ROBERT K. DUGGAN, CPA, CIA, CISA.  ITCP/ DRP often doesn’t work.  We discover it doesn’t work when we really need it to work.  We pay a fortune to.

Slides:



Advertisements
Similar presentations
Public v Private by Emma,Robs,Matt and Chris. Public Benefits It is paid for by taxes so it feels free Not elitist- does not separate the rich from the.
Advertisements

Illinois Department of Children and Family Services, Pathways to Strengthening and Supporting Families Program April 5, 2010 Division of Service Support,
Creating a Data Disaster Recovery Plan. What is a DR Plan? Is your best solution to: Continuous business services Prompt and smooth recovery Prepare for.
ONE TRILLION!!! How much is that???. Let’s Find Out!! Let’s count to ONE TRILLION!! With each second being one unit how long would it take to count to.
Deployment Adavatages Provisioning time reduced to minutes, not days to weeks! Configure hardware Install OS Configure OS & Tools Assign IP Addr Configure.
The Cost … … of Failure. What does it take to graduate? Graduation Requirements: Earn a minimum of 23 credits Pass the GHSGT or EOCTs (Classes of 2012,
Day and Night 3.8C; 5.8C 1. Why do we only see the sun part of the time? Sometimes we go outside and the sky is bright. We are able to see everything.
By: Tessa I.M. “We really were missing you.”I said. “I was thinking every day that you would be back. But every day you weren’t. Well, at least you were.
Presenters Ryan McMeekin Nancy Bong Scott Murphy University of Colorado SAP & ISACA University of Colorado SAP & ISACA.
HIRE ACT of 2010 Jason Meredith, CPA, CFP ® Mid-South CFO
Cloud Disaster Recovery. Typical Business Challenges How much does it cost me to have my IT environment off-line, and how quickly does my disaster recovery.
High Availability 24 hours a day, 7 days a week, 365 days a year… Vik Nagjee Product Manager, Core Technologies InterSystems Corporation.
Office of Internal Audit and Consulting Services at UT Tyler Budget Authority Training Fiscal Year 2015 Lou Ann Viergever, CPA, CIA, CRMA Executive Director.
Organizational Culture Lecture #4. Sea Voyage Question:
Frontier Continuity Services Protecting Your Data with Our Cloud.
WEEK OF JUNE 01, Physician:Dr. BEDROSSIAN Tel. No. : (647) Hours: 5:00 pm – 8:00 p.m.
Choosing a job for a set of parameters and overtime pay.
©HCCS & IBM® 2008 Stephen Linkin1 WebSphere Application Server on z/OS Stephen S. Linkin Houston Community College © HCCS and IBM 2008.
Larissa Torres HDFS 431 Dr. Seidel $5 Project.  Calories 340  Total Fat 5  Cholesterol 0  Sodium 495  Carbohydrates 358  Sugars 16  Protein 11.
#1. Calculating Gross Income Dan works part time at Shopko Dan worked 32 hours this week Dan makes $9.75/hour How much was Dan’s Gross Income?
Sales and Income Tax. Sales tax – a tax that is added to the cost of goods or services based on the percentage of the cost. Income tax – A tax that is.
 $10.65 x 40 = $  $ x 50 = $21,
EXTRAS Welcome, Parents!. Current Rates 1 Day2 Days3 Days4 Days5 Days Before/After Before/After 4:15 PU Before Only After.
An Overview: Reading Recovery. Overview of Reading Recovery O Reading Recovery is a highly effective (Tier 3) short- term intervention of one-to-one tutoring.
Board of Education Meeting June 22, Dr. Randa Jundi-Samman.
Practical Reports on Dependability Manifestation of System Failure Site unavailability System exception /access violation Incorrect result Data loss/corruption.
Benefit Laws 3-5 Mitch Jason and Isaiah. Unemployment Insurance Laws ● Welfare ● Social Security ● Qualification ● Give out unemployment funds ● Money.
CALCULATING NET MONTHLY INCOME. STEPS TO CALCULATING NET MONTHLY INCOME Step 1: Pay Rate X Hours Worked = Gross Weekly Income Step 2: Gross Weekly Income.
[INSERT COMPANY NAME] DISASTER RECOVERY SERVICES [Insert Date]
Interoperability and Image Analysis KC Stegbauer.
State of Washington Server Hosting Service Future Directions?
Disaster Recovery Quinn Gaalswyk, CISA Senior Information Systems Auditor University of Minnesota.
F.I.T. Principle THR & SMART goals. F.I.T.  Frequency  Frequency is how often you perform the physical activity.  Safe frequency is 3-5 times a week.
1 Press Ctrl-A ©G Dear 2008 – Not to be sold/Free to use Overtime Stage 6 - Year 11 General Mathematics Preliminary.
My Lancing Experience November By Owen R..
Before we start  Write your name, date, and note titles at the top of the page.  Copy down all notes.  Yes, ALL notes.
WEEK 1 You have 10 seconds to name…
Coupling Facility. The S/390 Coupling Facility (CF), the key component of the Parallel Sysplex cluster, enables multisystem coordination and datasharing.
Introduction to the new mainframe © Copyright IBM Corp., All rights reserved. 1 Main Frame Computing Objectives Explain why data resides on mainframe.
Grace enjoys baby-sitting, but it only pays $4 an hour. She has been offered a job as a tutor that pays $8 an hour. She can must work less than 15 hours.
Dr. Jamey Worrell, CPA, CISA, CIA. Managing Organizational Risk Associated with IT Managing Risks in Arms-length Transactions Governing collaboration.
Mechanical Engineering By Dutch Knight. What is mechanical engineering? A branch of engineering concerned primarily with the industrial application of.
African Walk to School Week. Many African children have to get up early so that they can get to school on time – often at about 5am!
Jose Escobedo. Law Enforcement  Law Enforcement is where you work to catch criminals. Or any other bad things criminals do.  Law enforcement is a branch.
1 Wages Press Ctrl-A ©2009 – Not to be sold/Free to use Stage 5 Year 9.
Data Backup Service. Backups Discucsion Focus is primarily for file servers. What are folks using now? Are you happy with it? What don’t you like? Doing.
Sydney’s If I had a Million dollars my house that I picked, because grandma Irene said to get a house that is at least 300,000 cost 1,539 a month and my.
WELCOME TO FIFTH GRADE READING!. Read as much as you can and choose books that you love reading. Find books, authors, subjects and themes that you.
1 COMP 3500 Introduction to Operating Systems Project 2 – An Introduction to OS/161 Overview Dr. Xiao Qin Auburn University
Long Multiplication. Napier Bones 347 x = 18,044.
ETH 557 Complete Class To purchase this material link Complete-Class-Guide For more courses visit our website.
IT 244 Week 3 Business Continuity Disaster Recovery To purchase this material link Week-3-Business-Continuity-Disaster-Recovery.
IT 244 Week 3 Assignment Disaster Recovery Plan To purchase this material link Assignment-Disaster-Recovery-Plan.
IT 244 Week 4 DQ 2 To purchase this material link Week-4-DQ-2 For more courses visit our website
Why To Wait For A Disaster To Disrupt Your Business?
Operating System Simulator
Enhancing Network Security
High Availability 24 hours a day, 7 days a week, 365 days a year…
What, When, Why, Where and How SCC maintains your Oracle database
Data Communications and Networking
Document DR Plan August 2010
PSYCH 770 Enthusiasstic Studysnaptutorial.com
تعارف. تعارف قواعد العمل ا الموبيل المشروبات الاحاديث الجانبية الاسئلة نفكر.
"שינוק", אלוף העולם בדמקה לאדם ולמכונה זיו בן-אליהו
نحو مفهوم شامل للجودة ومتطلبات التأهيل للأيزو
ADDITIVE VS. MULTIPLICATIVE RELATIONSHIPS
IT Service Delivery And Support Week Three - OS
Week1 software - Lecture outline & Assignments
财务管理案例教学法 研究及示例 ——王遐昌 2006/11/10.
Science is fun. Science is fun. Science is fun. Science is fun. Science is fun. Science is fun. Science is fun. Science is fun. Science is fun. Science.
Presentation transcript:

ROBERT K. DUGGAN, CPA, CIA, CISA

 ITCP/ DRP often doesn’t work.  We discover it doesn’t work when we really need it to work.  We pay a fortune to maintain it. (Tier 4-6- $400K-$2M and up!)  DR test recoveries are fun!

 IBM sets Tiers 1-6 for CICS operating on z/OS  Based on configuration - Tiers 1-3 being 1 week to >24 hours recovery time  Tiers 4-6 being <24 hours (large manufacturers/distributors with continuous processing needs and low downtime tolerance to business to instantaneous (Tier 6- banks- 0 downtime tolerance) (see IBM.com for more information)  Today’s example is on a Tier 4 Scenario for medium to large organizations with 24 hour RTO requirement for critical applications (If you have a mainframe you most likely need Tier 3 up)  < 24 hour recovery of critical platforms and applications – key success factors and evaluation steps are similar for the tiers

 Determined by Business Impact Analysis and Risk Assessment  RTO / RPO  Recovery of critical platforms and applications – regardless of tier or platform, key success factors and evaluation steps are similar for all tiers. Configuration and RTO changes.

 Walkthru -“Tabletop”- Scenario with roles and responsibilities  Functional Exercise – Verify the effectiveness of the backup by platform  Off-Site Test Restore – Verify the effectiveness of the IT DR plan offsite at the test center

Two different things, but: ITDR and BCP are severely impaired without each other.

 Should occur well before the offsite test  Include vendor team  Follow up process with platform owners/DR team and vendor team to resolve issues noted prior to actual test restore  Audit interviews platform support teams, IT Director, DR Manager assigned as part of planning to get an understanding of objectives and where the process is on an evolutionary scale

 Call tree notification system dysfunctional / not at vendor, call trees incomplete or not defined  Persons who can declare not defined or poorly separated (or the wrong people) – vendor cannot take action under contractual terms  Support teams not defined / backups for key members  Approval process for changes to DR Documents  DR Documents not current and at vendor/on secure website  Vendor in same geographic area

 Step by step instructions for platform owner / vendor operators are not crystal clear  No clear assignment of responsibilities or documented procedures for key platform owners  No clear assignment of responsibility for vendor personnel or appropriate training on platforms  Backups for key personnel not defined  Business impact analysis and risk assessment not current/tier of recovery is insufficient- Example: Distributor switch from call center to web application/proprietary remote order entry system

 Vendor personnel or backup recovery personnel cannot restore the system - Port mapping / system documentation not complete / up to date - Insufficient remote software / hardware support level - Vendor hardware is insufficient - Insufficient procedures / lack of clean updated scripts - Poorly trained recovery personnel

 Backup not really effective- verify successful recovery of each platform using a checklist and document verification method (system, volume information in header screens). PS - Don’t ask for screenshots in the middle of a DR test. Just catch platform, LPAR, times, and volume information – observe/confirm effective validation.  Application recovery not verified during the 24 hour test/inaccurate RTO  Inaccurate system documentation leads to failure to meet RTO  Port mapping is inaccurate /not maintained properly by hardware support

 Restore personnel cannot follow scripts without assistance from the company platform team  Test results not verified by DR Test Manager/DR Manager or test leader is not independent/does not rotate by test  Teams do not complete verification checklist or keep testing notes- it is an evolving process that needs to build  Teams do not update DR Instructions following test restore for lessons learned- expensive process- should have a post restore review with follow up task list  Teams do not accurately capture RT/RP, evaluate against true RTO/RPO by platform and application

 

Be sure to find me on Linked-In