Gulf Coast Energy International Business Continuity / Disaster Recovery Planning and Design Proposal Prepared by Andrew Rolf, Felipe Torres, Pranay Jaiswal.

Slides:



Advertisements
Similar presentations
Museum Presentation Intermuseum Conservation Association.
Advertisements

1 The Basics of Business Continuity Presented by Mary F. Sandy, CBCP Business Continuity/Disaster Recovery Class DePaul University ©Mary F. Sandy, 2006.
Disaster Planning: The Basics TEAJF Statewide Grantee Meeting Houston July 20, 2006.
Business Continuity Training & Awareness by Sulia Toutai (ANZ)
Oregon Department of Education Business Continuity / Disaster Recovery Program Implementation Mark Tyler Nigel Crowhurst.
Business Continuity and Disaster Recovery Planning.
Disaster Preparedness I Lessons Learned Don Hall Thomson Prometric 2006 Annual ConferenceAlexandria, Virginia Council on Licensure, Enforcement and Regulation.
1 The process of analyzing all core business functions and establishing an optimized timetable for recovery. Provides baseline for:  Justification for.
CIOassist Technologies Your CIO on Demand… Business Continuity Planning Our Offering CIOassist Technologies (
Maximizing Uptime and Your Firm's Bottom Line: Understanding risk and budget when evaluating business continuity & disaster recovery protocols Michael.
1 Disaster Recovery “Protecting City Data” Ron Bergman First Deputy Commissioner Gregory Neuhaus Assistant Commissioner THE CITY OF NEW YORK.
Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP)
BCP/DRP Consultancy Project- An approach
Business Continuity Planning and Disaster Recovery Planning
TEL382 Greene Chapter /27/09 2 Outline What is a Disaster? Disaster Strikes Without Warning Understanding Roles and Responsibilities Preparing For.
Business Continuity & Disaster Recovery Planning at The Chicago Board of Trade Presented By: Bryan Durkin Sr. Vice President The Chicago Board of Trade.
Business Continuity and You! The Ohio State University Business & Finance Enterprise Continuity Program Quarterly Update October 2008Business and Finance.
EASTERN MICHIGAN UNIVERSITY Continuity of Operations Planning (COOP)
© 2010 Plexent – All rights reserved. 1 Change –The addition, modification or removal of approved, supported or baselined CIs Request for Change –Record.
Continuity of Operations Planning COOP Overview for Leadership (Date)
School Technology Solutions, LLC Technology Audits What's in it for you? 4 th Annual SW/WC Technology Conference March 11, 2010 Presenter: Lee Whitcraft.
Module 3 Develop the Plan Planning for Emergencies – For Small Business –
Vital Records Fuel Your Recovery….. Donna Read, CRM Florida Gulf Coast ARMA November 16, 2010 Are You Running on Empty????
ISA 562 Internet Security Theory & Practice
Insurance Institute for Business & Home Safety Even if the worst happens, be prepared to stay.
David N. Wozei Systems Administrator, IT Auditor.
Rich Archer Partner, Risk Advisory Services KPMG LLP Auditing Business Continuity Plans.
Business Continuity & Disaster recovery
C ONNECTING FOR A R ESILIENT A MERICA Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP) Skip Breeden.
Business Continuity and Disaster Recovery Planning.
The views expressed in this presentation do not necessarily reflect those of the Federal Reserve Bank of New York or the Federal Reserve System Association.
Developing Plans and Procedures
Disaster Recovery and Business Continuity Planning.
Business Continuity Program Orientation (insert presentation date) (This presentation is a template that requires adjustments to meet your needs)
Phases of BCP The BCP process can be divided into the following life cycle phases: Creation of a business continuity and disaster recovery policy. Business.
Business Continuity. Business continuity... “Drive thy business or it will drive thee.” —Benjamin Franklin ( ), American entrepreneur, statesman,
This course, Essential Records Seminar, is part of
9 juni 2009 Alex van Os de Man BCI Forum 2009 Business Impact Analysis Process.
FIRMA 2010 Larry J. Kallembach April 1, MB Financial Headquarters - September 2008 Chicago is a Lakefront city…….
Disaster Recovery: Can Your Business Survive Data Loss? DR Strategies for Today and Tomorrow.
1 Verizon Florida, LLC Hurricane Season Preparation PSC Workshop – May 6, 2009.
Mitigation & Education (MES) Subcommittee Update Chris Jonientz-Trisler, FEMA Co-Chair.
Chapter 3: Business Continuity Planning. Planning for Business Continuity Assess risks to business processes Minimize impact from disruptions Maintain.
Tom Lenart & John Field CT DEMHS Region 2.  Department of Emergency Services and Public Protection (DESPP)  Commission on Fire Prevention and Control.
Business Continuity Disaster Planning
CBIZ RISK & ADVISORY SERVICES BUSINESS CONTINUITY PLANNING Developing a Readiness Strategy that Mitigates Risk and is Actionable and Easy to Implement.
A Lightweight Business Continuity & Disaster Recovery Plan Motahareh Moravej Issuers’ Affairs Director at CSDI PHD. Student of Computer Engineering, UT.
Introduction to Business continuity Planning 6/9/2016 Business Continuity Planning 1.
Disaster Recovery Planning (DRP) DRP: The definition of business processes, their infrastructure supports and tolerances to interruptions, and formulation.
AUDITING BUSINESS CONTINUITY PROGRAMS AND PLANS What to Look For Presented by: Tommye White, CBCP, DRP Chuck Walts, CBCP, CRP.
2007 Office of Risk Management Annual Conference 2007 David M. Shapiro Disaster Planning & Recovery Consultants
Business Continuity Planning 101
Dr. Gerry Firmansyah CID Business Continuity and Disaster Recovery Planning for IT (W-I)
THINK DIFFERENT. THINK SUCCESS.
Business Continuity / Recovery
Business Continuity Plan Training
Berry College Disaster Recovery Soft Exit
Fundamentals of a Business Impact Analysis
Audit Planning Presentation - Disaster Recovery Plan
The "Who, What, When, Where, Why, and How" of a
Mark Tyler Nigel Crowhurst
Business Continuity Basics
Stage 1 - Business Impact Review
Continuity of Operations Planning
Emerging Audit and Internal Control Issues
Developing and testing the Plan
INPUT OUTPUT ASSURANCE
Conducting a Business Impact Analysis (BIA)
Project Name Here Kick-off Date
Presentation transcript:

Gulf Coast Energy International Business Continuity / Disaster Recovery Planning and Design Proposal Prepared by Andrew Rolf, Felipe Torres, Pranay Jaiswal

© IT Consulting LLC. All Rights Reserved. Disaster Recovery Plan IT systems Corporate processes and procedures BCP/DR & Emergency Preparedness Plan  Business continuity, emergency management and disaster recovery are interconnected to protect, recover and resume business operations

© IT Consulting LLC. All Rights Reserved. How to initiate a BCP?  Perform in-depth review of existing DRP and perform immediate improvements as appropriate.  Establish a GCE Project Sponsor and Steering Committee.  Establish Business Continuity Definitions, Terms and Assumptions

© IT Consulting LLC. All Rights Reserved. Initiate Business Continuity Management Risk Assessment Business Impact Analysis Strategy Evaluation and Selection BR Organization and Responsibilities Develop Standard Operating Procedures Develop IT Recovery Plans Implement stand-by arrangements Implement Risk Reduction Measures Quality Assurance Stage 1 Initiation Stage 2 Requirements and Strategy Stage 3 Implementation Stage 4 Operational Management Education and Awareness Review and Audit Testing Change Management Training Business Continuity Lifecycle © IT Consulting LLC. All Rights Reserved.

Schedule for BCP/DR (SOW) CURRENT STATE TARGET STATE STABILIZE OPTIMIZE TRANSFORM Project Initiation Scope / Assumptions Schedule Team Contract Review / Validate Existing BCP/DR processes & procedures for ability to meet SLAs Deliverable (RA) Deliverable (BIA) Initiate Risk Assessment (RA) Initiate Business Impact Analysis (BIA) Recommend immediate updates to current procedures as appropriate Plan Annual Exercise Conduct Annual Exercise Periodic Review/ Validate BIAs And DRPs Coordinate Regular DR Tests per SLAs DR not a priority DR plans not updated to meet new business req. Plans not tested DR HW out-dated New BCP/DR Plan Annual Testing Constant Update Periodic BIAs validations Updated HW Management commitment Initiate Strategy Evaluation And Selection Deliverable (SES) Project Planning Project Execution Develop Recovery Plans Develop Procedures Implementation Deliverable (Exercise Result) Hurricane Season Starts Implement Critical Functions

© IT Consulting LLC. All Rights Reserved. Risk and Business Impact Analysis  Analysis Team Members –Individuals from each functional business unit –DR consultants from IT Consulting  Analysis Team Responsibility –Plan & conduct Risk & Business Impact Analysis –Report findings to management

© IT Consulting LLC. All Rights Reserved. Risk and Business Impact Analysis  Data Gathering –Cross-functional analysis –Interviews, Meetings, Questionnaires, Polls –On-site and electronic conferences  Data Storage and Distribution –Stored on LAN –Software: Microsoft Office –Distributed by mail, , LAN, face to face

© IT Consulting LLC. All Rights Reserved. Risk Analysis  Risk Evaluation Areas –Geographical Locations –Building Composition –Upstream, Downstream, Corporate, & IT Physical access controls and security Computing environments Personal practices Operating practices Backup practices

© IT Consulting LLC. All Rights Reserved. Risk Analysis  Items Included in Risk Analysis –List of potential disasters/crisis –Impact to people, assets, environment, reputation –Likelihood of occurrence –Severity rating based on impact and likelihood –Others…

© IT Consulting LLC. All Rights Reserved. Risk Analysis

© IT Consulting LLC. All Rights Reserved. People and Disasters  Disaster Awareness and Training –Detailed Evacuation Plans –Evacuation Drills  Emergency Communication Processes –Contact Information for All Employees  Laptops for Critical Functions

© IT Consulting LLC. All Rights Reserved. Business Impact Analysis  Critical Functions Questionnaire –Is function time critical? –Can function be performed at reduced efficiency? –Max time function can be unavailable? –Loss of revenue? –Fines or penalties? –Legal liabilities? –Loss of public image? –Others…

© IT Consulting LLC. All Rights Reserved. Business Impact Analysis  Steps in Analysis –Compare to risk analysis –Develop matrix of critical functions, risks, impacts –Review with stakeholders/management

© IT Consulting LLC. All Rights Reserved. Business Impact Analysis

© IT Consulting LLC. All Rights Reserved. Business Impact Analysis

© IT Consulting LLC. All Rights Reserved. Steps for a Disaster Recovery Plan  Identify staffing requirements  Identifying recovery strategies  Selecting recovery strategies  Draft Creation of disaster recovery plan  Testing the disaster recovery plan

© IT Consulting LLC. All Rights Reserved. Staffing Resources

© IT Consulting LLC. All Rights Reserved. Staffing Resources Time Dedication: Not more than 30% of their total work time should be needed to provide guidance to the IT Consulting Project Team.

© IT Consulting LLC. All Rights Reserved. Time to recover Money Maximum cost of plan Acceptable Downtime Cost (RTO) Loss (RPO) Relationship between RTO, RPO & Cost  Recovery Point Objective (RPO): Refers to the point in time to which data must be recovered.  Recovery Time Objective (RTO): Refers to the acceptable time period within which the business functions should be restored and made available to ensure normal functioning of the organization. Weeks Days Hrs SecsSecs Hrs Days Weeks DISASTER RPO RTO

© IT Consulting LLC. All Rights Reserved. Identifying Recovery Strategies  Computer facilities recovery strategy –Hot sites, Cold sites, Mirror sites, etc  Data and documentation recovery strategies –RPO, RTO  Department recovery strategies –Business Functions  Telecommunication recovery strategies –Voice and Data

© IT Consulting LLC. All Rights Reserved. Selecting Recovery Strategies  Cost Benefit Analysis

© IT Consulting LLC. All Rights Reserved. Selecting Recovery Strategies  Cost Benefit Analysis

© IT Consulting LLC. All Rights Reserved. Selecting Recovery Strategies  Cost Benefit Analysis

© IT Consulting LLC. All Rights Reserved. GCE Global Operations Corporate Headquarters Division Headquarters European Headquarters Asia Pacific Headquarters Houston: Corporate Upstream Downstream Real Estate IT ~4K employees Lockport, LA: Upstream Real Estate IT ~1K employees Brussels: Upstream IT ~200 employees Kuala Lumpur Upstream IT ~150 employees

© IT Consulting LLC. All Rights Reserved. GCE Gulf Coast Operations  As Is

© IT Consulting LLC. All Rights Reserved. GCE Corporate IT Group (as-is) Oil Platforms Operations/Support Datacenter Developer Datacenter Support/Op. Personnel Office Developers & PM Office

© IT Consulting LLC. All Rights Reserved. GCE Gulf Coast Operations  Redundancy –On-Shore –Off-Shore

© IT Consulting LLC. All Rights Reserved. GCE Gulf Coast Operations  Critical Data

© IT Consulting LLC. All Rights Reserved. Oil Platforms Operations/Support Datacenter Developer Datacenter Support/Op. Personnel Office Developers & PM Office Developers & PM Office COLDSITE MIRRORED Operations/Support Datacenter MIRRORED Developer Datacenter Support/Op. Personnel HOTSITE

© IT Consulting LLC. All Rights Reserved. Selecting Recovery Strategies  Data, Time, and Criticality

© IT Consulting LLC. All Rights Reserved. Selecting Recovery Strategies  Data, Time, and Criticality –Huge Data Quantity –Low Business Criticality –RTO → Delayed

© IT Consulting LLC. All Rights Reserved. Selecting Recovery Strategies  Data, Time, and Criticality –Small Data Quantity –High Business Criticality –RTO → Immediate

© IT Consulting LLC. All Rights Reserved. Steps for a Disaster Recovery Plan  Identifying recovery strategies  Selecting recovery strategies  Draft Creation of disaster recovery plan –Reviews and discussion sessions –Finalize and Sign-off  Testing the disaster recovery plan –Initial Test –Subsequent annual tests

Gulf Coast Energy International Business Continuity / Disaster Recovery Planning and Design Proposal

© IT Consulting LLC. All Rights Reserved.  Total Project Cost: $3.1 Million –.51% of GCE 2005 Income of $600M –.03% of GCE 2005 Revenue of $10B –Costs based on work completed through DR implementation for Critical systems (June 1, 2007) Project Cost Estimates  GCE losses estimated to be $1 Million a day without a comprehensive disaster recovery plan.