SlideShare a Scribd company logo
Alphabet Soup – A(utomation), BC(Business
Continuity) and DR (Disaster Recovery)
Christopher Rogers
Senior Technical Advisor, Intelligent Infrastructure
Internetwork Engineering
Agenda
• BC or DR? Defined….
• Business Continuity (BC)
• Disaster Recovery (DR)
• What about “Cloud”?
• Other Thoughts
• Automation
• Conclusion
What does it take to make a great soup?
A good base – maybe start with the trinity
(onions, celery, and bell peppers) sautéed
A good broth (probably chicken)
Layer in other flavors and ingredients
• How many have a DR Plan?
• How many have a BC Strategy?
• How many thought they had a BC Strategy because they had a DR Plan?
• May not be you, but what about others in your organization?
• How many are performing some type of automation in IT?
Quick Status Check
What does
it take to
have good
BC/DR
“soup”
BC or DR? Defined…
The processes, procedures,
and solutions needed to make
sure an organization can
continue to function
The plan an organization has in
place to recover data or
technology losses
Business Continuity Disaster Recovery
Business Continuity
Disaster
Recovery
Focused on planning for the
restoration and recovery of any
technology functionality or data
that was lost
Focused on risk analysis and
planning to ensure the
business can continue to
operate
Organizational
Arrangement of
BC and DR
Business Continuity Questions
• What is the organization’s primary function?
• What secondary functions support the primary
function?
• How does the organization perform its function?
• What processes and procedures that govern this
function?
• Are these functions offered virtually? Online,
telephone?
• Are there compliance/legal requirements that govern
how the functions are performed?
• Where do employees perform their job functions?
• Do they come to a brick and mortar?
• What do they use to perform their job functions?
Business Continuity Questions context
• What is the organization’s primary function?
• What is the impact/result of this function not being performed? Can the loss be quantified?
• Who (what) is affected by the loss of the primary function? How long can the constituents
continue without this function?
• What secondary functions support the primary function?
• Are these secondary functions essential to the operation of the primary function? What is the
operational impact of operating without a given secondary function?
• How does the organization perform this function
• What processes and procedures that govern this function? Essential processes?
• Can and are these functions offered virtually? Online, telephone? Require employee
interaction?
• Are there compliance/legal requirements that govern how the functions are performed?
• What requirements govern these functions? If necessary, can special operating procedures be
implemented?
• Where do employees perform their job functions?
• Do they HAVE come to a brick and mortar? If so has a location been identified?
• What do they use to perform their job functions? How do they work?
• No brick and mortar? Can they work virtually, What do they need to work virtually, Are
process changes needed to work virtually?
• May have to make hard decisions
• Not all business functions are truly necessary to support primary function
• Understand how to re-incorporate secondary business functions and impact
• Incident Response – Is your incident response incorporated?
Key Ingredient:
1) Know the top (up to 5)
critical function(s) of the
organization.
2) Think like a business,
what is the bare minimum
need to stay in operation
during the event and after
the event.
3) Incident Response
Why BC Strategy
– Scenarios
• Pandemic
• Regional Disaster
• Primary (Only) Site
• Many others …
Disaster Recovery Questions
• How is the organization’s primary function impacted by loss of
technology?
• What technology services support the organization’s primary
function?
• Is technology service dependency understood?
• What technology services support the organization’s secondary
functions?
• What compliance/legal requirements govern technology services?
• Are Service Level Agreements between organizational groups and the
technology group in place?
• What is the expected RPO (Recovery Point Objective)?
• What is the expected RTO (Recovery Time Objective)?
Disaster Recovery Questions context
• How is the organization’s primary function impacted by loss of technology?
• Can the primary function be performed without technology? If so, for how long? What is the perception
if technology services are lost?
• What technology services support the organization’s primary function?
• Is technology service dependency understood and documented? Have all technology services that
support the function been identified? Rank services, Know the order of service resumption, Understand
prerequisites for services
• What technology services support the organization’s secondary functions? Ask same questions
• What compliance/legal requirements govern technology services? What impact do compliance/legal
requirements have? How do requirements impact ability to perform disaster recovery?
• Are there DOCUMENTED Service Level Agreements (SLAs) between organizational groups and the
technology group in place? Does the organization understand the impact of fulfilling the SLAs?
(BC quantifies loss of ability to perform primary function)
• What is the expected RPO (Recovery Point Objective)? How much data loss is acceptable?
• What is the expected RTO (Recovery Time Objective)? How quickly do the technology services need to
be restored?
• Have to make hard decisions
• Not all technology services will be required for primary function
• Understand how to re-incorporate secondary services and impact
• In House - Start Small
• One Application that supports primary function or major secondary function
• Preferably one that has well documented guidelines and recommendations for DR
• Seek Assistance – Still Start Small
• Onboarding – As Applications are added or replaced – Assess and incorporate into DR
• Incident Response – Align your cybersecurity IR process with DR
Key Ingredient(s):
1) Know technological
dependencies for the top
(up to 5) function(s)
2) Availability path for the
technological
dependencies
3) Incident Response
Why DR Plan – Scenarios
• Localized (DC Center) Issues
• Ransomware – Malicious behavior
• Human Error
• Many others …
What About the “Cloud”?
• Primary Technology Platform
• IaaS, PaaS, SaaS, DaaS, BaaS, DRaaS
• Business Continuity
• Provide worker access to IT Resources (DaaS)
• DR
• IaaS, PaaS, SaaS, DRaaS, BaaS
• Things to think about
• Backups
• Provide redundancy – not backups
• Disaster Recovery
• Provide redundancy – but not normally beyond site
unless chosen
• Data Movement
• Free to bring in – Pay to leave
• Alternative Cloud https://docs.microsoft.com/en-
us/azure/architecture/resiliency/disas
ter-recovery-azure-applications
Things to think about
• Practice, Practice, Practice
• More Practice
• People
• Where are they?
• Are they affected by the situation?
• To what extent are they affected?
• What is the personal effect on them?
• Will they be able to fulfill their duties?
• Third Party
• Logistical
• Physical Access
• Card Access?
• Disaster causes card process to fail?
• Impassable?
• Documentation – secondary copy?
• BC/DR Equipment
• Understand where you are in CIP (Critical Infrastructure Protection)
• https://www.dhs.gov/what-critical-infrastructure
Automation
• Why Automation?
• Get things done faster!?!
• Steps to Automation –
• Looks for repetitive tasks
• Understand what we want to automate
• Document the process
• Standardize the process
• Utilize best practice
• Results of Automation
• Faster deployment
• Documented deployment
• Consistent deployment – less human error
• Better maintenance processes – help stay up to date
Automation – Reservations
• We’re too small organization – Don’t need Automation
• Moving to the Cloud
• Don’t have a mature IT process or governance
• Automate myself out of a job 
• Automate yourself into a disaster!?
• Build out in layers
• Treat like Dev Process – Test, Test, Test (not in Production )
• Where to start
• Semi-automate processes
• Change Management
• Request and approval
• Update BC/DR
• MAC (Moves, Adds, Changes)
• Information gathering
• Existing setups and configurations
• Topology
Automation – Impact
• BC/DR Impact
• Documented process for service restoration
• Known good configuration state
• Systematic restoration
• Faster restoration time
• Organizational Results
• Business continuity strategy and disaster recovery plan can be better maintained
• Less downtime of mission critical applications when a disaster or unexpected event
occurs
• Reduced risk of downtime due to human error
• Confidence that the recovery process is solid
• Reduced risk of recovery process failure due to inaccurate information or human
error
Key Ingredient:
Automation can make
your BC/DR process
better.
Conclusion
• What are the top 5 critical functions of the
organization. If the organization were a business,
what is the bare minimum it would take to stay in
business during the event and after the event.
• What technological dependencies do those top 5
functions require?
• What is the availability path for the technological
dependencies, should an event occur? Meaning, if an
event affects those resources, what is the
contingency.
• Incident Response
• Know how it integrates
• IR may require BC or DR to be put in motion
• Automation – Its your friend 
Thank you!
Questions?
Christopher Rogers
SeniorTechnical Advisor – Intelligent Infrastructure
SNR (704) 944-0072 | crogers@ineteng.com
Raleigh Security Users Group (Quarterly) – next mtg 6/7
Charlotte Security Users Group (Bi-monthly) – next mtg 6/22
www.ineteng.com/events

More Related Content

PDF
IBM Power Migration without the Risk and Downtime
Precisely
 
PDF
Brighttalk high scale low touch and other bedtime stories - final
Andrew White
 
PPTX
IT Automation Assessment Report - sample
Evergreen Systems
 
PPTX
What to expect from your IT People
Jason Caras
 
PDF
CRMready Webinar Series - Part 2 - Planning Ahead for CRM at Your Nonprofit
TheConnectedCause
 
PPTX
SharePoint Operations Framework - Planning and Guidance
Chandima Kulathilake
 
PDF
Brighttalk understanding the promise of sde - final
Andrew White
 
PDF
How Judson ISD Implemented and Tracks IT Metrics & Key Performance Indicators
Steve Young
 
IBM Power Migration without the Risk and Downtime
Precisely
 
Brighttalk high scale low touch and other bedtime stories - final
Andrew White
 
IT Automation Assessment Report - sample
Evergreen Systems
 
What to expect from your IT People
Jason Caras
 
CRMready Webinar Series - Part 2 - Planning Ahead for CRM at Your Nonprofit
TheConnectedCause
 
SharePoint Operations Framework - Planning and Guidance
Chandima Kulathilake
 
Brighttalk understanding the promise of sde - final
Andrew White
 
How Judson ISD Implemented and Tracks IT Metrics & Key Performance Indicators
Steve Young
 

What's hot (20)

PPT
Feb2007 Kelly Services Hdi Chapter Meeting 020807 Public Domain
IT Service and Support
 
PDF
Segregation of Duties and Continuous Delivery
Sriram Narayanan
 
PDF
ITIL and CMMI for service
BoonNam Goh
 
PDF
ITIL & CMMI for Services
NUS-ISS
 
PDF
Daniel Breston - DevOps metrics that matter
itSMF UK
 
PPT
Concepts of cutover planning and management
Sanjay Choubey
 
PDF
It's the organisation, Stupid
John M Walsh
 
PPTX
MY BUSINESS - MY IT - MY ITSM
Aditya Dashora
 
PPT
Improving Performance Improvement (Market Requirements Document - MRD)
Adam "AB" Bloom
 
PDF
Andrew Shepherd - Rethink the service desk role to change its image forever
itSMF UK
 
PDF
Steve Chambers - Cloud for GrownUps ITSM17
itSMF UK
 
PDF
Operating a Highly Available Cloud Service
Depankar Neogi
 
PDF
Sage People Migration
Net at Work
 
PPT
6 service operation
sagaroceanic11
 
PPTX
Group b opm-ppt_final
Mayur Challawar
 
PDF
Are processes masquerading as projects hurting your business
Ben Bradley
 
PPT
Office Lean Overview
ahmad bassiouny
 
PDF
La gouvernance au cœur de la transformation numérique - Comment COBIT 5 peut ...
Antoine Vigneron
 
PDF
Process modeling in agile environment alec sharp
Loihde Advisory
 
PPT
Aces 405 - Team that actually saved the most money..!!
Satwinder Singh
 
Feb2007 Kelly Services Hdi Chapter Meeting 020807 Public Domain
IT Service and Support
 
Segregation of Duties and Continuous Delivery
Sriram Narayanan
 
ITIL and CMMI for service
BoonNam Goh
 
ITIL & CMMI for Services
NUS-ISS
 
Daniel Breston - DevOps metrics that matter
itSMF UK
 
Concepts of cutover planning and management
Sanjay Choubey
 
It's the organisation, Stupid
John M Walsh
 
MY BUSINESS - MY IT - MY ITSM
Aditya Dashora
 
Improving Performance Improvement (Market Requirements Document - MRD)
Adam "AB" Bloom
 
Andrew Shepherd - Rethink the service desk role to change its image forever
itSMF UK
 
Steve Chambers - Cloud for GrownUps ITSM17
itSMF UK
 
Operating a Highly Available Cloud Service
Depankar Neogi
 
Sage People Migration
Net at Work
 
6 service operation
sagaroceanic11
 
Group b opm-ppt_final
Mayur Challawar
 
Are processes masquerading as projects hurting your business
Ben Bradley
 
Office Lean Overview
ahmad bassiouny
 
La gouvernance au cœur de la transformation numérique - Comment COBIT 5 peut ...
Antoine Vigneron
 
Process modeling in agile environment alec sharp
Loihde Advisory
 
Aces 405 - Team that actually saved the most money..!!
Satwinder Singh
 
Ad

Similar to Alphabet Soup: A(utomation), BC (Business Continuity) and DR (Disaster Recovery (20)

PPT
Disaster Biz Resumpt
JimGroark
 
PPT
Fulcrum Group- Layer Your DR/BC
Steve Meek
 
PPTX
Building a Business Continuity Capability
Rod Davis
 
PPT
Disaster recovery presentation for the servers
JohnsonPackiyaraj1
 
PPTX
module-3-chapter-1-Business-Continu.pptx
DrUshaDivakarlaNMAMI
 
PPTX
Bcp
madunix
 
PPT
Risk Based Approach To Recovery And Continuity Management John P Morency
jmorency1952
 
PDF
Disaster Recovery - Deep Dive
Envision Technology Advisors
 
PDF
OSBConf 2016: Building a Business Continuity Plan with Bareos and Rear - by G...
NETWAYS
 
PPT
Business continuity and disaster recovery
Adeel Javaid
 
PDF
Business Continuity Planning with Bareos and rear (Loadays 2015)
Gratien D'haese
 
PPTX
Protecting Against Disaster: Plan for the Inevitable Before it Happens
Hostway|HOSTING
 
PPTX
Varrow Madness 2014 DR Presentation
Andrew Miller
 
PDF
The Nuts and Bolts of Disaster Recovery
InnoTech
 
PDF
S014072 business-continuity-orlando-v1705e
Tony Pearson
 
PDF
S016386 business-continuity-melbourne-v1708c
Tony Pearson
 
PDF
Business Continuity And Disaster Recovery Are Top IT Priorities For 2010 And ...
Citrix Online
 
PPTX
Business continuity
abhijeethele15
 
PPT
Business Continuity Workshop Final
Bill Lisse
 
PPT
What is business continuity planning-bcp
Adv Prashant Mali
 
Disaster Biz Resumpt
JimGroark
 
Fulcrum Group- Layer Your DR/BC
Steve Meek
 
Building a Business Continuity Capability
Rod Davis
 
Disaster recovery presentation for the servers
JohnsonPackiyaraj1
 
module-3-chapter-1-Business-Continu.pptx
DrUshaDivakarlaNMAMI
 
Bcp
madunix
 
Risk Based Approach To Recovery And Continuity Management John P Morency
jmorency1952
 
Disaster Recovery - Deep Dive
Envision Technology Advisors
 
OSBConf 2016: Building a Business Continuity Plan with Bareos and Rear - by G...
NETWAYS
 
Business continuity and disaster recovery
Adeel Javaid
 
Business Continuity Planning with Bareos and rear (Loadays 2015)
Gratien D'haese
 
Protecting Against Disaster: Plan for the Inevitable Before it Happens
Hostway|HOSTING
 
Varrow Madness 2014 DR Presentation
Andrew Miller
 
The Nuts and Bolts of Disaster Recovery
InnoTech
 
S014072 business-continuity-orlando-v1705e
Tony Pearson
 
S016386 business-continuity-melbourne-v1708c
Tony Pearson
 
Business Continuity And Disaster Recovery Are Top IT Priorities For 2010 And ...
Citrix Online
 
Business continuity
abhijeethele15
 
Business Continuity Workshop Final
Bill Lisse
 
What is business continuity planning-bcp
Adv Prashant Mali
 
Ad

More from Internetwork Engineering (IE) (9)

PPTX
2019 Cybersecurity Threats & Trends: The Chart Toppers & One-hit Wonders
Internetwork Engineering (IE)
 
PPTX
2019 UNC Cause Session - Dennis Holmes - WiFi & Mobility Technology for Safer...
Internetwork Engineering (IE)
 
PPTX
Re-inventing the Wireless Network | 2019 Tri-State Technology Conference Pres...
Internetwork Engineering (IE)
 
PPTX
2019 NCLGISA Spring Cybersecurity Threats & Trends: Blended Threats and Smart...
Internetwork Engineering (IE)
 
PPTX
2019 Cyber Security Trends
Internetwork Engineering (IE)
 
PPTX
Eliminating the Confusion Surrounding Cyber Insurance
Internetwork Engineering (IE)
 
PPT
Lessons Learned from the Field: CyberSecurity that Works - Jason Smith Ses...
Internetwork Engineering (IE)
 
PPTX
Delivering an Exceptional Wireless Classroom Experience - Dennis Holmes Sessi...
Internetwork Engineering (IE)
 
PPTX
Building & Updating an Incident Response Plan - Jason Smith Session - 2018 Ch...
Internetwork Engineering (IE)
 
2019 Cybersecurity Threats & Trends: The Chart Toppers & One-hit Wonders
Internetwork Engineering (IE)
 
2019 UNC Cause Session - Dennis Holmes - WiFi & Mobility Technology for Safer...
Internetwork Engineering (IE)
 
Re-inventing the Wireless Network | 2019 Tri-State Technology Conference Pres...
Internetwork Engineering (IE)
 
2019 NCLGISA Spring Cybersecurity Threats & Trends: Blended Threats and Smart...
Internetwork Engineering (IE)
 
2019 Cyber Security Trends
Internetwork Engineering (IE)
 
Eliminating the Confusion Surrounding Cyber Insurance
Internetwork Engineering (IE)
 
Lessons Learned from the Field: CyberSecurity that Works - Jason Smith Ses...
Internetwork Engineering (IE)
 
Delivering an Exceptional Wireless Classroom Experience - Dennis Holmes Sessi...
Internetwork Engineering (IE)
 
Building & Updating an Incident Response Plan - Jason Smith Session - 2018 Ch...
Internetwork Engineering (IE)
 

Recently uploaded (20)

PDF
Unlocking the Future- AI Agents Meet Oracle Database 23ai - AIOUG Yatra 2025.pdf
Sandesh Rao
 
PDF
Data_Analytics_vs_Data_Science_vs_BI_by_CA_Suvidha_Chaplot.pdf
CA Suvidha Chaplot
 
PDF
AI-Cloud-Business-Management-Platforms-The-Key-to-Efficiency-Growth.pdf
Artjoker Software Development Company
 
PDF
Cloud-Migration-Best-Practices-A-Practical-Guide-to-AWS-Azure-and-Google-Clou...
Artjoker Software Development Company
 
PDF
Research-Fundamentals-and-Topic-Development.pdf
ayesha butalia
 
PDF
AI Unleashed - Shaping the Future -Starting Today - AIOUG Yatra 2025 - For Co...
Sandesh Rao
 
PDF
How Open Source Changed My Career by abdelrahman ismail
a0m0rajab1
 
PDF
SparkLabs Primer on Artificial Intelligence 2025
SparkLabs Group
 
PDF
Event Presentation Google Cloud Next Extended 2025
minhtrietgect
 
PDF
Advances in Ultra High Voltage (UHV) Transmission and Distribution Systems.pdf
Nabajyoti Banik
 
PDF
Security features in Dell, HP, and Lenovo PC systems: A research-based compar...
Principled Technologies
 
PDF
Google I/O Extended 2025 Baku - all ppts
HusseinMalikMammadli
 
PPTX
The-Ethical-Hackers-Imperative-Safeguarding-the-Digital-Frontier.pptx
sujalchauhan1305
 
PDF
How-Cloud-Computing-Impacts-Businesses-in-2025-and-Beyond.pdf
Artjoker Software Development Company
 
PDF
A Strategic Analysis of the MVNO Wave in Emerging Markets.pdf
IPLOOK Networks
 
PDF
Structs to JSON: How Go Powers REST APIs
Emily Achieng
 
PDF
Doc9.....................................
SofiaCollazos
 
PDF
The Future of Mobile Is Context-Aware—Are You Ready?
iProgrammer Solutions Private Limited
 
PDF
Brief History of Internet - Early Days of Internet
sutharharshit158
 
PDF
Get More from Fiori Automation - What’s New, What Works, and What’s Next.pdf
Precisely
 
Unlocking the Future- AI Agents Meet Oracle Database 23ai - AIOUG Yatra 2025.pdf
Sandesh Rao
 
Data_Analytics_vs_Data_Science_vs_BI_by_CA_Suvidha_Chaplot.pdf
CA Suvidha Chaplot
 
AI-Cloud-Business-Management-Platforms-The-Key-to-Efficiency-Growth.pdf
Artjoker Software Development Company
 
Cloud-Migration-Best-Practices-A-Practical-Guide-to-AWS-Azure-and-Google-Clou...
Artjoker Software Development Company
 
Research-Fundamentals-and-Topic-Development.pdf
ayesha butalia
 
AI Unleashed - Shaping the Future -Starting Today - AIOUG Yatra 2025 - For Co...
Sandesh Rao
 
How Open Source Changed My Career by abdelrahman ismail
a0m0rajab1
 
SparkLabs Primer on Artificial Intelligence 2025
SparkLabs Group
 
Event Presentation Google Cloud Next Extended 2025
minhtrietgect
 
Advances in Ultra High Voltage (UHV) Transmission and Distribution Systems.pdf
Nabajyoti Banik
 
Security features in Dell, HP, and Lenovo PC systems: A research-based compar...
Principled Technologies
 
Google I/O Extended 2025 Baku - all ppts
HusseinMalikMammadli
 
The-Ethical-Hackers-Imperative-Safeguarding-the-Digital-Frontier.pptx
sujalchauhan1305
 
How-Cloud-Computing-Impacts-Businesses-in-2025-and-Beyond.pdf
Artjoker Software Development Company
 
A Strategic Analysis of the MVNO Wave in Emerging Markets.pdf
IPLOOK Networks
 
Structs to JSON: How Go Powers REST APIs
Emily Achieng
 
Doc9.....................................
SofiaCollazos
 
The Future of Mobile Is Context-Aware—Are You Ready?
iProgrammer Solutions Private Limited
 
Brief History of Internet - Early Days of Internet
sutharharshit158
 
Get More from Fiori Automation - What’s New, What Works, and What’s Next.pdf
Precisely
 

Alphabet Soup: A(utomation), BC (Business Continuity) and DR (Disaster Recovery

  • 1. Alphabet Soup – A(utomation), BC(Business Continuity) and DR (Disaster Recovery) Christopher Rogers Senior Technical Advisor, Intelligent Infrastructure Internetwork Engineering
  • 2. Agenda • BC or DR? Defined…. • Business Continuity (BC) • Disaster Recovery (DR) • What about “Cloud”? • Other Thoughts • Automation • Conclusion
  • 3. What does it take to make a great soup? A good base – maybe start with the trinity (onions, celery, and bell peppers) sautéed A good broth (probably chicken) Layer in other flavors and ingredients
  • 4. • How many have a DR Plan? • How many have a BC Strategy? • How many thought they had a BC Strategy because they had a DR Plan? • May not be you, but what about others in your organization? • How many are performing some type of automation in IT? Quick Status Check
  • 5. What does it take to have good BC/DR “soup”
  • 6. BC or DR? Defined… The processes, procedures, and solutions needed to make sure an organization can continue to function The plan an organization has in place to recover data or technology losses Business Continuity Disaster Recovery Business Continuity Disaster Recovery Focused on planning for the restoration and recovery of any technology functionality or data that was lost Focused on risk analysis and planning to ensure the business can continue to operate
  • 8. Business Continuity Questions • What is the organization’s primary function? • What secondary functions support the primary function? • How does the organization perform its function? • What processes and procedures that govern this function? • Are these functions offered virtually? Online, telephone? • Are there compliance/legal requirements that govern how the functions are performed? • Where do employees perform their job functions? • Do they come to a brick and mortar? • What do they use to perform their job functions?
  • 9. Business Continuity Questions context • What is the organization’s primary function? • What is the impact/result of this function not being performed? Can the loss be quantified? • Who (what) is affected by the loss of the primary function? How long can the constituents continue without this function? • What secondary functions support the primary function? • Are these secondary functions essential to the operation of the primary function? What is the operational impact of operating without a given secondary function? • How does the organization perform this function • What processes and procedures that govern this function? Essential processes? • Can and are these functions offered virtually? Online, telephone? Require employee interaction? • Are there compliance/legal requirements that govern how the functions are performed? • What requirements govern these functions? If necessary, can special operating procedures be implemented? • Where do employees perform their job functions? • Do they HAVE come to a brick and mortar? If so has a location been identified? • What do they use to perform their job functions? How do they work? • No brick and mortar? Can they work virtually, What do they need to work virtually, Are process changes needed to work virtually? • May have to make hard decisions • Not all business functions are truly necessary to support primary function • Understand how to re-incorporate secondary business functions and impact • Incident Response – Is your incident response incorporated? Key Ingredient: 1) Know the top (up to 5) critical function(s) of the organization. 2) Think like a business, what is the bare minimum need to stay in operation during the event and after the event. 3) Incident Response
  • 10. Why BC Strategy – Scenarios • Pandemic • Regional Disaster • Primary (Only) Site • Many others …
  • 11. Disaster Recovery Questions • How is the organization’s primary function impacted by loss of technology? • What technology services support the organization’s primary function? • Is technology service dependency understood? • What technology services support the organization’s secondary functions? • What compliance/legal requirements govern technology services? • Are Service Level Agreements between organizational groups and the technology group in place? • What is the expected RPO (Recovery Point Objective)? • What is the expected RTO (Recovery Time Objective)?
  • 12. Disaster Recovery Questions context • How is the organization’s primary function impacted by loss of technology? • Can the primary function be performed without technology? If so, for how long? What is the perception if technology services are lost? • What technology services support the organization’s primary function? • Is technology service dependency understood and documented? Have all technology services that support the function been identified? Rank services, Know the order of service resumption, Understand prerequisites for services • What technology services support the organization’s secondary functions? Ask same questions • What compliance/legal requirements govern technology services? What impact do compliance/legal requirements have? How do requirements impact ability to perform disaster recovery? • Are there DOCUMENTED Service Level Agreements (SLAs) between organizational groups and the technology group in place? Does the organization understand the impact of fulfilling the SLAs? (BC quantifies loss of ability to perform primary function) • What is the expected RPO (Recovery Point Objective)? How much data loss is acceptable? • What is the expected RTO (Recovery Time Objective)? How quickly do the technology services need to be restored? • Have to make hard decisions • Not all technology services will be required for primary function • Understand how to re-incorporate secondary services and impact • In House - Start Small • One Application that supports primary function or major secondary function • Preferably one that has well documented guidelines and recommendations for DR • Seek Assistance – Still Start Small • Onboarding – As Applications are added or replaced – Assess and incorporate into DR • Incident Response – Align your cybersecurity IR process with DR Key Ingredient(s): 1) Know technological dependencies for the top (up to 5) function(s) 2) Availability path for the technological dependencies 3) Incident Response
  • 13. Why DR Plan – Scenarios • Localized (DC Center) Issues • Ransomware – Malicious behavior • Human Error • Many others …
  • 14. What About the “Cloud”? • Primary Technology Platform • IaaS, PaaS, SaaS, DaaS, BaaS, DRaaS • Business Continuity • Provide worker access to IT Resources (DaaS) • DR • IaaS, PaaS, SaaS, DRaaS, BaaS • Things to think about • Backups • Provide redundancy – not backups • Disaster Recovery • Provide redundancy – but not normally beyond site unless chosen • Data Movement • Free to bring in – Pay to leave • Alternative Cloud https://docs.microsoft.com/en- us/azure/architecture/resiliency/disas ter-recovery-azure-applications
  • 15. Things to think about • Practice, Practice, Practice • More Practice • People • Where are they? • Are they affected by the situation? • To what extent are they affected? • What is the personal effect on them? • Will they be able to fulfill their duties? • Third Party • Logistical • Physical Access • Card Access? • Disaster causes card process to fail? • Impassable? • Documentation – secondary copy? • BC/DR Equipment • Understand where you are in CIP (Critical Infrastructure Protection) • https://www.dhs.gov/what-critical-infrastructure
  • 16. Automation • Why Automation? • Get things done faster!?! • Steps to Automation – • Looks for repetitive tasks • Understand what we want to automate • Document the process • Standardize the process • Utilize best practice • Results of Automation • Faster deployment • Documented deployment • Consistent deployment – less human error • Better maintenance processes – help stay up to date
  • 17. Automation – Reservations • We’re too small organization – Don’t need Automation • Moving to the Cloud • Don’t have a mature IT process or governance • Automate myself out of a job  • Automate yourself into a disaster!? • Build out in layers • Treat like Dev Process – Test, Test, Test (not in Production ) • Where to start • Semi-automate processes • Change Management • Request and approval • Update BC/DR • MAC (Moves, Adds, Changes) • Information gathering • Existing setups and configurations • Topology
  • 18. Automation – Impact • BC/DR Impact • Documented process for service restoration • Known good configuration state • Systematic restoration • Faster restoration time • Organizational Results • Business continuity strategy and disaster recovery plan can be better maintained • Less downtime of mission critical applications when a disaster or unexpected event occurs • Reduced risk of downtime due to human error • Confidence that the recovery process is solid • Reduced risk of recovery process failure due to inaccurate information or human error Key Ingredient: Automation can make your BC/DR process better.
  • 19. Conclusion • What are the top 5 critical functions of the organization. If the organization were a business, what is the bare minimum it would take to stay in business during the event and after the event. • What technological dependencies do those top 5 functions require? • What is the availability path for the technological dependencies, should an event occur? Meaning, if an event affects those resources, what is the contingency. • Incident Response • Know how it integrates • IR may require BC or DR to be put in motion • Automation – Its your friend 
  • 20. Thank you! Questions? Christopher Rogers SeniorTechnical Advisor – Intelligent Infrastructure SNR (704) 944-0072 | [email protected] Raleigh Security Users Group (Quarterly) – next mtg 6/7 Charlotte Security Users Group (Bi-monthly) – next mtg 6/22 www.ineteng.com/events