Logo

Wednesday, March 7, 2012

DEVELOPING SEAMLESS BUSINESS CONTINUITY AND DISASTER RECOVERY PLANS by Dr. Jim Kennedy.


Introduction

The development of recovery times for both the business organization’s business continuity plan and the IT department’s disaster recovery plan need to be developed through the collaboration of both parties for either plan to provide the proper protection. However in my thirty-five years in the business continuity and resiliency field I have found in many situations they are not.
The reasons for this can be timing or a lack of knowledge of the overall business continuity and/or disaster recovery planning process coupled with a lack of understanding of each other’s real recovery timing needs.
The purpose of this article is to provide a framework in which the recovery time objectives (RTOs) for the business continuity and the disaster recovery plan can be developed together.


Reason for inconsistencies and failures

Generally the drivers for business continuity and disaster recovery planning are considered to be one and the same, but this is not always the case. Many times the very design process for IT infrastructure requires that the IT organization develop disaster recovery planning thoughts and plans early in the application and/or systems development process. So, early in the project’s timescale of the development of a new application or system, IT must have some understanding of what kind of recovery timing and recovery point timing will be needed to support the technology to be deployed. IT will try to obtain the RTO and RPO (recovery point objective) numbers, but the business is most often focused on insuring that the deployment of the new business process or function is rolled out on time and within budget. The business organization is not thinking about business continuity planning at this time. So, IT will take it on itself to develop a best guess of the required recovery times either based on conversations with the business organization or on its own, if the latter cannot or will not commit to a number.
In other cases that I have seen, there is a clear lack of knowledge about business continuity and disaster recovery planning. Each organization knows that they need either a business continuity or a disaster recovery plan but they are not trained in the overall steps in developing such plans. As such the business organization does not understand the risks, tradeoffs, and costs involved in developing a proper business continuity plan. The business organization also often does not understand that it needs to properly analyze the operation to better understand the recovery requirements during the process/systems/application development phase of the systems/process development life cycle or, as ITIL defines it, the application life cycle (ALC). The business organization needs to quantify the impacts of loss of that process or system; and may not be sure of the right questions to ask - not only in terms of loss of productivity, but in terms of costs to process manually in case of a system loss or failure. Can the organization develop and use manual processes at all if the system or IT infrastructure fails? Does the organization have the human resources to perform the necessary manual processes or will they need to bring in contingent workers and for how long and for what cost? Every business organization needs to clearly understand and to articulate their operation’s maximum tolerable period of disruption (MTPD).
MTPD is the maximum time an activity or resource can be unavailable before irreparable harm is caused to the organization. This applies to both customer-facing and internal activities. Note that the recovery time objective specifies the time by which an organization intends to recover an activity or resource: the maximum tolerable period of disruption is the upper bound on this time.

The business needs to utilize the MTPD to develop its processes and contingency processes, and the IT organization need to understand the MTPD to properly develop its technology and RTO which, in turn, will enable the business to achieve its RTO objectives.
At the same time, IT needs to utilize the recovery time numbers developed by the business organization as a basis for its system and infrastructure RTO values.
Standards and planning process
There are so many business continuity and disaster recovery standards to choose from, as well as other related standards of practice, that this might be the reason for all of the confusion. The fact that none of these standards really talk of integrating the business recovery and the IT technology recovery plans together in to the overall process or application development life cycle complicates the matter even further.

There is also the issue that business continuity and/or disaster recovery planning classes are usually only electives in business administration or computer technology/information systems curriculum. So we are not exactly preparing our next batch of business or technology leaders to properly understand the methods, or importance, of contingency planning.
All that being said, most of the standards that exist do have a pretty consistent set of predefined steps to be reasonably successful. So if we take all of the contingency planning steps and align them with the ITIL ALC phases the planning cycle will integrate system development with continuity planning together at the best possible time in the development process.
I will outline the steps below in developing business continuity and disaster recovery plans with their corresponding points within the ITIL application development life cycle:
STEPS IN BUSINESS CONTINUITY AND DISASTER RECOVERY PLANNINGITIL APPLICATION LIFE CYCLE PHASES
1) Understand the Organization
a. Risk Assessment
b. Business Impact Assessment
            i. Determine MTPD for operation
           ii. Develop RTO for Critical Systems
           iii. Develop RPO for Critical Systems
Requirements – requirements gathered based on business needs of the organization
2) Evaluate and Determine Strategy
a. BC strategy to meet RTO/RPO
b. DR strategy to meet RTO/RPO
Design – requirements translated into specifications
3) Develop Plans
a. BCP – Business Organization
b. DRP –IT Organization
Build – Application and the operational model are made ready for deployment
4) Exercise PlanOperate -- IT operates the application as part of the business service
5) Audit and Maintain PlanOptimize

Using the standards and good practices
During the requirements gathering phase of the ITIL ALC the business owner should have also conducted the risk assessment and business impact analysis or BIA. The results of these two activities allow the business owner to clearly see the impact on the business of a failure or discontinuation of operations in either, or both, of the business or IT operations. They can then translate that knowledge from the risk assessment and business impact analysis into quantifiable RTO and RPO numbers to be used in the next phase of business continuity and disaster recovery planning (Evaluate and Determine Strategy) and the Design phase of the ITIL ALC.

The RTO and RPO numbers are used to develop alternative strategies that meet the recovery time and point needs. A cost for each alternative design is developed. The cost is the total of the IT cost to design, implement, build and operate; and the business cost for any workarounds or special handling during the outage period; plus costs to load any transactions processed during that outage period into the system (processing resynchronization) after they are brought back on-line and are processing again as before the incident.

The alternative strategies are then looked at using a cost and benefit (time, reduced workaround complexity, and etc.) analysis of each alternative. The best option will accomplish return to operation in a reasonable time with an acceptable cost to the business and IT. However, the alternative selected will require input from both IT and the business to properly address the risk of outage. The business will need to insure that it can perform the workarounds and still meet all of the business, regulatory and audit needs of the operation for the time period that the alternative defines the IT organization to need for restoring the IT systems needed to restart the application and its associated services.
For the plans to be effective and ‘fit for purpose’ it is very important that the business and IT are on the ‘same sheet of music’ as to recovery times and points. It is no good if the business has planned its resources and workarounds expecting a system recovery time of 24 hours only to find that the system will be down for 48 hours. On the other side of the coin it is not fiscally responsible to pay the cost to expedite the recovery time of an IT system to less than four hours if the business can tolerate an outage period of 24 hours or more at much less cost for the final IT solution.
Once it has been concluded that both plans are consistent with each other, the actual plans can be developed. While the business prepares for implementation of the new application and/or service, IT will make ready the systems and infrastructure needed to also meet the business schedule for implementation.


Exercising the plans
There is one caveat, however. Even if both sides have planned together and developed their plans based on a single and consistent recovery time, the two planning activities still need to verify (via exercising the plans together) that the IT recovery timing (the disaster recovery plan which includes hardware restoration, software restoration, synchronization of databases, and etc.) actually comes in on time to meet the business’ needs as provided for in the business continuity plan.
Only in testing and timing the two recovery processes to ensure that they are coincident can an organization truly be confident that the overall plans will be successful.

Social media can transform enterprise business continuity management


Social media can hold the key to transforming enterprise business continuity management, especially crisis/incident management and communications practices, according to Gartner.
Gartner analysts predict that, by 2015, 75 percent of organizations with business continuity management systems will have public social media services in their crisis communications strategies; and BCM professionals are advised to immediately begin assessing social media's opportunities and risks.

"Enterprises simply cannot afford to ignore social media as a crisis communications tool," said Andrew Walls, research vice president at Gartner. "In many cases, social media may represent the only available means of locating and contacting personnel; providing stakeholders with the information and assistance they need; informing citizens, customers and partners of product/service availability; and taking other business-critical actions following a disruptive event."
However, Mr. Walls said that effective use of a new communications channel requires forward planning and practice. Attempting to leverage social media for the first time during a crisis can cause more harm than good. Instead, he said that organizations must develop comprehensive social media strategies and tactics for crisis/incident management and integrate social media with the enterprise's established business continuity management processes.
The use of social media for user input and knowledge sharing can create a conflict for organizations when the sites are being used during a crisis by the workforce and others that are involved or watching the event unfold.

"As the workforce develops personal, digital friendships that might take precedence over the official spokesperson of the organization, a conflict over who is the authority during an event can emerge, leading to unanticipated and negative results if official procedures are not followed," said Roberta Witty, research vice president at Gartner. "Such usage shouldn't turn into a battle for control, but organizations must protect their reputations and the effectiveness of their communications during stressful times. Therefore, putting forth a social media management strategy as part of a business continuity management program is essential to ensure that the organization's crisis communications effectiveness is protected, and that response and recovery plans and procedures are followed."

Social media is very different, technically and culturally, from the tightly controlled technologies and means of communication that enterprises are accustomed to using and supporting (such as corporate email systems). The use of social media for collection and distribution of information can create serious challenges for enterprises:
  • Maintaining an authoritative and credible information source;
  • Enlisting active, effective participation of staff and the public that are active in social media;
  • Collecting, filtering, analyzing and applying information gathered from social platforms
"Organizations developing social media strategies and tactics for crisis/incident management must take these factors into account by establishing effective authorization processes, content guidelines, and monitoring and message retention capabilities," Ms. Witty said. "The bottom line is that no enterprise's business continuity management efforts can afford to ignore the opportunities and risks presented by social media. BCM and crisis management specialists should begin working now to integrate social media tools and practices into their BCM efforts."

Sunday, February 19, 2012

Africa’s internet use sees 2 000% growth

Growth of internet use in Africa has gone beyond that of the global average in the last decade, reaching 2000 percent growth, compared to 480 percent growth globally.

Internet in Africa has grown at an incredible speed (image: Patrick Hajzler)
This significant growth is partly as a result of the increased capacity provided by new ICT infrastructure on the continent, including improved fiber-optic connectivity and increased accessibility to computers and mobile phones.
Internet penetration on the continent remains lower than that of the developed world however. South Africa, Ghana and Egypt experienced the most growth, according to Frost & Sullivan ICT analyst Birgitta Cederstrom.
“With the new undersea cables and terrestrial fiber roll-out, as well as the satellite influx across Africa, we expect to see close to double-digits in terms of growth in the more mature markets over the next two to three years,” she said.
Data service prices in Africa are set to drop in the coming year as well. In the next two to three years, the use of data services is expected to grow by as much as 60 percent.
Sarah Sheffer

Anonymous to shut down the internet..Can they really

Anonymous, the leaderless hacking collective, has vowed to effectively shut down the entire internet on 31 March.

The logo of hacker collective Anonymous (image: Forbes)
The group, which has been credited for bringing down sites such as HBGary, Amazon and Sony’s PlayStation Network, said they would attempt the shutdown to highlight the problems facing the internet, and to “protest SOPA (The Stop Online Piracy Act), Wall Street, our irresponsible leaders and the beloved bankers who are starving the world for their own selfish needs out of sheer sadistic fun”.
Anonymous communicates through Pastebin, and in the latest entry they detailed exactly how they will achieve their goal. The initiative is called Operation Global Blackout, and will be done by shutting down the “13 root DNS servers of the Internet”.
The group claims that it will attempt to prevent users of the net from performing domain name searches (entering any URL or doing a Google search), causing an error screen. “By cutting these off the Internet, nobody will be able to perform a domain name lookup, thus, disabling the HTTP Internet, which is, after all, the most widely used function of the Web.”
Although they will attack the entire internet, the group isn’t sure how long it will last. “It may only last one hour, maybe more, maybe even a few days. No matter what, it will be global. It will be known.”
Charlie Fripp – Online editor
For further assistance please contact enquiry@artcosolutions.com or artcosolution.com

Saturday, February 4, 2012

Is your organisation better prepared?

 2010 saw major earthquakes strike Haiti, Chile, China and Indonesia. It saw devastating floods in Pakistan and Australia. 2011 have brought out the opposite of resilience in people and organisation, confronted by the most extreme challenges. With flood events in Lagos, Australia, Brazil, the earthquakes in turkey, New Zealand, the tsunami in Japan, civil unrests in London, Greece, Spain, Italy, and the Arab spring of 2011, which ousted regimes in Tunisia, Egypt and Libya and created fuelled growing opposition to regimes in Syria, Yemen, Bahrain and other middle eastern states. These are very real recovery challenges that face organisations and you.  According to the Lloyd’s of London’s risk index 2011, 2011 was the second most expensive year ever for the insurance industry because of these incidents. 

In addition, while many of types of risk may be industry or regional specific, cyber risk is universal. 2011 saw the hacking of state network from India to Brazil to Nigeria. For businesses, the incident and frequency of data breaches have been even more unrelenting; Nintendo, Honda, Toshiba, Playstation, Nokia, Google, IMF, Wiki-leak and the Hong Kong stock exchange are victims of some form of cyber crime or hacking. A global estimate of cyber crime is now costing business around $114bn annually. Technical solutions are needed to evolve rapidly, together with more efficient reporting of breaches to help quantify the risk more accurately. 

By reflecting on disaster in terms of the need for strong, visible and distributes leadership, differentiated response, recovery and effective communication, organisations can achieve better outcomes with BCM, and reliably meet their obligations to regulators, boards and stakeholders. Since the true measure of a BCM plan is the success of it after an incident, organisations should apply the good practice approach which provides a baseline and common language to help BCM professionals to perform a rigorous Business Impact Analysis Assessment (BIA). The BIA is the foundation on which the whole BCM is built. It can be used to understand the impact of the failure to deliver a service or a product. The BIA identifies business activities across the organisation, identifies management owners of processes, identifies suitable staff, quantifies time scale and collects data for the Continuity Requirements Analysis (CRA). The good practice dictates that a BIA should be reviewed as a minimum annually but frequently in the event of business change, change to internal and external business process and significant change to risk and threats. Furthermore organisations must focus on robust BCM frame works strategies, resource allocation supporting continuity plans which objectively ‘fit for purpose’, practical and periodically tested and rehearsed.

After the unfolding events of the last two years, businesses need to give much greater priority to BCM planning carefully for those risks they cannot prevent, as well as being realistic about those they can. Organisations must determine its BCM strategy by using information gathered from the BIA, CRA and risk and threat assessment. Whatever strategy an organisation selects it has to ensure that it meets the target time for resuming the delivery of its products and services following its disruption. One strategy could be ‘balancing cost and speed of recovery’. In this strategy, there is always a trade off between cost and speed of recovery which needs to be balanced when selecting a strategy. So shorter recovery time objectives = higher cost and vice versa. Another strategy worth considering and is quite popular is ‘separation distance and the concept of “off site” it’s basically replicating operations in a different location. It reduces the likelihood of two sites being affected by the same incident except in cases like pandemics and cyber attacks.  Artco Solutions will also recommend a centralised access to data, emergency communications, emergency plans and key documents so senior management and employee have what they need when they need it.

As we have read, more than ever, businesses need effective BCM plans in place to protect their plants, infrastructure, property, staff, and supply chains from the fall of natural, political, social and economic threats.  

For further assistance please contact enquiry@artcosolutions.com

Friday, February 3, 2012

South Africa: top 10 business continuity issues for 2012


What are the risks that South African companies and their boards should be factoring into their planning for 2012? ContinuitySA has identified what it believes are the top issues facing business in 2012 that are likely to impact on business continuity strategies:

1. Socio-economic challenges ratchet up a notch
Last year, it seemed as though we might be coming out the recession, but now the talk is all about the dreaded double dip. Economic hardship is exacerbating social and political tensions, especially as retrenchments swell the hordes of unemployed. Too many people without work or the prospect of it places a huge burden on the state, provides the climate for crime and is likely to fuel tension between the haves and the have-nots.

2. Government performance and service delivery still lag behind expectation
Ongoing service delivery and corruption issues have continued to fuel widespread social unrest. Some commentators are even talking about popular uprisings comparable to those that occurred earlier in the year in North Africa. Instability in the ruling party continues to unsettle political and social life, and this will only get worse as the ANC’s leadership conference approaches. Meanwhile — no doubt fuelled in part by the economic problems mentioned above — strikes and social protests seem to be getting more prevalent.
For business, one direct consequence is frequent work stoppages, with staff actually finding it hard to get to their places of work.
“It seems that South Africa is coming to a crossroads again, faced with the choice between the high and low roads,” says Michael Davies, ContinuitySA’s managing director. “We have to have confidence that our leadership will make the right choices but, meanwhile, prudence demands a renewed focus on safety measures, including proper business continuity plans.”

3. National infrastructure remains weak—and the middle class is feeling the pinch
While Eskom contrived to come through a very cold winter with relatively few blackouts, concern remains high as summer is the time for planned maintenance. Another concern is the availability of skills to maintain the aging infrastructure at Koeberg, and to operate planned new nuclear power facilities. On the positive side, recent moves to introduce independent power generation and green power into the South African energy market are welcome.
That said, there are worrying reports that lack of additional energy capacity at present is affecting the ability of some data centres to expand.
Other infrastructural challenges include the new toll roads around Gauteng and the new national health insurance system. While both are desirable, they are placing additional financial burdens on the middle class—i.e. the small tax base on which everything rests. Is the middle class coming close to feeling as squeezed as the poor and unemployed and, if so, how will it make its distress known?

4. Water remains a concern
Water security remains a problem in this country, exacerbated by the pollution of our existing water stocks.
Although the government finally woke up to the problem of acid mine drainage and made R400 million available, media reports indicate that little action has actually occurred. If substantial progress is not made in finding a solution, the acid water is expected to begin decanting into the Johannesburg basin in March 2012—it is already decanting on the West Rand. Companies with IT equipment in basements need to remain on high alert.

5. Worsening business climate
The risks mentioned elsewhere will continue to weigh on risk-averse foreign investors, while the volatility of the rand will encourage destabilising capital movements. The socio-political challenges we have mentioned are also taking their toll on the outlook of local business. With the business confidence index declining, investment in equipment and people will be curtailed at a time when they are more necessary than ever. Militant unions and demands for increases that are significantly above inflation are further worsening the business outlook.
With revenues under pressure, many companies will be tempted to skimp on business continuity but this approach is short-sighted.

6. Regulatory burdens and responsibilities increase
Promulgated during 2011, the new Companies Act has made the directors of companies personally liable for the outcome of their decisions. The legislation is new and untested, making compliance even more risky than it might otherwise have been.
In combination with the recommendations of the King Commission, the new act has made risk management a much more important item on the board agenda—and this includes IT risk.
Boards are increasingly accountable to all stakeholders rather than just shareholders. In this regard, environmental issues are becoming more prominent, which may add impetus to the move towards cloud computing, which has the effect of greening the IT department.

7. The sting in the supply chain tail
Recent natural disasters like the volcanic eruption in Iceland and the earthquake and tsunami in Japan have emphasised the flipside of global interconnectedness. In order to ensure business continuity, companies must increasingly consider their entire supply chains. Adequate consulting around the business continuity threats originating outside of the organization is imperative.

8. Cloud computing blurs vision
As predicted, 2011 saw considerable movement in cloud computing. While it’s clear that cloud computing has real benefits, non-specialist public cloud offerings should not be confused with specialist business continuity, which is also making use of cloud-based approaches.
“The need to have absolute quality assurance and security in terms of your business continuity remains, especially in light of boards’ enhanced accountability,” Davies notes. “On the other hand, the greater availability of bandwidth and improvements in technology are changing the model.”

9. Mobility is creating huge new data risks
The growing range of smart mobile devices, and the explosion in useful applications, has made mobility a fact of life. At the same time, there is growing awareness of the value of a company’s data, hence the emergence of ‘data as a platform’. Securing and backing up the corporate data on mobile devices usually owned by employees rather than companies is raising CIOs’ temperatures worldwide.

10. Business continuity is still not integrated into corporate strategy
Given the scale and magnitude of the challenges business faces, the danger remains that business continuity is marginalised and siloed. In many instances, financial pressures are causing companies to cut back on business continuity. For example, banks which have retrenched large numbers of people now have excess office space which they tend to use to provide their own workplace recovery—and this may lead to a business continuity solution that is less than optimal.
A related issue is that the long-term viability of smaller business continuity providers is looking less certain in this climate. We think this will prompt a ‘flight to quality’ in many cases.
As indicated above, the emergence of new opportunities to remodel business continuity using a private cloud approach is a game-changer, offering cost savings, a much more effective product and the opportunity to get a return on your business continuity investment.
www.continuitysa.com

Saturday, January 14, 2012

Does BCM exist in Afica?





Business Continuity management (BCM) has become a very important aspect of good corporate governance and has become a part of best practice recommendations in various countries. However, in Africa, BCM is still in its infancy, and is nonexistent in a few African countries.

It is crucial to separate Africa from the rest of the world because the continent has its unique set of challenges that could disrupt business at any time. Think of draught, poor supply chain infrastructure, political instability, bureaucracy and industrial actions. Furthermore, power disruption and pandemics such as HIV/AIDS also have impacts on workers, is a real concern in Africa.

Many organisation leave BCM until a crisis. BCM is simply the ability to maintain operations and services during a disruptive event. It provides a framework for building organisational resilience with the capacity for an effective response that safeguards the interest of key stakeholders, reputation, brand and value creating activities.

Remember the Blackberry outage in October 2011? That is a good example of poor Business Continuity Management. It appears that the most recent service outage will no doubt have a long term impact on Research in Motion (RIM). The poor crisis response contributed to the drop of its Smartphone market share from 19% year earlier to 12% in 2011.

The lack of BCM is not a story about Africa unwilling to follow the rest of the world, but the story of how Africa lacks awareness, leadership and standardisation. Some central banks on the continent are beginning to take matters in their own hands by creating their own BCM guidelines for the banking community in their country. Countries like Kenya, Nigeria, Tanzania and Ghana have all developed a set of standards that can be applied in the African Context.

The next few points will discuss some of the challenges Africa needs to overcome before BCM can become a norm in the private and public sector.

1.     Lack of Skills

There are not enough skilled people to meet the continent’s need. The continent needs to promote and invest more on developing graduates and encourage more professionals to learn about the business discipline.

2.     Awareness

Another challenge Africa is to overcome is the lack of awareness. There is a need for standardisation in the continent that is globally recognised and acceptable. The region as a whole is to be aware of these standards and how important it is to implement effectively.
The successful establishment of BCM has to be embedded in national and organisational cultures by training and education.

3.     Understanding

With awareness comes understanding of what BCM really is. There are some misconceptions of what BCM is. Many managers think BCM is all about backing up data. No, it not just about backing up data in a remote location. It is a holistic process that identifies potential threats to an organisation and the impact to business operations that those threats, if realised, might cause. BCM is critical to ‘Business As Usual’ it is a benchmark for a resilient organisation.

4.     Long term management and maintenance

Even when awareness and understanding is improved through the educational effort of professional BCM companies, the lack of skills limits the effective implementations and maintenance of plans. Consultants often engaged by organisations develop and roll out BCM plans, design an efficient system for them. However the problems occur once the consultants have left. BCM is a continual process that needs to be tested and updated regularly, so training people in BCM skills is crucial for an effective strategy.

5.     Cost

Every company is concerned about costs and Business Continuity can be an expensive affair, especially if solutions are created in-house. In many instances, Business Continuity is put on the backburner simply because of the costs involved in setting up a programme. This is the wrong approach to take. If executives consider the expenses involved in creating their Business Continuity plan and then compare it to the amount of money it would take to recover from a serious disaster without such a plan, they would realise that the initial costs are quite reasonable. The Information Warfare Site states that fires permanently close 44 per cent of businesses affected, while after the 1993 World Trade Centre bombing, 150 businesses out of 350 affected (that did not prepare BCM plans) failed to survive the event.

Finally, business continuity process is a necessary sustainability tool for maintaining successful business operations and securing more Foreign Direct Investment (FDI) in Africa.  We have to cultivate the sprit of getting things done, planning for, anticipating and minimising disruptive event. Let us protect our stakeholder.

Considering a BCM plan? Talk to Artcosolutions on enquiry@artcosolutions.com