Disaster and Recovery

13
Disaster and Recovery

description

Disaster and Recovery. Shawn Kirkland. Overview. Business Impact Analysis System Description/Purpose Impact to business if degradation Estimated Downtime Resource Requirements. Business Contingency Plan Incident Response Policy Purpose Identifying and Reporting Incidents - PowerPoint PPT Presentation

Transcript of Disaster and Recovery

Page 1: Disaster and Recovery

Disaster and Recovery

Page 2: Disaster and Recovery

Business Impact Analysis System Description/Purpose Impact to business if degradation Estimated Downtime Resource Requirements.

Business Contingency Plan Incident Response Policy

Purpose Identifying and Reporting Incidents Mitigation and Containment

Questions?

OverviewShawn

Kirkland

Page 3: Disaster and Recovery

Purpose Determine mission/business processes and recovery

criticality. Identify resource requirements. Identify recovery priorities for system resources.

System Description/Purpose Impact to business if degradation Estimated Downtime Resource Requirements.

Business Impact AnalysisShawn

Kirkland

Page 4: Disaster and Recovery

Operating System Microsoft Windows Server 2008 R2

Application Microsoft SQL Server 2008 Enterprise Edition

Hardware Dell R720

Location Server Rack on second floor server room.

Connection System Administrator connects via local area network. Other users connect remotely

DR Method 1 Full backup weekly and dailies every day. 3 hours after close of business.

System DescriptionShawn

Kirkland

Page 5: Disaster and Recovery

ImpactMission/Business Process Description

Query customer record Database retrieval of customer information (e.g. address, phone, payment information)

Store customer transaction Recording of customer purchases and creditsAuthenticate user name and

password Stored procedure verifying user credentials

Impact values Severe = $100,000 Moderate = $50,000 Minimal = $10,000

Mission/Business Process

Impact Category

MinimalModerat

e High Severe Impact

Query customer record x       MinimalStore customer

transaction   

  x Severe

Authenticate user name and password  

x    Moderat

e

Jamarcus White

Page 6: Disaster and Recovery

Estimated Downtime

Mission/Business Process MTD RTO RPO

Query customer record 48 hours 24 hours 8 hours

Store customer transaction 24 hours 12 hours4 hours

Authenticate user name and password 36 hours 24 hours 8 hours

MTD RTO RPO

Jamarcus White

Page 7: Disaster and Recovery

Resource RequirementsSystem

Resource/Component

Platform/OS/Version (as applicable)

Description

Server-class System Dell R720 Rack-mounted system

Windows Server 2008 R2 Host operating system

Microsoft SQL Server 2008 Database management

systemDatabase files Latest, or latest

snapshot if needed Binary files containing

data

Garrett Grey

Page 8: Disaster and Recovery

1. CEO consults department leads to consider time for recovery and determine need for business contingency.

2. CEO announces business contingency is in effect.3. CEO works with local authorities to ensure human safety as needed.4. Network managers and technicians move network operations to warm site.5. IT managers and technicians assess ability to move existing systems to warm

site.6. IT managers and technicians requisition new equipment to be delivered to

warm site as needed.7. Technicians validate warm site's network infrastructure and telecommunications

capabilities.8. IT managers and technicians install/restore systems at warm site.9. Technicians connect systems to warm site network.10.Technicians update public domain name records.11.Technicians inform customer service representatives of changes to telephone

numbers, public IP addresses, etc.12.Customer service representatives contact customers with new contact

information.

Business Contingency planGarrett Grey

Page 9: Disaster and Recovery

Purpose Scope Definitions

Incident Response PolicyGarrett Grey

Page 10: Disaster and Recovery

Purpose Scope Definitions

Information Systems Security Incident Physical Security

PurposeDallas Jones

Page 11: Disaster and Recovery

Employees IT Technicians Severity Levels

Level 1 Level 2 Level 3 Level 4

Identifying and Reporting Incidents

Dallas Jones

Page 12: Disaster and Recovery

Eradication Restoration Log Of Security Incident Annual Report

Mitigation and ContainmentDallas Jones

Page 13: Disaster and Recovery

Questions?