Business Continuity Plan Executive Overview

Size: px
Start display at page:

Download "Business Continuity Plan Executive Overview"

Transcription

1 Business Continuity Plan Executive Overview In terms of business continuity and disaster recovery planning, Harland Clarke s mission is to ensure the availability of critical business functions and Information Technology (IT) operations within acceptable timeframes should a disaster or outage affect one or more of our facilities or operations. Harland Clarke s plan is developed to meet the criteria and sound practices of the Federal Financial Institution Examination Council (FFIEC) interagency statement on contingency planning. The planning approach has the following features: Proactively evaluating risks and mitigating their effect through implementation of loss control counter measures, e.g., cyber risks & internet security provisions Annually updating the business impact analyses for prioritization of core processing and customer service functions and their information and service dependencies. Reviewing the plan quarterly Frequently upgrading business continuity strategies, the supporting disaster recovery strategies and their associated action plans part of our product development process Annually exercising sections of the business continuity plans and annual testing of disaster recovery plans Effectively providing awareness communications and training related to emergency operations, mitigation measures and recovery responsibilities for all associates 1 P age

2 BCP Activation Process Start Outage Reported -Console -Internal call, , fax -Client call, , fax -Automated Script -Supplier/PSP call, , fax Gather Details -Description of disaster? -Injuries? -City emergency offices contacted? -Extent of damage -Who else is affected? -Contact information Initiate Emergency Notification to CORPDR01 DRTDR Assessment Team Convenes at Predetermined Location Damage Assessment DRTDR Alert Alternate Site(s) Yes Activate Disaster Relocation Plan? Notify M&F Crisis Team Activate BCP/ DR Plan(s) No Follow Incident Management Process Notify Affected Clients 2 P age

3 Summary In the event of an emergency in one or more of our facilities, Harland Clarke has a number of available options depending on the particular situation. The Harland Clarke Information Systems are designed to transmit and transfer work anywhere in our system. Our typesetting systems and quality assurance files are centrally controlled and distributed. Therefore, the specifications for all of your documents are available for immediate use nationwide for as long as necessary. All check plants have designated alternate plants prepared to provide back-up support in case of a disaster or additional workload. However, in an emergency, any plant in any area can assist immediately. In addition, we have our own rebuilding operation with spare equipment ready and available for expansion, new plant start-ups, or for immediate shipment to any plant. This includes major equipment as well as spare parts. In addition to the above, Harland Clarke has employees who frequently travel to plants system-wide to support new technology installation, new plant start-ups and special high volume or short notice conversions. These employees, along with manufacturing staff employees, are available immediately in emergency situations. The following is an overview of Recovery Plans for critical business services: CPU and Network Contingency Plan A. Plan Elements Harland Clarke as a multi-faceted approach to protect the essential business functions served through data processing and data communications system. This approach is designed to prevent, minimize, and optimally recover from the loss of computing and communications resources, which drive our operations. Some of the elements of Legacy Clarke s plan are as follows: 1. Redundancy in mechanical and electrical systems UPS (Uninterruptible Power Supply) Emergency generator Redundant air conditioning Redundant chilled water units 3 P age

4 2. State-of-the-art fire protection and site security systems Fire suppression system Water detection system 3. Data protection and security systems Software and telecommunications security protection systems Off-site storage of data and system control software for backup protection 4. Redundancy in hardware and communications systems Redundancy in remote device and communications controllers at primary and recovery sites Integrated telecommunications dial back-up capability to remote customer sites and plants at primary and recovery sites 5. Site selection criterion for disaster prevention Not in flood plain Not in flight patterns Located away from railroads B. Disaster Downtime (RTO) We anticipate that, should a catastrophe strike a Harland Clarke computer center, critical systems can be recovered in hours. This estimate is based upon our current design, and exercise results, the nature of the disaster, and what day of the week the disaster occurs. During this short period, all plant and customer service personnel would continue to operate using manual procedures. After computer operations are restored, this manual tracking of all orders and service calls would be re-entered into the system and all operations would return to normal. 4 P age

5 Disaster Recovery Plan for Imprint Plants All Harland Clarke imprint plants have designated alternate plants prepared to provide backup support in case of a disaster or additional workload. Our plan network is designed to direct or re-direct complete processing information from one production site to another. Each plant maintains a spare parts inventory in the event of a machine breakdown. Expensive or hard to replace parts are maintained by Plant Engineering Services (PES) to be shipped overnight if needed. Equipment Imprint plants in the Harland Clarke system are not run at full capacity. Based on this, any of our production sites are equipped for additional production capacity. In addition, we have our own equipment rebuilding and storage operation. This location houses enough spare equipment to expand or open a new operation. This includes major equipment as well as spare parts. Base Stock Inventories Should volumes increase to Harland Clarke for any reason, Harland Clarke Base Stock operations can immediately respond with increased production of check stock for any of our facilities. This additional base stock would be available for overnight shipment to any production site. Harland Clarke has deployed redundant systems in each regional print facility, and each system has the ability to hub work to an alternate plant due to application design. Redundant systems can be reconfigured quickly to accept work up to double the normal work performed. Disaster backup tapes are performed each work night. In the event that one or more plants become unavailable, work can be hubbed to an alternative plant within hours while backup tapes are being transported to the alternate plant location. These disaster recovery procedures are standard across the Harland Clarke plant network. 5 P age

6 Disaster Recovery Plan for MICR Forms Salt Lake City, UT Harland Clarke s MICR Forms primary production facility is located in Salt Lake City, Utah. The plants computer systems run on Windows NT platform (Compaq ProLiant and IBM blade servers). All systems are backed up to a tape library and stored onsite and offsite. The network is connected across the Harland Clarke WAN to allow communication between all plants and departments within the company. Our Jeffersonville, Indiana facility is our designated disaster recovery site. Most composition and production equipment is virtually identical. In the event of an emergency requiring additional capacity, our Columbia, South Carolina facility would be used for the creation of inventory and specific overprint product lines. Composition files are maintained on-line in both facilities. Daily backups are performed on all updated composition files. All composition files are compatible with Postscript Level III. Full system backups are performed once per week. Two rotating backups of the system files are maintained. One backup is kept at the on- site and another one is kept at Perpetual storage. Each week the backups are rotated. All press equipment is regularly maintained and each facility has a minimum of five presses, all virtually identical. In the event of an equipment breakdown, the products can be moved to another press within the facility within two hours. Both facilities have multiple pieces of bindery equipment equally capable of performing redundant tasks necessary to ship orders in a timely basis. Harland Clarke has a policy of planned redundancy and back-up sourcing of computer, equipment, staffing and source of supply. If equipment fails for any reason, the equipment is repaired on an emergency basis if possible. We have maintenance agreements and emergency repair arrangements on critical equipment. If the equipment cannot be repaired in sufficient time to avoid significant down-time (greater than 24 hours or less depending on demand) the work will be: a) transferred to an alternate work center or b) outsourced, as appropriate. In the event of major equipment failure or loss due to fire, vandalism, etc., work will be immediately transferred to an alternate process or outsourced and the process to replace equipment will be expedited where possible. 6 P age

7 Disaster Recovery Plan for Contact Service Centers In the unlikely event of a Customer Service Center being shut down for any reason, Harland Clarke has contracted with our Telecom provider to immediately route all incoming calls to our additional Customer Service Center to ensure clients and their customers of uninterrupted service. Harland Clarke has also developed a Telephone Disaster Recovery Plan Checklist for our Contact Service Centers to utilize in the event of a disaster. Disaster Recovery Plan for Web servers In the event of prolonged outage impacting all our web servers, Harland Clarke has contracted with SunGard Availability Services to provide site, hardware and connectivity replacement until a return to normal operations. Anticipated recovery time is hours. For individual outages on a web server, redundancy is built into each server. Investment Services/Direct Marketing Baltimore, MD The Baltimore facility has added to the routine plant recovery procedures described above, by the addition of a hot-switchable, non-interrupted CPU processors and disk drives, reducing recovery time. Baltimore has also leveraged its disaster recovery for immediate movement to an alternate Harland Clarke facility; in the event of a major failure short of a site disaster at Baltimore, mirroring and automatic Wide-Area data updates allow for rapid continued processing to resume from the alternate site. Checks In The Mail, New Braunfels, TX Checks In The Mail recovery objective is to restore critical (Category I & II) production processes within hours, and essential (Category III) production processes within 72 hours to 1 week of a disaster that disables any functional area and/or essential equipment supporting the systems or functions in that area. In the event of a short or long-term outage, all areas can perform their functions from another location (even their own homes) with access to the Odyssey application. In the worst-case scenario of total destruction of the facility, with the restoration of 100% of the critical servers and applications, Priority 1 & 2 critical services can be 100% functional within the defined RTO of 8 hours to 1 week. SunGard Availability Services, 401 North Broad Street, Philadelphia, PA has been designated as the technology backup location for the CITM facility. 7 P age

8 Direct Marketing/Investment Services Disaster Recovery Plan Fallback Site Chicago, IL Customer Data Primary Site Glen Burnie, MD T1 Dedicated Data Line Real Time Data Shadowing Chicago HP3000 (fallback) DMIS HP3000 (primary) Harland WideArea Network DMIS Solimar Xerox Print Servers Xerox 4635 Xerox 4635 Primary Site Closeout Equipment Bindery Inserting Folding Harland Chicago Print Facilities 8 P age

9 Harland Clarke Data Centers Harland Clarke has two data centers located in Atlanta, GA and Dallas, TX; both are under contract with SunGard Availability Services for hot-site services. Included in the SunGard services at the time of a disaster or recovery exercises are: mainframe and distributed systems equipment, network connectivity and internet access. Harland Clarke Recovery Time Objective (RTO) is hours. The two data centers support different services for Harland Clarke and do not act as alternate backups to each other. Harland Clarke Routine Recovery As with any business, there are a number of routine outages, which occur that are not classified as a major disasters. In order to ensure the availability of Harland Clarke s services and products, standard operating procedures have been developed to effectively manage these outages. 9 P age

University Information Systems. Administrative Computing Services. Contingency Plan. Overview

University Information Systems. Administrative Computing Services. Contingency Plan. Overview University Information Systems Administrative Computing Services Contingency Plan Overview Last updated 01/11/2005 University Information Systems Administrative Computing Services Contingency Plan Overview

More information

Introduction to Business continuity Planning

Introduction to Business continuity Planning Week - 06 Introduction to Business continuity Planning 1 Introduction The purpose of this lecture is to give an overview of what is Business Continuity Planning and provide some guidance and resources

More information

TUFTS HEALTH PLAN CORPORATE CONTINUITY STRATEGY

TUFTS HEALTH PLAN CORPORATE CONTINUITY STRATEGY JUNE 2017 TUFTS HEALTH PLAN CORPORATE CONTINUITY STRATEGY OVERVIEW The intent of this document is to provide external customers and auditors with a high-level overview of the Tufts Health Plan Corporate

More information

INFORMATION SECURITY- DISASTER RECOVERY

INFORMATION SECURITY- DISASTER RECOVERY Information Technology Services Administrative Regulation ITS-AR-1505 INFORMATION SECURITY- DISASTER RECOVERY 1.0 Purpose and Scope The objective of this Administrative Regulation is to outline the strategy

More information

Business Continuity and Disaster Recovery. Ed Crowley Ch 12

Business Continuity and Disaster Recovery. Ed Crowley Ch 12 Business Continuity and Disaster Recovery Ed Crowley Ch 12 Topics Disaster Recovery Business Impact Analysis MTBF and MTTR RTO and RPO Redundancy Failover Backup Sites Load Balancing Mirror Sites Disaster

More information

Data Storage, Recovery and Backup Checklists for Public Health Laboratories

Data Storage, Recovery and Backup Checklists for Public Health Laboratories Data Storage, Recovery and Backup Checklists for Public Health Laboratories DECEMBER 2018 Introduction Data play a critical role in the operation of a laboratory information management system (LIMS) and

More information

Table of Contents. Sample

Table of Contents. Sample TABLE OF CONTENTS... 1 CHAPTER 1 INTRODUCTION... 4 1.1 GOALS AND OBJECTIVES... 5 1.2 REQUIRED REVIEW... 5 1.3 APPLICABILITY... 5 1.4 ROLES AND RESPONSIBILITIES SENIOR MANAGEMENT AND BOARD OF DIRECTORS...

More information

Template. IT Disaster Recovery Planning: A Template

Template. IT Disaster Recovery Planning: A Template Template IT Disaster Recovery Planning: A Template When disaster strikes, business suffers. A goal of business planning is to mitigate disruption of product and services delivery to the greatest degree

More information

BUSINESS CONTINUITY. Topics covered in this checklist include: General Planning

BUSINESS CONTINUITY. Topics covered in this checklist include: General Planning BUSINESS CONTINUITY Natural and manmade disasters are happening with alarming regularity. If your organization doesn t have a great business continuity plan the repercussions will range from guaranteed

More information

Security+ Guide to Network Security Fundamentals, Third Edition. Chapter 13 Business Continuity

Security+ Guide to Network Security Fundamentals, Third Edition. Chapter 13 Business Continuity Security+ Guide to Network Security Fundamentals, Third Edition Chapter 13 Business Continuity Objectives Define business continuity Describe the components of redundancy planning List disaster recovery

More information

Module 4 STORAGE NETWORK BACKUP & RECOVERY

Module 4 STORAGE NETWORK BACKUP & RECOVERY Module 4 STORAGE NETWORK BACKUP & RECOVERY BC Terminology, BC Planning Lifecycle General Conditions for Backup, Recovery Considerations Network Backup, Services Performance Bottlenecks of Network Backup,

More information

CANVAS DISASTER RECOVERY PLAN AND PROCEDURES

CANVAS DISASTER RECOVERY PLAN AND PROCEDURES CANVAS DISASTER RECOVERY PLAN AND PROCEDURES Instructure Security, Engineering, and Operations INSTRUCTURE, INC. 6330 South 3000 East Salt Lake City, Utah 84121 Table of Contents Disaster Plan and Procedures...

More information

Data Recovery Policy

Data Recovery Policy Data Recovery Policy The Marketware, Inc. Contingency Plan establishes procedures to recover Marketware, Inc. following a disruption resulting from a disaster. This Disaster Recovery Policy is maintained

More information

Contingency Planning

Contingency Planning Contingency Planning Introduction Planning for the unexpected event, when the use of technology is disrupted and business operations come close to a standstill Procedures are required that will permit

More information

IT CONTINUITY, BACKUP AND RECOVERY POLICY

IT CONTINUITY, BACKUP AND RECOVERY POLICY IT CONTINUITY, BACKUP AND RECOVERY POLICY IT CONTINUITY, BACKUP AND RECOVERY POLICY Effective Date May 20, 2016 Cross- Reference 1. Emergency Response and Policy Holder Director, Information Business Resumption

More information

Appendix 3 Disaster Recovery Plan

Appendix 3 Disaster Recovery Plan Appendix 3 Disaster Recovery Plan DRAFT March 5, 2007 Revision XX Qwest Government Services, Inc. 4250 North Fairfax Drive Arlington, VA 22203 A3-i RFP: TQC-JTB-05-0002 March 5, 2007 REVISION HISTORY Revision

More information

Continuity of Business

Continuity of Business White Paper Continuity of Business SAS Continuity of Business initiative reflects our commitment to our employees, to our customers, and to all of the stakeholders in our global business community to be

More information

TEL2813/IS2820 Security Management

TEL2813/IS2820 Security Management TEL2813/IS2820 Security Management Contingency Planning Jan 22, 2008 Introduction Planning for the unexpected event, when the use of technology is disrupted and business operations come close to a standstill

More information

EXHIBIT A. - HIPAA Security Assessment Template -

EXHIBIT A. - HIPAA Security Assessment Template - Department/Unit: Date: Person(s) Conducting Assessment: Title: 1. Administrative Safeguards: The HIPAA Security Rule defines administrative safeguards as, administrative actions, and policies and procedures,

More information

Certified Information Systems Auditor (CISA)

Certified Information Systems Auditor (CISA) Certified Information Systems Auditor (CISA) 1. Domain 1 The Process of Auditing Information Systems Provide audit services in accordance with IT audit standards to assist the organization in protecting

More information

Audit & Advisory Services. IT Disaster Recovery Audit 2015 Report Date January 28, 2015

Audit & Advisory Services. IT Disaster Recovery Audit 2015 Report Date January 28, 2015 Audit & Advisory Services IT Disaster Recovery Audit 2015 Report Date January 28, 2015 Audit & Advisory Services Mission and Function The JCCC Audit & Advisory Services department provides an independent

More information

Aljex Software, Inc. Business Continuity & Disaster Recovery Plan. Last Updated: 1/30/2017.

Aljex Software, Inc. Business Continuity & Disaster Recovery Plan. Last Updated: 1/30/2017. Aljex Software, Inc. Business Continuity & Disaster Recovery Plan Last Updated: 1/30/2017 Table of Contents Introduction... 3 Business Continuity... 3 Employee Structure... 3 On-Site Disruption Procedures...

More information

Piton Investment Management. Business Continuity Plan

Piton Investment Management. Business Continuity Plan Date: May 2018 Table of Contents 1. Introduction... 3 2. Firm Policy... 3 2.1 Plan Location & Access... 3 3. Office Locations... 3 4. Evacuation Plan... 4 5. Alternate Physical Location of Employees...

More information

Please indicate below the principle nature of your department s operations (check all that apply): Student life support.

Please indicate below the principle nature of your department s operations (check all that apply): Student life support. BUSINESS 2016 A. BUSINESS CONTINUITY PLAN (BCP) To be better prepared, UH personnel and its programs may use this form to complete a Business Continuity Plan (BCP) checklist to describe how your program

More information

IT SECURITY RISK ANALYSIS FOR MEANINGFUL USE STAGE I

IT SECURITY RISK ANALYSIS FOR MEANINGFUL USE STAGE I Standards Sections Checklist Section Security Management Process 164.308(a)(1) Information Security Program Risk Analysis (R) Assigned Security Responsibility 164.308(a)(2) Information Security Program

More information

Disaster Recovery Planning

Disaster Recovery Planning Disaster Recovery Planning How to Ensure your IT systems are protected and your business keeps running should disaster strike. Benefits of Using Disaster Recovery as a Service DRaaS over Traditional Disaster

More information

Memorandum APPENDIX 2. April 3, Audit Committee

Memorandum APPENDIX 2. April 3, Audit Committee APPENDI 2 Information & Technology Dave Wallace, Chief Information Officer Metro Hall 55 John Street 15th Floor Toronto, Ontario M5V 3C6 Memorandum Tel: 416 392-8421 Fax: 416 696-4244 dwwallace@toronto.ca

More information

Dude Solutions Business Continuity Overview

Dude Solutions Business Continuity Overview Dude Solutions Business Continuity Overview Table of Contents Overview.... 2 Primary and Disaster Recovery Data Centers.... 2 Network Infrastructure.... 3 Emergency Processes.... 3 Power and Cooling Systems....

More information

DISASTER RECOVERY PRIMER

DISASTER RECOVERY PRIMER DISASTER RECOVERY PRIMER 1 Site Faliure Occurs Power Faliure / Virus Outbreak / ISP / Ransomware / Multiple Servers Sample Disaster Recovery Process Site Faliure Data Centre 1: Primary Data Centre Data

More information

University of Hawaii Hosted Website Service

University of Hawaii Hosted Website Service University of Hawaii Hosted Website Service Table of Contents Website Practices Guide About These Practices 3 Overview 3 Intended Audience 3 Website Lifecycle 3 Phase 3 Begins 3 Ends 3 Description 3 Request

More information

3.3 Understanding Disk Fault Tolerance Windows May 15th, 2007

3.3 Understanding Disk Fault Tolerance Windows May 15th, 2007 3.3 Understanding Disk Fault Tolerance Windows May 15th, 2007 Fault tolerance refers to the capability of a computer or network to continue to function when some component fails. Disk fault tolerance refers

More information

Network Performance, Security and Reliability Assessment

Network Performance, Security and Reliability Assessment Network Performance, Security and Reliability Assessment Presented to: CLIENT NAME OMITTED Drafted by: Verteks Consulting, Inc. 2102 SW 20 th Place, Suite 602 Ocala, Fl 34474 352-401-0909 ASSESSMENT SCORECARD

More information

Admin Plus Pack Option. ExecView Web Console. Backup Exec Admin Console

Admin Plus Pack Option. ExecView Web Console. Backup Exec Admin Console WHITE PAPER Managing Distributed Backup Servers VERITAS Backup Exec TM 9.0 for Windows Servers Admin Plus Pack Option ExecView Web Console Backup Exec Admin Console VERSION INCLUDES TABLE OF CONTENTS STYLES

More information

STATE OF NORTH CAROLINA

STATE OF NORTH CAROLINA STATE OF NORTH CAROLINA AUDIT OF THE INFORMATION SYSTEMS GENERAL CONTROLS ELIZABETH CITY STATE UNIVERSITY JULY 2006 OFFICE OF THE STATE AUDITOR LESLIE MERRITT, JR., CPA, CFP STATE AUDITOR AUDIT OF THE

More information

BUSINESS CONTINUITY MANAGEMENT PROGRAM OVERVIEW

BUSINESS CONTINUITY MANAGEMENT PROGRAM OVERVIEW BUSINESS CONTINUITY MANAGEMENT PROGRAM OVERVIEW EXECUTIVE SUMMARY CenturyLink is committed to ensuring business resiliency and survivability during an incident or business disruption. Our Corporate Business

More information

Contents. Chapter 3: Chapter 4: Critical Server Ranking Classifying Systems for Recovery Priority Mission-Critical Only, Please...

Contents. Chapter 3: Chapter 4: Critical Server Ranking Classifying Systems for Recovery Priority Mission-Critical Only, Please... Chapter 1: Building a Disaster Recovery Plan The Need...... 1 The Need............................ 3 Plan for All Types of Disasters................ 11 Reasons for Planning.................... 13 Let s

More information

NORTH AMERICAN SECURITIES ADMINISTRATORS ASSOCIATION Cybersecurity Checklist for Investment Advisers

NORTH AMERICAN SECURITIES ADMINISTRATORS ASSOCIATION Cybersecurity Checklist for Investment Advisers Identify Protect Detect Respond Recover Identify: Risk Assessments & Management 1. Risk assessments are conducted frequently (e.g. annually, quarterly). 2. Cybersecurity is included in the risk assessment.

More information

Disaster Recovery (DR) Planning with the Cloud Desktop

Disaster Recovery (DR) Planning with the Cloud Desktop with the Cloud Desktop Info@RIAWorkSpace.com 877.361.3499 www.riaworkspace.com In preparing for the unexpected, most companies put specific disaster recovery plans in place. Without planning, recovering

More information

SERVICE DESCRIPTION MANAGED BACKUP & RECOVERY

SERVICE DESCRIPTION MANAGED BACKUP & RECOVERY Contents Service Overview.... 3 Key Features... 3 Implementation... 4 Validation... 4 Implementation Process.... 4 Internal Kick-Off... 4 Customer Kick-Off... 5 Provisioning & Testing.... 5 Billing....

More information

BME CLEARING s Business Continuity Policy

BME CLEARING s Business Continuity Policy BME CLEARING s Business Continuity Policy Contents 1. Introduction 1 2. General goals of the Continuity Policy 1 3. Scope of BME CLEARING s Business Continuity Policy 1 4. Recovery strategies 2 5. Distribution

More information

Power Outages and the Hosted VOIP Option

Power Outages and the Hosted VOIP Option Power Outages and the Hosted VOIP Option What happens to your business when the POWER is OUT? Office 1: On-Premise VOIP Voice applications are lost when grid and UPS backup fail. Without power to your

More information

Disaster Recovery Solutions for Oracle Database Standard Edition RAC. A Dbvisit White Paper By Anton Els

Disaster Recovery Solutions for Oracle Database Standard Edition RAC. A Dbvisit White Paper By Anton Els Disaster Recovery Solutions for Oracle Database Standard Edition RAC A Dbvisit White Paper By Anton Els Copyright 2017 Dbvisit Software Limited. All Rights Reserved V3, Oct 2017 Contents Executive Summary...

More information

MassMutual Business Continuity Disclosure Statement

MassMutual Business Continuity Disclosure Statement MassMutual Business Continuity Disclosure Statement Overview Resiliency is a high priority at Massachusetts Mutual Life Insurance Company ( MassMutual or the Company ). To that end, significant investments

More information

Keys To Disaster Preparedness

Keys To Disaster Preparedness Keys To Disaster Preparedness Presented By: Rob Robbins 2012 Setting up your Chess Board Identify your Queen Decide who s going to be King How many assets to protect and in what order (moving your pieces)

More information

Business Continuity Planning Keeping Pace with New Technology

Business Continuity Planning Keeping Pace with New Technology Business Continuity Planning Keeping Pace with New Technology Old issues, new threats Force Majeure Increasing severe weather incidents, terrorist attacks Legacy modernization Cutover issues, system crashes,

More information

Trust Services Principles and Criteria

Trust Services Principles and Criteria Trust Services Principles and Criteria Security Principle and Criteria The security principle refers to the protection of the system from unauthorized access, both logical and physical. Limiting access

More information

Florida State University

Florida State University Florida State University Disaster Recovery & Business Continuity Planning Overview October 24, 2017 1 Key Readiness Questions Has your department identified the business functions and infrastructure that

More information

Disaster Recovery Planning: Weighing your customer s options

Disaster Recovery Planning: Weighing your customer s options Disaster Recovery Planning: Weighing your Even though backing up data and developing a plan to restore it isn't the first step in business continuity planning (BCP), it's still a cornerstone. Without a

More information

Our key considerations include:

Our key considerations include: October 2017 We recognize that our ability to continue to function as an organization is critical to our clients, who rely heavily on our firm and our people to keep their own real estate functioning properly.

More information

Rapid Recovery from Logical Corruption

Rapid Recovery from Logical Corruption Rapid Recovery from Logical Corruption Brett Quinn DellEMC 1 Nov 2016 Session DD Topics Physical vs Logical Recovery SnapVX zdp: Data Protector for z Systems Isolated Recovery Solutions Logical vs Physical

More information

Leveraging ITIL to improve Business Continuity and Availability. itsmf Conference 2009

Leveraging ITIL to improve Business Continuity and Availability. itsmf Conference 2009 Leveraging ITIL to improve Business Continuity and Availability Samuel Lo MBA, MSc, CDCP, PMP, CISSP, CISA Data Centre Services Manager COL Limited Strictly Business itsmf Conference 2009 25 February 2009

More information

REGIONAL UTILITY COORDINATION PLAN. Portland, Oregon / Vancouver, Washington Metropolitan Area

REGIONAL UTILITY COORDINATION PLAN. Portland, Oregon / Vancouver, Washington Metropolitan Area REGIONAL UTILITY COORDINATION PLAN Portland, Oregon / Vancouver, Washington Metropolitan Area I. PURPOSE The purpose of this plan is to outline procedures for coordination between local governments and

More information

Data Center Operations Guide

Data Center Operations Guide Data Center Operations Guide SM When you utilize Dude Solutions Software as a Service (SaaS) applications, your data is hosted in an independently audited data center certified to meet the highest standards

More information

Disaster recovery planning for health care data and HIPAA compliance regulations

Disaster recovery planning for health care data and HIPAA compliance regulations Disaster recovery care data and HIPAA compliance regulations Disaster recovery care Disaster recovery planning takes on special importance in health care organizations dealing with patients and care delivery.

More information

The Future of Business Continuity & Resiliency

The Future of Business Continuity & Resiliency The Future of Business Continuity & Resiliency Richard Cocchiara: IBM Distinguished Engineer; CTO IBM Business Continuity & Resiliency Services (BCRS); Managing Partner IBM Resiliency Consulting Services

More information

Testimony of Donald D. Kittell Executive Vice President Securities Industry Association

Testimony of Donald D. Kittell Executive Vice President Securities Industry Association Testimony of Donald D. Kittell Executive Vice President Securities Industry Association "Government and Industry Efforts to Protect Our Money During Blackouts, Hurricanes and Other Disasters" Opening Remarks

More information

COUNTY GOVERNMENT OF BUSIA P.O. PRIVATE BAG BUSIA, KENYA. Disaster Recovery & Business Continuity Plan for ICT Services

COUNTY GOVERNMENT OF BUSIA P.O. PRIVATE BAG BUSIA, KENYA. Disaster Recovery & Business Continuity Plan for ICT Services COUNTY GOVERNMENT OF BUSIA P.O. PRIVATE BAG 50400 BUSIA, KENYA. Disaster Recovery & Business Continuity Plan for ICT Services October, 2015 This document is copyright to County Government of Busia and

More information

Any observations not included in this report were discussed with your staff at the informal exit conference and may be subject to follow-up.

Any observations not included in this report were discussed with your staff at the informal exit conference and may be subject to follow-up. Larry Mandel Vice Chancellor and Chief Audit Officer Audit and Advisory Services 401 Golden Shore, 4th Floor Long Beach, CA 90802-4210 562-951-4430 562-951-4955 (Fax) lmandel@calstate.edu October 10, 2018

More information

Introduction. Overview. Every Crisis Management Team Needs a Critical Decision Checklist. Presented by Roseanne Rostron, CBCP President Raido Response

Introduction. Overview. Every Crisis Management Team Needs a Critical Decision Checklist. Presented by Roseanne Rostron, CBCP President Raido Response Every Crisis Management Team Needs a Critical Decision Checklist Presented by Roseanne Rostron, CBCP President Raido Response Tuesday, May 9, 2006 Introduction Roseanne Rostron, CBCP - President Raido

More information

Cybersecurity Checklist Business Action Items

Cybersecurity Checklist Business Action Items Cybersecurity Checklist Business Action Items This section provides a thorough (although not all-inclusive or exhaustive) checklist of action items within the three categories for Incident Management (Planning,

More information

Disaster Recovery and Business Continuity Planning (Mile2)

Disaster Recovery and Business Continuity Planning (Mile2) Disaster Recovery and Business Continuity Planning (Mile2) Course Number: DRBCP Length: 4 Day(s) Certification Exam This course will help you prepare for the following exams: ABCP: Associate Business Continuity

More information

Chapter 18 SaskPower Managing the Risk of Cyber Incidents 1.0 MAIN POINTS

Chapter 18 SaskPower Managing the Risk of Cyber Incidents 1.0 MAIN POINTS Chapter 18 SaskPower Managing the Risk of Cyber Incidents 1.0 MAIN POINTS The Saskatchewan Power Corporation (SaskPower) is the principal supplier of power in Saskatchewan with its mission to deliver power

More information

Public and Private Interdependencies Filling a Gap in Most Continuity Plans

Public and Private Interdependencies Filling a Gap in Most Continuity Plans Public and Private Interdependencies Filling a Gap in Most Continuity Plans John A Jackson Executive Vice President Fusion Risk Management, Inc. The evolution of the continuity industrytechnology advancement

More information

Business Continuity: How to Keep City Departments in Business after a Disaster

Business Continuity: How to Keep City Departments in Business after a Disaster Business Continuity: How to Keep City Departments in Business after a Disaster Shannon Spence, PE Red Oak Consulting, an ARCADIS group Agenda Security, Resilience and All Hazards The Hazards Cycle and

More information

High Availability through Warm-Standby Support in Sybase Replication Server A Whitepaper from Sybase, Inc.

High Availability through Warm-Standby Support in Sybase Replication Server A Whitepaper from Sybase, Inc. High Availability through Warm-Standby Support in Sybase Replication Server A Whitepaper from Sybase, Inc. Table of Contents Section I: The Need for Warm Standby...2 The Business Problem...2 Section II:

More information

Business Resiliency in the Cloud: Reality or Hype?

Business Resiliency in the Cloud: Reality or Hype? Business Resiliency in the Cloud: Reality or Hype? Karen Jaworski Senior Director, Product Marketing EVault, a Seagate Company 8/10/2012 2012 EVault, Inc. All Rights Reserved 1 Who is EVault? Cloud-Connected

More information

MUNICIPALITY OF NORRISTOWN. Responses to Proposal Questions

MUNICIPALITY OF NORRISTOWN. Responses to Proposal Questions Q: What are the pain points being experienced with the current IT setup? A: Age of the equipment, reliability of service, no redundancy for internet service. Q: How is technology managed today? A: Outsourced

More information

Businesss Continuity. Client Briefing

Businesss Continuity. Client Briefing Businesss Continuity Client Briefing About this document This document describes Mediaocean s disaster recovery and business continuity policy. Mediaocean LLC. Mediaocean Systems Limited 2017 This manual

More information

A CommVault White Paper: Business Continuity: Architecture Design Guide

A CommVault White Paper: Business Continuity: Architecture Design Guide A CommVault White Paper: Business Continuity: Architecture Design Guide CommVault Corporate Headquarters 2 Crescent Place Oceanport, New Jersey 07757-0900 USA Telephone: 888.746.3849 or 732.870.4000 2007

More information

Achieving Rapid Data Recovery for IBM AIX Environments An Executive Overview of EchoStream for AIX

Achieving Rapid Data Recovery for IBM AIX Environments An Executive Overview of EchoStream for AIX Achieving Rapid Data Recovery for IBM AIX Environments An Executive Overview of EchoStream for AIX Introduction Planning for recovery is a requirement in businesses of all sizes. In implementing an operational

More information

Build a viable plan for disaster recovery and crisis management.

Build a viable plan for disaster recovery and crisis management. Disaster recovery and crisis management solutions To support your IT objectives Build a viable plan for disaster recovery and crisis management. Highlights Build a plan to help respond to and recover from

More information

2 ESF 2 Communications

2 ESF 2 Communications 2 ESF 2 Communications THIS PAGE LEFT BLANK INTENTIONALLY Table of Contents 1 Introduction... 1 1.1 Purpose and Scope... 1 1.2 Relationship to Other ESF Annexes... 1 1.3 Policies and Agreements... 1 2

More information

University of Pittsburgh Security Assessment Questionnaire (v1.7)

University of Pittsburgh Security Assessment Questionnaire (v1.7) Technology Help Desk 412 624-HELP [4357] technology.pitt.edu University of Pittsburgh Security Assessment Questionnaire (v1.7) Directions and Instructions for completing this assessment The answers provided

More information

A Model for Resilience

A Model for Resilience A Model for Resilience THREE STEPS TO CREATING A RESILIENT, CHANGE-READY ENTERPRISE Business resilience is the ability to anticipate risk, mitigate the impact and move forward with confidence as you transform

More information

NUIT Tech Talk. Emergency Preparedness. March 1, Sharlene Mielke. Jay Bagley. Disaster Recovery / Business Continuity Coordinator

NUIT Tech Talk. Emergency Preparedness. March 1, Sharlene Mielke. Jay Bagley. Disaster Recovery / Business Continuity Coordinator NUIT Tech Talk Emergency Preparedness March 1, 2011 Sharlene Mielke Disaster Recovery / Business Continuity Coordinator Jay Bagley Distributed Support Specialist Information and Systems Security/Compliance

More information

Infocomm Professional Development Forum 2011

Infocomm Professional Development Forum 2011 Infocomm Professional Development Forum 2011 1 Agenda Brief Introduction to CITBCM Certification Business & Technology Impact Analysis (BTIA) Workshop 2 Integrated end-to-end approach in increasing resilience

More information

RECENT HURRICANE CASE STUDIES: IMPACT OF BUSINESS RECOVERY PLANNING AND TESTING. Dan Perrin, Regus Stephanie Samuels, Voya

RECENT HURRICANE CASE STUDIES: IMPACT OF BUSINESS RECOVERY PLANNING AND TESTING. Dan Perrin, Regus Stephanie Samuels, Voya RECENT HURRICANE CASE STUDIES: IMPACT OF BUSINESS RECOVERY PLANNING AND TESTING Dan Perrin, Regus Stephanie Samuels, Voya 1 Dan Perrin Regus Dan runs the Workplace Recovery Group within Regus, an International

More information

DoDI IA Control Checklist - MAC 1-Classified. Version 1, Release March 2008

DoDI IA Control Checklist - MAC 1-Classified. Version 1, Release March 2008 DoDI 8500-2 IA Control Checklist - MAC 1-Classified Version 1, Release 1.4 Developed by DISA for the DOD UNTILL FILLED IN CIRCLE ONE FOR OFFICIAL USE ONLY (mark each page) CONFIDENTIAL and SECRET (mark

More information

Subject: Audit Report 18-84, IT Disaster Recovery, California State University, Sacramento

Subject: Audit Report 18-84, IT Disaster Recovery, California State University, Sacramento Larry Mandel Vice Chancellor and Chief Audit Officer Audit and Advisory Services 401 Golden Shore, 4th Floor Long Beach, CA 90802-4210 562-951-4430 562-951-4955 (Fax) lmandel@calstate.edu October 23, 2018

More information

POWERING NETWORK RESILIENCY WITH UPS LIFECYCLE MANAGEMENT

POWERING NETWORK RESILIENCY WITH UPS LIFECYCLE MANAGEMENT POWERING NETWORK RESILIENCY WITH UPS LIFECYCLE MANAGEMENT Network downtime is a business disrupter, cutting off communication between employees and customers, bringing service delivery to a halt. Yet all

More information

Natural Disaster Preparation Checklist

Natural Disaster Preparation Checklist Natural Disaster Preparation Checklist Weather patterns are clearly changing and natural disasters are becoming more frequent. In 2017, Hurricanes Harvey, Irma, and Maria devastated areas in the United

More information

IPMA State of Washington. Disaster Recovery in. State and Local. Governments

IPMA State of Washington. Disaster Recovery in. State and Local. Governments IPMA State of Washington Disaster Recovery in State and Local Governments Disaster by the Numbers Over 70% of agencies had some sort of data loss incident in 2012 Under 5% report that they were able to

More information

Level 3 Certificate in Cloud Services (for the Level 3 Infrastructure Technician Apprenticeship) Cloud Services

Level 3 Certificate in Cloud Services (for the Level 3 Infrastructure Technician Apprenticeship) Cloud Services 9628-08 Level 3 Certificate in Cloud Services (for the Level 3 Infrastructure Technician Apprenticeship) 9628-808 Cloud Services Sample question paper Duration: 60 minutes Candidate s name: Candidate s

More information

IT-BCP Survey 2014 Report

IT-BCP Survey 2014 Report IT-BCP Survey 214 Report Re-examine and improve your IT-BCP efforts 42% Companies that experienced unexpected downtime of critical information systems in the past 12 months 26% Companies that can identify

More information

ASSURING BUSINESS CONTINUITY THROUGH CONTROLLED DATA CENTER

ASSURING BUSINESS CONTINUITY THROUGH CONTROLLED DATA CENTER ASSURING BUSINESS CONTINUITY THROUGH CONTROLLED DATA CENTER IT Audit, Information Security & Risk Insight Africa 2014 Johnson Falana CISA,MIT,CEH,Cobit5 proverb814@yahoo.com Overview Information technology

More information

Corporate Security & Emergency Management Summary of Submitted 2015 Budget From Rates

Corporate Security & Emergency Management Summary of Submitted 2015 Budget From Rates Corporate Security & Emergency Management Summary of Submitted 2015 From Rates Service Expense 2014 2015 Revised Non Tax Revenue Net Tax Supported Expense Draft Non Tax Revenue Net Tax Supported Increase

More information

Business Continuity and Disaster Recovery

Business Continuity and Disaster Recovery Business Continuity and Disaster Recovery Index Section Title 1. Executive Summary 2. Policy Statement 3. Strategy 4. Governance 5. Key Documentation 6. Testing 1 Executive Summary Business Continuity

More information

Report. Diemer Plant Improvements Program Audit Report. Internal Audit Report for January 2011

Report. Diemer Plant Improvements Program Audit Report. Internal Audit Report for January 2011 Report Office of the General Auditor January 31, 2011 Internal Audit Report for January 2011 Summary Three reports were issued during the month: Diemer Plant Improvements Program Audit Report Business

More information

Information Technology Disaster Recovery Planning Audit Redacted Public Report

Information Technology Disaster Recovery Planning Audit Redacted Public Report 1200, Scotia Place, Tower 1 10060 Jasper Avenue Edmonton, Alberta T5J 3R8 edmonton.ca/auditor Information Technology Disaster Recovery Planning Audit Redacted Public Report June 12, 2018 City of Edmonton

More information

Physical and Environmental Security Standards

Physical and Environmental Security Standards Physical and Environmental Security Standards Table of Contents 1. SECURE AREAS... 2 1.1 PHYSICAL SECURITY PERIMETER... 2 1.2 PHYSICAL ENTRY CONTROLS... 3 1.3 SECURING OFFICES, ROOMS AND FACILITIES...

More information

Disaster Recovery Planning: Is Your Plan in Place? Presented by: Steve Shofner, CISA, CGEIT

Disaster Recovery Planning: Is Your Plan in Place? Presented by: Steve Shofner, CISA, CGEIT Disaster Recovery Planning: Is Your Plan in Place? Presented by: Steve Shofner, CISA, CGEIT 1 The material appearing in this presentation is for informational purposes only and is not legal or accounting

More information

Six Myths About Business Continuity Management and Disaster Recovery

Six Myths About Business Continuity Management and Disaster Recovery Research Publication Date: 16 March 2005 ID Number: G00126538 Six Myths About Business Continuity Management and Disaster Recovery Josh Krischer, Donna Scott, Roberta J. Witty There is no "one size fits

More information

COMMUNICATIONS EMERGENCY SUPPORT FUNCTION (ESF #2) FORMERLLY COMMUNICATIONS AND WARNING

COMMUNICATIONS EMERGENCY SUPPORT FUNCTION (ESF #2) FORMERLLY COMMUNICATIONS AND WARNING ICS Category: Operations ESF # 2 Responsible for the EOC message center, providing working radio & telephone equipment, and providing warning to vulnerable facilities Reports to the emergency management

More information

Business Continuity Planning

Business Continuity Planning Information Systems Audit and Control Association www.isaca.org Business Continuity Planning AUDIT PROGRAM & INTERNAL CONTROL QUESTIONNAIRE The Information Systems Audit and Control Association With more

More information

CUNY Graduate Center Information Technology. IT Provisioning for Business Continuity & Disaster Recovery Effective Date: April 6, 2018

CUNY Graduate Center Information Technology. IT Provisioning for Business Continuity & Disaster Recovery Effective Date: April 6, 2018 CUNY Graduate Center Information Technology IT for & Effective Date: April 6, 2018 Introduction Organization Information Technology (IT) is the division of the Graduate Center responsible for voice, video

More information

Disaster Recovery Planning Blackout. Katrina

Disaster Recovery Planning Blackout. Katrina Disaster Recovery 2003 Blackout Before: After: Katrina 1 Sandy Mentor, Ohio Flood Disaster Map 2 It is believed that some of the companies spend up to 25% of their budgets on disaster recovery planning;

More information

BUSINESS CONTINUITY: THE PROFIT SCENARIO

BUSINESS CONTINUITY: THE PROFIT SCENARIO WHITE PAPER BUSINESS CONTINUITY: THE PROFIT SCENARIO THE BENEFITS OF A COMPREHENSIVE BUSINESS CONTINUITY STRATEGY FOR INCREASED OPPORTUNITY Organizational data is the DNA of a business it makes your operation

More information

Cooling Contingency Planning. Planni ng for the U nexpected. Is Your Health Care Facility Prepared?

Cooling Contingency Planning. Planni ng for the U nexpected. Is Your Health Care Facility Prepared? Cooling Contingency Planning Planni ng for the U nexpected Is Your Health Care Facility Prepared? R isk Management Unexpected events, such as natural disasters, can expose organizations to risks. Even

More information

April Appendix 3. IA System Security. Sida 1 (8)

April Appendix 3. IA System Security. Sida 1 (8) IA System Security Sida 1 (8) Table of Contents 1 Introduction... 3 2 Regulatory documents... 3 3 Organisation... 3 4 Personnel security... 3 5 Asset management... 4 6 Access control... 4 6.1 Within AFA

More information

Global Statement of Business Continuity

Global Statement of Business Continuity Business Continuity Management Version 1.0-2017 Date January 25, 2017 Status Author Business Continuity Management (BCM) Table of Contents 1. Credit Suisse Business Continuity Statement 3 2. BCM Program

More information