How to Improve your Resiliency Lebanon s Banking Community March 2016
Sometimes Nothing works!!! / Entry Production system Alliance Gateway SWIFTNet Link DB / Entry DR system DB Alliance Gateway SWIFTNet Link
enda Best Practices of SWIFT infrastructure Implementation SWIFT Connectivity Resilience SWIFT Gateway Resilience Database Resilience Security best practices
Single Site Setup Typical SWIFTNet Configuration Single Operating Site Back-Office SAG/ SNL Alliance Connect Bronze Internet SWIFTNet
Active/Standby Setup Typical SWIFTNet Configuration Active Site DR Site Back-Office Back-Office SAG/ SNL HSM SAG/ SNL HSM Alliance Connect Silver+ / Gold Alliance Connect Silver+ / Gold Lease line Internet Lease line Internet SWIFTNet
Dual Active Setup Typical SWIFTNet Configuration Active Site Active Site Back-Office Back-Office SAG/ SNL HSM SAG/ SNL HSM Alliance Connect Silver / Gold Alliance Connect Silver / Gold Lease line Internet SWIFTNet Lease line Internet
Business Continuity Requirements How to improve you Resiliency Recovery Time Objective (RTO) acceptable amount of time to restore the function Requirement example: RTO = 0 in case of a site loss. RTO = 4 hour in case of 2 sites loss Recovery Point Objective (RPO) acceptable latency of data that will not be recovered Requirement example: RPO = 0 (no data is lost) in case of a site loss. RPO = 30 min in case of 2 sites loss
Resiliency Setup Comparison How to improve you Resiliency Single Site Recovery Point Objective Active / Standby Setup Dual Active Setup 0 Recovery Time Objective
enda Best Practices of SWIFT infrastructure Implementation SWIFT Connectivity Resilience SWIFT Gateway Resilience Database Resilience Security best practices
Connectivity Resilience RAHA Multi Host How to improve your Resiliency Legend: Primary route(s) office application Production Site Automatic failover of LT for FIN, SnF InterAct and SnF FileAct to backup Gateway. Without downtime and loss of in-flight messages. Active standby route DR Site / Local Backup system / Entry Production system DMZ DB / Entry Cold DR/Backup system DMZ DB RAHA Alliance Gateway SWIFTNet Link RAHA Alliance Gateway SWIFTNet Link
enda Best Practices of SWIFT infrastructure Implementation SWIFT Connectivity Resilience SWIFT Gateway Resilience Database Resilience Security best practices
ance Remote Gateway How to improve your Resiliency Customer premises Alliance Gateway Customer premises HSMs Alliance Connect ce ns Alliance Access or Alliance Entry Replace your Gateways, SNLs, HSMs Customer premises SWIFT Alliance Connect* Alliance Remote Gateway * All Alliance Connect versions are supported (Bronze / Silver / Silver+ / Gold)
sider Alliance ote Gateway if How to improve your Resiliency You want the benefits of or Entry at your premises without needing to operate Alliance Gateway, SWIFTNet Link and HSMs You want to reduce technical complexity, effort and infrastructure for SWIFT messaging, while keeping control and application integration at your side You want to reduce your total cost of ownership (TCO) Alliance Remote Gateway is designed for customers with up to five BIC-8 destinations, up to 20 concurrent users, and low-to-medium message volumes (up to Alliance Gateway band 4)
enda Best Practices of SWIFT infrastructure Implementation SWIFT Connectivity Resilience SWIFT Gateway Resilience Database Resilience Security best practices
Recovering from an failure Database Recovery DB contains: - Live and archived messages - Configuration data - Event log Embedded Oracle Database DB backups contains: - Configuration data - NO messages Data files Redo Logs DB Backups Traffic Failure No DB corruption se of partial DB corruption e of Redo logs corruption
Database Recovery Improving your Resiliency - Native feature - Based on Industry proven technology - Recover on another host - Single command to recover Embedded Oracle Database Database Recovery Data files Redo Logs Mirror Disk Backup disk A single command saa_dbrecovery DB Backups Traffic Failure B corruption DB recovery Up to the last committed state(*)
Database Recovery Active/Standby Setup Improving your Resiliency Active Site Backup Site Synchronous Replication (for ex: SAN infrastructure) Backup Active Site DR Site Asynchronous Replication Backup Alliance Database Recovery - FULL CONTENT RECOVERY - up to the last committed state - no data loss - synchronous replications - some reconciliation - asynchronous replication
ucing RTO / RPO Improving your Resiliency Single Site Recovery Point Objective Active / Standby Setup Dual Active Setup 0 Database Recovery Recovery Time Objective
enda Best Practices of SWIFT infrastructure Implementation SWIFT Connectivity Resilience SWIFT Gateway Resilience Database Resilience Security best practices
More Security How to Improve your Resiliency Security best practices in the market Never use File Integration without LAU feature activation If it s not supported by your back office application, try other alternative like Web services, MQ integration Implementation of proper workflow without giving full permissions to one user Upgrade your SWIFT infrastructure to the latest release and follow SWIFT security guides Administrators are never given messages handling permissions. Keep security officers passwords stored in a safe place
THANK YOU! How to improve your Resiliency