDR plans.
These are, of course, planning targets, and their sequence in time is shown in the figure. During the planning stages, they are used to help management determine whether certain BCDR activities need to be better resourced or placed at a higher priority or urgency. Real-world experience clearly demonstrates that many, many organizations do not expire the moment after the MAD window does; nor do they cease to be viable businesses or government service organizations because the RPO that they planned with has been far outstripped by the actual data losses suffered during a major disruption.
Prior to the MAD point, there is the RTO point, and obviously there is a cost to this decision.
The quicker we define when operations are to be resumed, the higher the cost of the BCDR solution we will have to implement.
The last component influencing the choice of a BCDR solution is the RPO. When discussing a financial institute, for example, we cannot lose even a minute of data. When operations are resumed, we must have the same data we had at the second of interruption. But in other industries, there is more tolerance to data loss. Obviously RPO also affects the choice of the recovery site implemented.
Finally, there is Work Recovery Time (WRT). This is the period during which the newly restored systems, software, connectivity, and databases are used to work off transactions or operational backlogs that have been building up since the last good backup was taken-since all of the data from that moment (the left-hand edge of the RPO window) until the systems are declared operationally stable and ready for use has been waiting to be processed.
Text on this slide
RPO RTO -
Time
Stage 1 Business as Usual Stage 2 Disaster Occurs
Figure: Disaster recovery planning timeline factors
MTD
Stage 3 Recovery
- WRT
Stage 4 Resume Production
