0% found this document useful (0 votes)
6 views3 pages

Disa Project Work

The project report outlines an audit of XYZ Manufacturing Ltd., focusing on their business continuity planning (BCP) in light of regulatory requirements and past disruptions. Key findings include a lack of offsite backups and reliance on a single supplier, with recommendations for implementing AWS backups and onboarding alternate suppliers. The BCP aims to enable recovery of critical operations within 24 hours, significantly reducing risks.

Uploaded by

Deepesh Jagwani
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
6 views3 pages

Disa Project Work

The project report outlines an audit of XYZ Manufacturing Ltd., focusing on their business continuity planning (BCP) in light of regulatory requirements and past disruptions. Key findings include a lack of offsite backups and reliance on a single supplier, with recommendations for implementing AWS backups and onboarding alternate suppliers. The BCP aims to enable recovery of critical operations within 24 hours, significantly reducing risks.

Uploaded by

Deepesh Jagwani
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

B.

Project Report (Solution)

1. Introduction

Auditee Overview:
XYZ Manufacturing Ltd. produces automotive components with 5 factories across India. It uses ERP
(SAP), IoT-enabled machines, and cloud-based inventory systems.

Audit Firm (Fictitious):


Alpha Auditors LLP, a team of 4 IS auditors with expertise in BCP, ISO 22301, and manufacturing risk
assessment.

2. Auditee Environment

Aspect Details

Business Nature Automotive parts manufacturing (B2B).

IT Infrastructure SAP ERP, Oracle DB, AWS Cloud, IoT sensors.

Policies Information Security Policy (ISP) exists but lacks BCP integration.

Visual: Organizational Structure Diagram (Factory > IT > Supply Chain).

3. Background

 Why BCP? Regulatory requirements (SEBI, RBI) and past disruptions (e.g., 2023 cyberattack).

 Goals: Minimize downtime, ensure supplier redundancy, comply with ISO 22301.

4. Situation

Current Gaps:

 IT: No offsite backups.

 Operations: No alternate suppliers for critical raw materials.

 Compliance: BCP not tested annually.

Visual: Pie Chart of Risk Distribution (Cyber 40%, Supply Chain 30%, Equipment 20%).

5. Terms and Scope

 In Scope: IT systems, supply chain, factory operations.

 Out of Scope: HR policies, marketing.


6. Logistic Arrangements

Resource Purpose

Laptops with ACL Data analysis for recovery time objectives.

AWS Backup
Cloud-based BCP testing.
Suite

7. Methodology

Phases:

1. Risk Assessment (ISO 31000).

2. BCP Design (RTO/RPO calculations).

3. Testing (Tabletop exercises).

Visual: Flowchart of BCP Implementation Steps.

8. Documents Reviewed

 IT Disaster Recovery Policy.

 Supplier Contracts.

 ISO 22301 Compliance Checklist.

9. References

 ISO 22301:2019.

 NIST SP 800-34.

 ICAI’s IS Audit Guidelines.

10. Deliverables

 Draft/Final BCP Report.

 Executive Summary.

 Risk Heat Map (Table: Likelihood vs. Impact).


11. Findings & Recommendations

Finding Recommendation

No offsite backups. Implement AWS S3 backups (RPO < 4 hours).

Single supplier
Onboard 2 alternate suppliers.
reliance.

12. Summary/Conclusion

The BCP ensures XYZ Ltd. can recover critical operations within 24 hours, reducing financial and
reputational risks. Annual drills and cloud adoption are key next steps.

Visual: Before/After BCP Comparison Graph (Downtime reduced by 70%).

You might also like