SlideShare a Scribd company logo
The Importance Of Business Continuity And Disaster Recovery Planning 
By Aqel M. Aqel 
Information Systems Audit & Control Association 
Rolling Meadows Illinois –USA (www.isaca.org) 
CISA –Coordinator / Research Director -Riyadh Chapter 
Dec 2014
Why BCP & DRP 
•Successful businesses expect the unexpected and plan for it. 
•Disruptions to your business can result in: 
•Data risk, 
•Revenue loss, 
•Failure to deliver services 
•That’s why organizations need strong business continuity planning. 
John Sharp, 2012,The Route Map to Business Continuity Management: Meeting the Requirements of ISO 22301’ by 
A Good Plan Increases Your Chances of Recovery
Concepts and Terminology 
•Business continuitydescribes the processes and procedures an organization must put in place to ensure that mission-critical functions can continue during and after a disaster. 
•Disaster recoveryrefers to specific steps taken to resume operations in the aftermath of a catastrophic disaster (natural or national emergency)
Reasons behind Disasters 
•Environmental Disasters 
•Tornado& Hurricane 
•Power Grid Failure 
•Flood 
•Snowstorm 
•Earthquake 
•Electrical storms 
•Fire 
•Fire 
•Sink Holes 
•Landslides 
Man Made Disruptions 
Terrorist Attack 
Sabotage التخريب 
War / Theft 
Arson الحريق المتعمد 
Labor Disputes 
Equipment or System Failure 
Internal power failure 
Air conditioning failure 
Cooling plant failure 
Equipment failure 
IT Failures and Security Breaches 
Cyber crime 
Loss of records or data 
Disclosure of sensitive information 
IT system failure
More Concepts and Terminology 
Recovery Point Objective(RPO) measures the ability to recover files by specifying a point in time restore of the backup copy. 
Recovery Time Objective(RTO)measures the time that it takes for a system to be completely up and running in the event of a disaster. 
Source: Network Servers 2011
More Concepts and Terminology 
•Recovery Point Objective(RPO) measures the ability to recover files by specifying a point in time restore of the backup copy.i.e. 
•Amount of data lost from failure, measured as the amount of time from a disaster event 
•It's determined by the amount of time between data protection events and reflects the amount of data that potentially could be lost during a disaster recovery. 
•The metric is an indication of the amount of data at risk of being lost. 
•Recovery Time Objective(RTO)measures the time that it takes for a system to be completely up and running in the event of a disaster. i.e. 
•Targeted amount of time to restart a business service after a disaster event. 
•It is related to downtime. The metric refers to the amount of time it takes to recover from a data loss event and how long it takes to return to service. 
•RTO refers then to the amount of time the system's data is unavailable or inaccessible preventing normal service.
RPO and RTO
RTO and RPO 
Source: http://wikibon.org/w/images/0/04/RPO_RTO_Horison.jpg
Facts 
•The US Chamber of Commerce reported that: 
•the economic losses in 2011, as a result of natural disasters, reached $380 million. 
•Federal Emergency Management Agency (www.fema.gov) reports: 
•40-60% of businesses that close due to disaster never reopen!! 
(source: https://telovations.wordpress.com/tag/revenue-lost-due-to-natural-disaster/
Facts 
Source: FreeFormDynamics 2011 
•Only 23% of Respondents said: yes, there is a formal DR plan in place.
Facts 
•Numbers Speaks!
Facts 
Source: http://www.e-janco.com/DRP_BCP_Audit.html
Facts 
Source: http://powerwindows.wordpress.com/2010/10/25/windows-geoclusters-stretch-clusters-and-recoverpointce-failover/ 
•Cost of downtime does not propagate linearly!
Facts 
•What part of IT infrastructures are covered by BC/DR plans 
Source: Howard Marks (2008) http://www.informationweek.com/practical-disaster-recovery-for-midsize-companies/d/d-id/1075012?
Facts 
Source: Howard Marks (2008) http://www.informationweek.com/practical-disaster-recovery-for-midsize-companies/d/d-id/1075012? 
•What are the barriers to adoption of a business continuity plan? 
•Cost and complexity are 
•Lack of skills is a reason as well.
Facts 
http://www.crn.com/slide-shows/storage/240006796/8-surprising-disaster-recovery-stats.htm/pgno/0/7 
86% of companies experienced one or more instances of system downtime in the previous 12 months. 
Downtimes lasted 2.2 days on the average and cost each business an average of $366,363 a year. 
33% of businesses admitted they do not back up virtual servers as often as they do their physical servers.
Policies 
Support Motivation 
Sponsoring & follow up 
Procedures 
Policies 
Tools 
Roles and Responsibilities 
Methodologies / Best Practices 
Training 
Validation 
Audit Programs 
Reports 
Awareness 
Source: Aqel M. Aqel, IT Security in your firm, what is it, & how to achieve it. (2011). 
Monitoring 
Execution 
Leadership 
Actionable model
ISO 22301 
In 2012, BCI in partnership with BSI launch of ISO 22301, the new global standard for business continuity management.
ISO 22301 
•Provides a comprehensive set of controls based on BCM best practice. 
•Covets the whole BCM lifecycle. 
•Defines the strategic and tactical capability of an organization to plan for and respond to incidents. 
•It is generic and offers organizations guidance on putting their BCM systems in place.
ISO 22301 –2012 key Clauses 
•Clause 1:Scope 
•Clause 2:Normative References 
•Clause 3:Terms and Conditions 
•Clause 4:Context of the organization 
•Clause 5:Leadership 
•Clause 6:Planning 
•Clause 7:Support 
•Clause 8:Operation 
•Clause 9:Performance evaluation 
•Clause 10: Improvement
ISO 22301 -Clause 4:Context of the organization
ISO 22301 –Clause 5:Leadership 
•Top management needs to demonstrate an ongoing commitment to the BCMS. 
•Integrating the BCMS requirements into the organization’s business processes 
•Providing the necessary resources for the BCMS 
•Communicating the importance of effective business continuity management 
•Ensuring that the BCMS achieves its expected outcomes 
•Directing and supporting continual improvement 
•Establish and communicate a business continuity policy 
•Ensuring that BCMS objectives and plans are established 
•Ensuring that the responsibilities and authorities for relevant roles are assigned
ISO 22301 –Clause 6:Planning 
•Establishing strategic objectives and guiding principles for the BCMS. 
•The business continuity objectives must: be consistent with the business continuity policy; 
•Ttakeinto account the minimum level of products and services that is acceptable to the organization to achieve its objectives; 
•be measurable; 
•take into account applicable requirements; 
•be monitored and updated as appropriate
ISO 22301 –Clause 7:Support 
•Using the appropriate resources for each task. 
•Competent staff with relevant (and demonstrable) 
•Training and supporting services 
•Awareness and communication. 
•Both internal and external communications of the organization must be considered in this area. 
•The requirements on the creation, update and control of documented information are also specified in this clause.
ISO 22301 –Clause 8:Operation 
•Business Impact Analysis (BIA): 
•Risk assessment 
•Business continuity strategy: 
•Business continuity procedures: 
•Exercising and testing
ISO 22301 –Clause 9:Performance evaluation 
•ISO 22301 requires permanent monitoring of the system as well as periodic reviews to improve its operation: 
•monitoring the extent to which the organization’s business continuity policy, objectives and targets are met; 
•measuring the performance of the processes, procedures and functions that protect its prioritized activities; 
•monitoring compliance with this standard and the business continuity objectives; 
•monitoring historical evidence of deficient BCMS’ performance 
•conducting internal audits at planned intervals; and 
•evaluating all this in the management review at planned intervals.
ISO 22301 –Clause 10: Improvement 
•Continual improvement: 
•all the actions taken throughout the organization to increase effectiveness (reaching objectives) and efficiency (an optimal cost/benefit ratio) of security processes and controls to bring increased benefits to the organization and its stakeholders.
More information 
•The American Institute of Certified Public Accountants (AICPA) 
•Information Systems Audit and Control Association (ISACA) 
•Association of Information Technology Professionals (AITP) 
•Institute of Internal Auditors (IIA) 
•International Association for Computer Information Systems (IACIS) 
•Information Systems Security Association (ISSA) 
•International Disaster Recovery Association (IDRA) 
•Business Recovery Managers Association (BRMA) 
•British Standards Institute (BSI) 
•http://www.slideshare.net/AhmedRiad2/ss-38345026
Thank you

More Related Content

PPT
Business continuity and disaster recovery
Adeel Javaid
 
PPTX
Business Continuity Management
Lusungu Mkandawire CISA,CISM,CGEIT,CPF,PRINCE2
 
PPTX
Business continuity & Disaster recovery planing
Hanaysha
 
PPTX
Bcp
madunix
 
PPTX
BCP Awareness
Imad Almurib
 
PPT
business-continuity-management-awareness-presentation-for-mampu2929
Andy Willams
 
PPT
Business Continuity Planning Presentation Overview
Bob Winkler
 
PPT
What is business continuity planning-bcp
Adv Prashant Mali
 
Business continuity and disaster recovery
Adeel Javaid
 
Business Continuity Management
Lusungu Mkandawire CISA,CISM,CGEIT,CPF,PRINCE2
 
Business continuity & Disaster recovery planing
Hanaysha
 
Bcp
madunix
 
BCP Awareness
Imad Almurib
 
business-continuity-management-awareness-presentation-for-mampu2929
Andy Willams
 
Business Continuity Planning Presentation Overview
Bob Winkler
 
What is business continuity planning-bcp
Adv Prashant Mali
 

What's hot (20)

PPTX
Business continuity & disaster recovery planning (BCP & DRP)
Narudom Roongsiriwong, CISSP
 
PPT
Disaster Recovery Plan
Emilie Gray
 
PPT
Business continuity planning
Sandeep Kashyap
 
PPTX
How to write an IT DR plan
Databarracks
 
PPTX
Disaster Recovery Plan
Indeevari Ramanayake
 
PDF
Business Continuity Planning
alanlund
 
PPTX
Disaster Recovery Plan / Enterprise Continuity Plan
Marcelo Silva
 
PPSX
9 Bcp+Drp
Alfred Ouyang
 
PPTX
Disaster Recovery Plan
mhdpaknejad
 
PPTX
Business Continuity & Disaster Recovery
EC-Council
 
PPT
Business Continuity Workshop Final
Bill Lisse
 
PDF
IT-Centric Disaster Recovery & Business Continuity
Steve Susina
 
PPTX
Business Continuity Planning Presentation
The Chamber For a Greater Chapel Hill-Carrboro
 
PDF
Business Continuity Plan PowerPoint Presentation Slides
SlideTeam
 
PPTX
Business continuity planning and disaster recovery
KrutiShah114
 
PPT
Business Continuity Planning
Dipankar Ghosh
 
PPTX
Business Continuity Planning
gcleary
 
PPTX
Business continuity
Alka Mehar
 
PDF
Business Continuity Management PowerPoint Presentation Slides
SlideTeam
 
PPT
Data center disaster recovery.ppt
omalreda
 
Business continuity & disaster recovery planning (BCP & DRP)
Narudom Roongsiriwong, CISSP
 
Disaster Recovery Plan
Emilie Gray
 
Business continuity planning
Sandeep Kashyap
 
How to write an IT DR plan
Databarracks
 
Disaster Recovery Plan
Indeevari Ramanayake
 
Business Continuity Planning
alanlund
 
Disaster Recovery Plan / Enterprise Continuity Plan
Marcelo Silva
 
9 Bcp+Drp
Alfred Ouyang
 
Disaster Recovery Plan
mhdpaknejad
 
Business Continuity & Disaster Recovery
EC-Council
 
Business Continuity Workshop Final
Bill Lisse
 
IT-Centric Disaster Recovery & Business Continuity
Steve Susina
 
Business Continuity Planning Presentation
The Chamber For a Greater Chapel Hill-Carrboro
 
Business Continuity Plan PowerPoint Presentation Slides
SlideTeam
 
Business continuity planning and disaster recovery
KrutiShah114
 
Business Continuity Planning
Dipankar Ghosh
 
Business Continuity Planning
gcleary
 
Business continuity
Alka Mehar
 
Business Continuity Management PowerPoint Presentation Slides
SlideTeam
 
Data center disaster recovery.ppt
omalreda
 
Ad

Viewers also liked (20)

PPTX
Toward an organizational E-readiness Model
aqel aqel
 
PPT
Disaster Recovery Plan for IT
hhuihhui
 
PPT
Disaster Recovery Presentation
TimSchaefer
 
PPTX
e-government summit - may 2013 - Riyadh - Saudi Arabia - opening note by aqel...
aqel aqel
 
PPTX
3rd kingdom cyber security forum it gov in saudi arabia- aqel
aqel aqel
 
PPTX
Managing human resources at data centers 1.0
aqel aqel
 
PPTX
Business Continuity Planning
Bharath Rao
 
PPTX
Business continuity overview slideshare
Chris Greenhill
 
PPTX
Introduction to IT Governance using Cobit 5 مقدمة في حوكمة تقنية المعلومات - ...
aqel aqel
 
PPTX
COBIT 5 IT Governance Model: an Introduction
aqel aqel
 
PPTX
DRP Presentation
Jamaz Hall
 
PPTX
The MILES Series - IT - Bringing Everything Together
Anurag Purohit
 
PPTX
Business continuity and disaster recovery planning
Yaakub Idris
 
PPTX
DRP presentation
Wajahat Ali Khan
 
PPT
Emerging Risks, BCP & DRP
Jorge Sebastiao
 
PDF
Cobit 5 introduction plgr
Pedro Garcia Repetto
 
PPTX
Pecha Kuch - BCP & DRP - By Balasubramanian P
Compassites Navigator
 
PPTX
Pecha Kuch – Trips You Should Definitely Make In Your Lifetime- By Sanjay P A
Compassites Navigator
 
PDF
Myths and realities about designing high availability data centers
Morrison Hershfield
 
Toward an organizational E-readiness Model
aqel aqel
 
Disaster Recovery Plan for IT
hhuihhui
 
Disaster Recovery Presentation
TimSchaefer
 
e-government summit - may 2013 - Riyadh - Saudi Arabia - opening note by aqel...
aqel aqel
 
3rd kingdom cyber security forum it gov in saudi arabia- aqel
aqel aqel
 
Managing human resources at data centers 1.0
aqel aqel
 
Business Continuity Planning
Bharath Rao
 
Business continuity overview slideshare
Chris Greenhill
 
Introduction to IT Governance using Cobit 5 مقدمة في حوكمة تقنية المعلومات - ...
aqel aqel
 
COBIT 5 IT Governance Model: an Introduction
aqel aqel
 
DRP Presentation
Jamaz Hall
 
The MILES Series - IT - Bringing Everything Together
Anurag Purohit
 
Business continuity and disaster recovery planning
Yaakub Idris
 
DRP presentation
Wajahat Ali Khan
 
Emerging Risks, BCP & DRP
Jorge Sebastiao
 
Cobit 5 introduction plgr
Pedro Garcia Repetto
 
Pecha Kuch - BCP & DRP - By Balasubramanian P
Compassites Navigator
 
Pecha Kuch – Trips You Should Definitely Make In Your Lifetime- By Sanjay P A
Compassites Navigator
 
Myths and realities about designing high availability data centers
Morrison Hershfield
 
Ad

Similar to Bcp drp (20)

PPTX
ICTD Material PowerPoint Presentation Format.pptx
MahmoudElmahdy32
 
PPSX
The Revere Group - Making A Case For Disaster Recovery
cadavis22
 
PPTX
awareness bcp for manufacturing industry.pptx
shiva3305
 
PPTX
BCP awareness ISO 22301 2019 training .pptx
shiva3305
 
PPT
Disaster recovery presentation for the servers
JohnsonPackiyaraj1
 
DOCX
Business Continuity Plan TemplateCIO Maria Sosa has asked you to p.docx
felicidaddinwoodie
 
PPTX
Awareness iso 22301 danang suryo
Danang suryo Wardhono
 
PDF
Developing and Managing Business Continuity Plan (BCP)
Goutama Bachtiar
 
PPTX
sdfdsfsfsdfsdfsdfsdfssefsdfsdfsdfwteesfgrtertwetetwewetwetwerwerewrdfsds
srizvi9
 
PDF
BCP Lecturesdfdkjhfjshdkjfhskjd-ISO 22301.pdf
dharnashrivastavamcl
 
PDF
Business Continuity Management
Milan Petrásek
 
PPTX
BCMSBCMSBCMSBCMSBCMSBCMSBCMSBCMSBCMSBCMS
sarankamalanathan
 
PDF
Business continuity & disaster recovery
George Coutsoumbidis
 
PPT
Drp For Menora
Pini Cohen
 
PPTX
Building a Business Continuity Capability
Rod Davis
 
PPTX
Business continuity
abhijeethele15
 
PPTX
module-3-chapter-1-Business-Continu.pptx
DrUshaDivakarlaNMAMI
 
PDF
Business Continuity Management System ISO 22301:2012 An Overview
Ahmed Riad .
 
PPS
Business continuity management system overveiw
Naresh Rao
 
PDF
Cyber Security and Business Continuity an Integrated Discipline
Graeme Parker
 
ICTD Material PowerPoint Presentation Format.pptx
MahmoudElmahdy32
 
The Revere Group - Making A Case For Disaster Recovery
cadavis22
 
awareness bcp for manufacturing industry.pptx
shiva3305
 
BCP awareness ISO 22301 2019 training .pptx
shiva3305
 
Disaster recovery presentation for the servers
JohnsonPackiyaraj1
 
Business Continuity Plan TemplateCIO Maria Sosa has asked you to p.docx
felicidaddinwoodie
 
Awareness iso 22301 danang suryo
Danang suryo Wardhono
 
Developing and Managing Business Continuity Plan (BCP)
Goutama Bachtiar
 
sdfdsfsfsdfsdfsdfsdfssefsdfsdfsdfwteesfgrtertwetetwewetwetwerwerewrdfsds
srizvi9
 
BCP Lecturesdfdkjhfjshdkjfhskjd-ISO 22301.pdf
dharnashrivastavamcl
 
Business Continuity Management
Milan Petrásek
 
BCMSBCMSBCMSBCMSBCMSBCMSBCMSBCMSBCMSBCMS
sarankamalanathan
 
Business continuity & disaster recovery
George Coutsoumbidis
 
Drp For Menora
Pini Cohen
 
Building a Business Continuity Capability
Rod Davis
 
Business continuity
abhijeethele15
 
module-3-chapter-1-Business-Continu.pptx
DrUshaDivakarlaNMAMI
 
Business Continuity Management System ISO 22301:2012 An Overview
Ahmed Riad .
 
Business continuity management system overveiw
Naresh Rao
 
Cyber Security and Business Continuity an Integrated Discipline
Graeme Parker
 

Recently uploaded (20)

PDF
The Crystal Ball Chronicles - Battle of the Healers - Tran Quoc Bao the winner
Gorman Bain Capital
 
PDF
Asia’s Health Titans - Meet the Hospital CEOs Revolutionizing Care Across the...
Gorman Bain Capital
 
PDF
2019_10 The changing world of the Law Firm CFO
tanbir16
 
PPTX
AAccounts Prepration for Public Limited Companies
uneed1
 
PPTX
Active listening skills for school education
jara6896
 
PDF
40.-Rizal-And-Philippine-Identity-Formation.pdf
floreshaisheenlei
 
PDF
What tools can you use to build and manage a product roadmap?
Writegenic AI
 
PPT
IHRM(international human resource management) PPT NEW.ppt
Sunaina44
 
PPTX
Empowering Women Achieving Dreams Setting and Reaching Your Personal Profess...
Muhammad Musawar Ali
 
PPTX
1_Introduction_African and Caribbean Literatures.pptx
POORNIMAN26
 
PDF
How does risk management integrate with project control?
Writegenic AI
 
PPTX
ANIn Ahmedabad 2025 | Quality as Foundation of Business Agility: How QA Enabl...
AgileNetwork
 
PDF
2024_10 Approach to selecting a CPM Application
tanbir16
 
PPTX
SAP Security Road Map with the Strategic move
tomar2000
 
PDF
Dynamic Capabilities for a Sustainable Future
David Teece
 
PDF
PMI UK 31st July 2025 Presentation...pdf
PMIUKChapter
 
PDF
OBSTRUCTIONS OF TURKISH PUBLIC ORGANIZATIONS GETTING ISO/IEC 27001 CERTIFIED
ijmvsc
 
PDF
Situation Managment - Lesson in Krishna Way.pdf
Avijit Kumar Roy
 
PDF
Asia’s Healthcare Power Players - The Visionary CEOs Reshaping Medicine for 4...
Gorman Bain Capital
 
PPTX
ANIn Ahmedabad 2025 | Beyond Survival: Enabling Growth Mindset by Abhishek Bh...
AgileNetwork
 
The Crystal Ball Chronicles - Battle of the Healers - Tran Quoc Bao the winner
Gorman Bain Capital
 
Asia’s Health Titans - Meet the Hospital CEOs Revolutionizing Care Across the...
Gorman Bain Capital
 
2019_10 The changing world of the Law Firm CFO
tanbir16
 
AAccounts Prepration for Public Limited Companies
uneed1
 
Active listening skills for school education
jara6896
 
40.-Rizal-And-Philippine-Identity-Formation.pdf
floreshaisheenlei
 
What tools can you use to build and manage a product roadmap?
Writegenic AI
 
IHRM(international human resource management) PPT NEW.ppt
Sunaina44
 
Empowering Women Achieving Dreams Setting and Reaching Your Personal Profess...
Muhammad Musawar Ali
 
1_Introduction_African and Caribbean Literatures.pptx
POORNIMAN26
 
How does risk management integrate with project control?
Writegenic AI
 
ANIn Ahmedabad 2025 | Quality as Foundation of Business Agility: How QA Enabl...
AgileNetwork
 
2024_10 Approach to selecting a CPM Application
tanbir16
 
SAP Security Road Map with the Strategic move
tomar2000
 
Dynamic Capabilities for a Sustainable Future
David Teece
 
PMI UK 31st July 2025 Presentation...pdf
PMIUKChapter
 
OBSTRUCTIONS OF TURKISH PUBLIC ORGANIZATIONS GETTING ISO/IEC 27001 CERTIFIED
ijmvsc
 
Situation Managment - Lesson in Krishna Way.pdf
Avijit Kumar Roy
 
Asia’s Healthcare Power Players - The Visionary CEOs Reshaping Medicine for 4...
Gorman Bain Capital
 
ANIn Ahmedabad 2025 | Beyond Survival: Enabling Growth Mindset by Abhishek Bh...
AgileNetwork
 

Bcp drp

  • 1. The Importance Of Business Continuity And Disaster Recovery Planning By Aqel M. Aqel Information Systems Audit & Control Association Rolling Meadows Illinois –USA (www.isaca.org) CISA –Coordinator / Research Director -Riyadh Chapter Dec 2014
  • 2. Why BCP & DRP •Successful businesses expect the unexpected and plan for it. •Disruptions to your business can result in: •Data risk, •Revenue loss, •Failure to deliver services •That’s why organizations need strong business continuity planning. John Sharp, 2012,The Route Map to Business Continuity Management: Meeting the Requirements of ISO 22301’ by A Good Plan Increases Your Chances of Recovery
  • 3. Concepts and Terminology •Business continuitydescribes the processes and procedures an organization must put in place to ensure that mission-critical functions can continue during and after a disaster. •Disaster recoveryrefers to specific steps taken to resume operations in the aftermath of a catastrophic disaster (natural or national emergency)
  • 4. Reasons behind Disasters •Environmental Disasters •Tornado& Hurricane •Power Grid Failure •Flood •Snowstorm •Earthquake •Electrical storms •Fire •Fire •Sink Holes •Landslides Man Made Disruptions Terrorist Attack Sabotage التخريب War / Theft Arson الحريق المتعمد Labor Disputes Equipment or System Failure Internal power failure Air conditioning failure Cooling plant failure Equipment failure IT Failures and Security Breaches Cyber crime Loss of records or data Disclosure of sensitive information IT system failure
  • 5. More Concepts and Terminology Recovery Point Objective(RPO) measures the ability to recover files by specifying a point in time restore of the backup copy. Recovery Time Objective(RTO)measures the time that it takes for a system to be completely up and running in the event of a disaster. Source: Network Servers 2011
  • 6. More Concepts and Terminology •Recovery Point Objective(RPO) measures the ability to recover files by specifying a point in time restore of the backup copy.i.e. •Amount of data lost from failure, measured as the amount of time from a disaster event •It's determined by the amount of time between data protection events and reflects the amount of data that potentially could be lost during a disaster recovery. •The metric is an indication of the amount of data at risk of being lost. •Recovery Time Objective(RTO)measures the time that it takes for a system to be completely up and running in the event of a disaster. i.e. •Targeted amount of time to restart a business service after a disaster event. •It is related to downtime. The metric refers to the amount of time it takes to recover from a data loss event and how long it takes to return to service. •RTO refers then to the amount of time the system's data is unavailable or inaccessible preventing normal service.
  • 8. RTO and RPO Source: http://wikibon.org/w/images/0/04/RPO_RTO_Horison.jpg
  • 9. Facts •The US Chamber of Commerce reported that: •the economic losses in 2011, as a result of natural disasters, reached $380 million. •Federal Emergency Management Agency (www.fema.gov) reports: •40-60% of businesses that close due to disaster never reopen!! (source: https://telovations.wordpress.com/tag/revenue-lost-due-to-natural-disaster/
  • 10. Facts Source: FreeFormDynamics 2011 •Only 23% of Respondents said: yes, there is a formal DR plan in place.
  • 14. Facts •What part of IT infrastructures are covered by BC/DR plans Source: Howard Marks (2008) http://www.informationweek.com/practical-disaster-recovery-for-midsize-companies/d/d-id/1075012?
  • 15. Facts Source: Howard Marks (2008) http://www.informationweek.com/practical-disaster-recovery-for-midsize-companies/d/d-id/1075012? •What are the barriers to adoption of a business continuity plan? •Cost and complexity are •Lack of skills is a reason as well.
  • 16. Facts http://www.crn.com/slide-shows/storage/240006796/8-surprising-disaster-recovery-stats.htm/pgno/0/7 86% of companies experienced one or more instances of system downtime in the previous 12 months. Downtimes lasted 2.2 days on the average and cost each business an average of $366,363 a year. 33% of businesses admitted they do not back up virtual servers as often as they do their physical servers.
  • 17. Policies Support Motivation Sponsoring & follow up Procedures Policies Tools Roles and Responsibilities Methodologies / Best Practices Training Validation Audit Programs Reports Awareness Source: Aqel M. Aqel, IT Security in your firm, what is it, & how to achieve it. (2011). Monitoring Execution Leadership Actionable model
  • 18. ISO 22301 In 2012, BCI in partnership with BSI launch of ISO 22301, the new global standard for business continuity management.
  • 19. ISO 22301 •Provides a comprehensive set of controls based on BCM best practice. •Covets the whole BCM lifecycle. •Defines the strategic and tactical capability of an organization to plan for and respond to incidents. •It is generic and offers organizations guidance on putting their BCM systems in place.
  • 20. ISO 22301 –2012 key Clauses •Clause 1:Scope •Clause 2:Normative References •Clause 3:Terms and Conditions •Clause 4:Context of the organization •Clause 5:Leadership •Clause 6:Planning •Clause 7:Support •Clause 8:Operation •Clause 9:Performance evaluation •Clause 10: Improvement
  • 21. ISO 22301 -Clause 4:Context of the organization
  • 22. ISO 22301 –Clause 5:Leadership •Top management needs to demonstrate an ongoing commitment to the BCMS. •Integrating the BCMS requirements into the organization’s business processes •Providing the necessary resources for the BCMS •Communicating the importance of effective business continuity management •Ensuring that the BCMS achieves its expected outcomes •Directing and supporting continual improvement •Establish and communicate a business continuity policy •Ensuring that BCMS objectives and plans are established •Ensuring that the responsibilities and authorities for relevant roles are assigned
  • 23. ISO 22301 –Clause 6:Planning •Establishing strategic objectives and guiding principles for the BCMS. •The business continuity objectives must: be consistent with the business continuity policy; •Ttakeinto account the minimum level of products and services that is acceptable to the organization to achieve its objectives; •be measurable; •take into account applicable requirements; •be monitored and updated as appropriate
  • 24. ISO 22301 –Clause 7:Support •Using the appropriate resources for each task. •Competent staff with relevant (and demonstrable) •Training and supporting services •Awareness and communication. •Both internal and external communications of the organization must be considered in this area. •The requirements on the creation, update and control of documented information are also specified in this clause.
  • 25. ISO 22301 –Clause 8:Operation •Business Impact Analysis (BIA): •Risk assessment •Business continuity strategy: •Business continuity procedures: •Exercising and testing
  • 26. ISO 22301 –Clause 9:Performance evaluation •ISO 22301 requires permanent monitoring of the system as well as periodic reviews to improve its operation: •monitoring the extent to which the organization’s business continuity policy, objectives and targets are met; •measuring the performance of the processes, procedures and functions that protect its prioritized activities; •monitoring compliance with this standard and the business continuity objectives; •monitoring historical evidence of deficient BCMS’ performance •conducting internal audits at planned intervals; and •evaluating all this in the management review at planned intervals.
  • 27. ISO 22301 –Clause 10: Improvement •Continual improvement: •all the actions taken throughout the organization to increase effectiveness (reaching objectives) and efficiency (an optimal cost/benefit ratio) of security processes and controls to bring increased benefits to the organization and its stakeholders.
  • 28. More information •The American Institute of Certified Public Accountants (AICPA) •Information Systems Audit and Control Association (ISACA) •Association of Information Technology Professionals (AITP) •Institute of Internal Auditors (IIA) •International Association for Computer Information Systems (IACIS) •Information Systems Security Association (ISSA) •International Disaster Recovery Association (IDRA) •Business Recovery Managers Association (BRMA) •British Standards Institute (BSI) •http://www.slideshare.net/AhmedRiad2/ss-38345026