1 Availability Policy (slides from Clement Chen and Craig Lewis)

Slides:



Advertisements
Similar presentations
Security and Control Soetam Rizky. Why Systems Are Vulnerable ?
Advertisements

Information Technology Disaster Recovery Awareness Program.
How to Ensure Your Business Survives, Even if Your Server Crashes Backup Fast, Recover Faster Fast and Reliable Disaster Recovery, Data Protection, System.
BCM and Security ROGSI/DMS Präsentation ROGSI/DMS Suite for Corporate Survival ROGSI/Business Impact Analysis TOP 7 Best Practices for Business Continuity.
Business Plug-In B4 MIS Infrastructures.
Business Continuity Section 3(chapter 8) BC:ISMDR:BEIT:VIII:chap8:Madhu N PIIT1.
Chapter 13 Managing Computer and Data Resources. Introduction A disciplined, systematic approach is needed for management success Problem Management,
Business Continuity Disaster Recovery Risk Management How do these fit into a Framework?
1 Disaster Recovery “Protecting City Data” Ron Bergman First Deputy Commissioner Gregory Neuhaus Assistant Commissioner THE CITY OF NEW YORK.
1 Continuity Planning for transportation agencies.
© 2009 EMC Corporation. All rights reserved. Introduction to Business Continuity Module 3.1.
Building a Business Case for Disaster Recovery Planning - State and Local Government Chris Turnley
Business Continuity Planning and Disaster Recovery Planning
Iron Mountain’s Continuity Service ©2006 Iron Mountain Incorporated. All rights reserved. Iron Mountain and the design of the mountain are registered.
Stephen S. Yau CSE , Fall Contingency and Disaster Recovery Planning.
Copyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin CHAPTER FIVE INFRASTRUCTURES: SUSTAINABLE TECHNOLOGIES CHAPTER.
NERC Lessons Learned Summary March NERC lessons learned published in March 2015 Two NERC lessons learned (LL) were published in March2015 LL
1 Lesson 3 Computer Protection Computer Literacy BASICS: A Comprehensive Guide to IC 3, 3 rd Edition Morrison / Wells.
1 Disaster Recovery Planning & Cross-Border Backup of Data among AMEDA Members Vipin Mahabirsingh Managing Director, CDS Mauritius For Workgroup on Cross-Border.
John Graham – STRATEGIC Information Group Steve Lamb - QAD Disaster Recovery Planning MMUG Spring 2013 March 19, 2013 Cleveland, OH 03/19/2013MMUG Cleveland.
Copyright © 2015 Pearson Education, Inc. Processing Integrity and Availability Controls Chapter
Business Crisis and Continuity Management (BCCM) Class Session
Services Tailored Around You® Business Contingency Planning Overview July 2013.
November 2009 Network Disaster Recovery October 2014.
Security Equipment Equipment for preventing unauthorised access to data & information.
Security+ All-In-One Edition Chapter 16 – Disaster Recovery and Business Continuity Brian E. Brzezicki.
Security of Data. Key Ideas from syllabus Security of data Understand the importance of and the mechanisms for maintaining data security Understand the.
IT Business Continuity Briefing March 3,  Incident Overview  Improving the power posture of the Primary Data Center  STAGEnet Redundancy  Telephone.
Business Continuity and Disaster Recovery Chapter 8 Part 2 Pages 914 to 945.
IS 380.  Provides detailed procedures to keep the business running and minimize loss of life and money  Identifies emergency response procedures  Identifies.
Chapter 11: Designing a Data Recovery Solution for a Database MCITP Administrator: Microsoft SQL Server 2005 Database Server Infrastructure Design Study.
ISA 562 Internet Security Theory & Practice
David N. Wozei Systems Administrator, IT Auditor.
How Hospitals Protect Your Health Information. Your Health Information Privacy Rights You can ask to see or get a copy of your medical record and other.
Business Continuity & Disaster recovery
Important points and activities.  The objective is to secure life, property, information in the event of a disaster and to facilitate business continuity.
By Srosh Abdali.  Disaster recovery is the process, policies and procedures related to preparing for recovery or continuation of technology infrastructure.
Chapter © 2006 The McGraw-Hill Companies, Inc. All rights reserved.McGraw-Hill/ Irwin Chapter 7 IT INFRASTRUCTURES Business-Driven Technologies 7.
Preventing Common Causes of loss. Common Causes of Loss of Data Accidental Erasure – close a file and don’t save it, – write over the original file when.
IT Disaster Recovery CAUBO 2008 Information Systems and Technology.
1 Nassau Community CollegeProf. Vincent Costa Session 7 Infrastructures Sustainable Technologies CMP 117 Business Computing: Concepts &Applications.
Mark A. Magumba Storage Management. What is storage An electronic place where computer may store data and instructions for retrieval The objective of.
E.Soundararajan R.Baskaran & M.Sai Baba Indira Gandhi Centre for Atomic Research, Kalpakkam.
McLean HIGHER COMPUTER NETWORKING Lesson 15 (a) Disaster Avoidance Description of disaster avoidance: use of anti-virus software use of fault tolerance.
Component 8/Unit 9bHealth IT Workforce Curriculum Version 1.0 Fall Installation and Maintenance of Health IT Systems Unit 9b Creating Fault Tolerant.
This course, Essential Records Seminar, is part of
Continuity of Operations (COOP) Planning Guidelines for Dukes County.
Erman Taşkın. Information security aspects of business continuity management Objective: To counteract interruptions to business activities and to protect.
Disaster Recovery 2015 Indiana Statewide Payroll Conference Michael Ievoli-Client Support Specialist IV, Major Accounts September 16, 2015 Copyright ©
Component 8 Installation and Maintenance of Health IT Systems Unit 9b Creating Fault-Tolerant Systems, Backups, and Decommissioning This material was developed.
Security Operations Chapter 11 Part 2 Pages 1262 to 1279.
CBIZ RISK & ADVISORY SERVICES BUSINESS CONTINUITY PLANNING Developing a Readiness Strategy that Mitigates Risk and is Actionable and Easy to Implement.
Disaster Recovery Planning Barry Navarre Charter Business.
A Lightweight Business Continuity & Disaster Recovery Plan Motahareh Moravej Issuers’ Affairs Director at CSDI PHD. Student of Computer Engineering, UT.
Disaster Recovery Planning (DRP) DRP: The definition of business processes, their infrastructure supports and tolerances to interruptions, and formulation.
Information Security Crisis Management Daryl Goodwin.
Contingency Management Indiana University of Pennsylvania John P. Draganosky.
CompTIA Security+ Study Guide (SY0-401)
BUSINESS CONTINUITY BY HUI ZHENG.
Business Continuity / Recovery
Peggy M. Jackson, DPA, CPCU Peg Jackson & Associates
Business Continuity Plan Training
Processing Integrity and Availability Controls
Audit Plan Michelangelo Collura, Folake Stella Alabede, Felice Walden, Matthew Zimmerman.
CompTIA Security+ Study Guide (SY0-501)
Business Contingency Planning
Backup and restoration of data, redundancy
OnBase Training Speaker: Dora Compis Disaster Recovery.
Disaster Recovery is everyone’s job!
Presentation transcript:

1 Availability Policy (slides from Clement Chen and Craig Lewis)

2 Definition The degree to which data or systems are accessible and in functioning condition. Looking at it another way, the degree to which the system is fulfilling the intended function.

3 Availability and Reliability Availability and Reliability are not the same thing. Availability means that the system is ready for use. Reliability means that a device or system can perform its job when called upon to do so. There is overlap but they are not the same thing.

4 Major Causes of Disruption Human Interference –Operator error; –Virus and hacker attack; –Theft or sabotage; Communication Failure Hardware or system failure Natural Disasters Power Failure Water Damage Fire

5 Aspects of Availability Data Availability Network Availability Communication Availability System Availability Power Availability People Availability Other Resources Availability

6 Data Availability Rule #1: Backup ! Rule #2: Backup !! Rule #3: Backup !!!

7 Backup Methods Full Backup –Backup every file –Takes a lot of storage space Incremental Backup –backs up files that have been created or modified only since the last backup; –backup operator needing several tapes to do a complete restoration Differential Backup –backs up files that have been created or modified only since the last full backup –backup operator need only the full backup and the one differential backup to restore thesystem.

8 Data Retention Sarbanes Oxley All electronic company information must be retained for at least five years. Accounting firms that audit publicly traded companies must retain all related documents for 7 years after audit. HIPPA Members of health care industry must retain patient information for 6 years SEC 17a-3 and 17a-4 Brokers/dealers must retain records for 3-6 years and more

9 Data Vaulting Copy of data is saved at a remote site periodically or continuously, via network Remote site may be own site or at a vendor location Minimal or no data maybe lost in a disaster There is typically some delay before data can actually be used

10 Network Availability Prioritize the systems needing network access Measure the amount of bandwidth needed to fulfill purpose of each component Calculate overhead of protective measures. Decide what (if anything) can drop

11 Service Level Agreement Can the ISP deliver? Can your equipment handle it? Higher bandwidth – for what? –More business –Faster customer access –Faster music downloads –More scanning

12 People and Availability People are a source of information. Staff with knowledge of how to fix a problem not being there to fix it negatively impacts availability. –Positional redundancy – “Worker X can do that, but she’s not here until tomorrow.” –Shared knowledge – “What if I get hit by a bus?” –Limitations on physical access – “It’s a 30 second fix, but it will take me 10 minutes to get there.” –Limitations placed by policy – “I know how to fix it, but I’m not allowed to go in the server room.”

13 Infrastructure Availability Availability of the infrastructure can have a direct impact on availability of information –Voice communications –Power –HVAC –Physical access

14 Infrastructure Solutions Voice Cellular Phones WiFi Phones Walkie-talkies Power Uninterruptible Power Supply (UPS) Generators HVAC Portable coolers Fans/Blowers Physical Access Security guards Transportation shuttles Backup/alternative to electronic access controls

15 Measuring Availability What does it mean to be available and how can it be measured? Availability means that systems or data are accessible but does not guarantee: –Performance –Typical ways of doing things can still be used –Full system capacity

16 MTBF & MTTR Definitions: Mean Time Between Failure (MTBF) is the amount of time between failures, where failure is defined as a departure from acceptable service for a system. This is a measure of reliability. Mean Time to Recover (MTTR) measures the amount of time required to repair or recovery for a failed system. Availability is the ratio of the time a system is actually available to the time it should have been available. Availability = MTBF / (MTBF + MTTR)

17 Availability Values 1 week: ThresholdDowntime 99%1.1 hr 99.9%6.3 min 99.99%37.8 sec %3.8 sec %0.38 sec

18 Business Continuity Planning Big deal since 9/11 Every Business Continuity strategy includes three fundamental components: –Business Impact Analysis –Recovery Strategy –Design and Develop the disaster recovery process BCP should consider every type of interruption from a brief power outage up to the worst possible natural disaster or terrorist attack

19 Requirements of a BCP 1.Provide procedures and listing of resources to assist in the recovery process. 2.Provide an immediate, accurate and measured response to emergency situations. 3.Identify vendors that may be needed in the recovery process and put agreements in place with selected vendors. 4.Avoid confusion experienced during a crisis by documenting, testing an training plan procedures. 5.Clear guidance for declaring a disaster 6.Provide the necessary directions to ensure the timely resumption of critical services 7.Document recovery processes so they can be executed by knowledgeable people

20 BCDR Resources Survive: The Business Continuity Group – Emergency Information Infrastructure Partnership – Disaster Recovery Journal –

21 Summary Lots of parts of availability Tradeoffs are essential Complexity, complexity, complexity Need policy for a roadmap