Name of Institution
Infrastructure for Cloud
Dr. Nitish Kumar Ojha
Syllabus Name of Institution
Business Continuity
& Disaster Recovery
Business Impact Analysis
RPO/RTO
Disaster Recovery
Testing, Backups, Audit
Imagine a company…
Bank with 1 Million accounts, social security numbers, credit
cards, loans…
Airline serving 50,000 people on 250 flights daily…
Pharmacy system filling 5 million prescriptions per year, some of
the prescriptions are life-saving…
Factory with 200 employees producing 200,000 products per day
using robots…
Imagine a system failure…
Server failure
Disk System failure
Hacker break-in
Denial of Service attack
Extended power failure
Snow storm
Spyware
Malevolent virus or worm
Earthquake, tornado
Employee error or revenge
How will this affect each business?
Objectives
Running a business continuity and disaster recovery planning project.
Developing business continuity and disaster recovery plans.
Testing business continuity and disaster recovery plans.
Training users.
Maintaining business continuity and disaster recovery plans
What is a Disaster ??
Any natural or man-made event that disrupts the operations of a business in such
a significant way that a considerable and coordinated effort is required to
achieve a recovery.
Natural Disasters
Geological: earthquakes, volcanoes, tsunamis, landslides, and sinkholes
Meteorological: hurricanes, tornados, wind storms, hail, ice storms, snow storms, rainstorms,
and lightning
Other: avalanches, fires, floods, meteors and meteorites, and solar storms
Health: widespread illnesses, quarantines, and pandemics
Man-made Disasters
Labor: strikes, walkouts, and slow-downs that disrupt services and supplies
Social-political: war, terrorism, sabotage, vandalism, civil unrest, protests,
demonstrations, cyber attacks, and blockades
Man-made Disasters (cont.)
Materials: fires, hazardous materials spills
Utilities: power failures, communications outages, water supply
shortages, fuel shortages, and radioactive fallout from power plant
accidents
How Disasters Affect Businesses
Direct damage to facilities and equipment.
Transportation infrastructure damage
Delays deliveries, supplies, customers, employees going to work.
Communications outages
Utilities outages
How BCP and DRP Support Security
BCP (Business Continuity Planning) and DRP (Disaster Recovery Planning).
Security pillars: C-I-A
Confidentiality
Integrity
Availability
BCP and DRP directly support availability
The Role of Prevention
Not prevention of the disaster itself
Prevention of surprise and disorganized response
Reduction in impact of a disaster
Better equipment bracing
Better fire detection and suppression
Contingency plans that provide [near] continuous operation of critical business processes
Prevention of extended periods of downtime
First Step:
Business Impact Analysis
Which business processes are of strategic importance?
What disasters could occur?
What impact would they have on the organization financially? Legally? On human life?
On reputation?
What is the required recovery time period?
Answers obtained via questionnaire, interviews, or meeting with key users of IT
Event Damage Classification
Negligible: No significant cost or damage
Minor: A non-negligible event with no material or financial impact on the business
Major: Impacts one or more departments and may impact outside clients
Crisis: Has a major material or financial impact on the business.
Minor, Major, & Crisis events should be documented and tracked to repair
Workbook: Disasters and Impact
Problematic Event or Affected Business Process(es) Impact Classification &
Incident Effect on finances, legal liability,
(Assumes a university) human life, reputation
Fire Class rooms, business departments Crisis, at times Major,
Human life
Hacking Attack Registration, advising, Mentoring Major,
Legal liability
Network Unavailable Registration, advising, classes, Crisis
homework, education
Social engineering, Registration, Major,
/Fraud Legal liability
Server Failure Registration, advising, classes, Major, at times: Crisis
(Disk/server) homework, education.
Develop Key Recovery Targets
Recovery Time Objective (RTO)
Period of time from disaster onset to resumption of business process.
Recovery Point Objective (RPO)
Maximum period of data loss from onset of disaster counting backwards.
Amount of work that will have to be done over.
Recovery Time: Terms
Interruption Window: Time duration organization can wait between point of failure and service
resumption
Service Delivery Objective (SDO): Level of service in Alternate Mode
Maximum Tolerable Outage: Max time in Alternate Mode
Disaster
Recovery
Plan Implemented
Regular Service Regular
Service
SDO Alternate Mode
Time… Restoration
Interruption Interruption Plan Implemented
Window
Maximum Tolerable Outage
Definitions
Business Continuity: Offer critical services in event of disruption.
Disaster Recovery: Survive interruption to computer information systems.
Alternate Process Mode: Service offered by backup system.
Disaster Recovery Plan (DRP): How to transition to Alternate Process Mode.
Restoration Plan: How to return to regular system mode
Classification of Services
Critical $$$$: Cannot be performed manually. Tolerance to interruption is very low.
Vital $$: Can be performed manually for very short time.
Sensitive $: Can be performed manually for a period of time, but may cost more in staff.
Nonsensitive ¢: Can be performed manually for an extended period of time with little
additional cost and minimal recovery effort
Determine Criticality of Business Processes
Corporate
Shipping Engineering
Sales (1)
(2) (3)
Web Sales Calls Product A Product B
Service (1) (2) (1) (2)
Product A
Orders (1)
(1)
Product B Inventory
(2) (2)
Product C
(3)
RPO and RTO
Interruption
Recovery Point Objective Recovery Time Objective
1 1 1 1 1 1
Week Day Hour Hour Day Week
How far back can you fail to? How long can you operate without a system?
One week’s worth of data? Which services can last how long?
Recovery Point Objective
Backup Mirroring:
Images RAID
Orphan Data: Data which is lost and never recovered.
RPO influences the Backup Period
Business Impact Analysis Summary Work
Book
Service Recovery Recovery Critical Special Notes
Point Time Resources (Unusual treatment at
Objective Objective (Computer, Specific times, unusual risk conditions)
(Hours) (Hours) people,
peripherals)
Registration 0 hours 4 hours SOLAR, network High priority during Nov-Jan,
Registrar March-June, August.
Personnel 2 hours 8 hours PeopleSoft Can operate manually for some time
Teaching 1 day 1 hour D2L, network, During school semester: high priority.
faculty files
Partial BIA for a university
RAID – Data Mirroring
AB CD ABCD ABCD
RAID 0: Striping RAID 1: Mirroring
AB CD Parity
Higher Level RAID: Striping & Redundancy
Redundant Array of Independent Disks
Disruption vs. Recovery Costs
Service Downtime
Cost * Hot Site
* Warm Site
Alternative Recovery Strategies
Minimum Cost * Cold Site
Time
Alternative Recovery Strategies
Hot Site: Fully configured, ready to operate within hours.
Warm Site: Ready to operate within days: no or low power main computer. Does contain
disks, network, peripherals.
Cold Site: Ready to operate within weeks. Contains electrical wiring, air conditioning,
flooring.
Reciprocal Agreement with another organization or division.
Mobile Site: Fully- or partially-configured trailer comes to your site, with microwave or
satellite communications
What is Cloud Computing?
Laptop
Database
Cloud Web Server
Computing
App Server
VPN Server PC
Introduction to Cloud
ThisThis
would cost $200/month.
would cost
$200/month.
NIST Visual Model of Cloud Computing Definition
National Institute of Standards and Technology, [Link]
Cloud Service Models
Software(SaaS): Provider runs own
applications on cloud infrastructure.
• Cloud’s
SAAS Software &
Apps
Platform(PaaS): Consumer provides • Your Application
apps; provider provides system and PAAS • E.g., Cloud’s
DB, OS
development environment. • Cloud’s
IAAS Computer
• OS, networks
Infrastructure(laaS): Provides
customers access to processing, storage,
networks or other fundamental resources
Business Continuity Process
Perform Business Impact Analysis.
Prioritize services to support critical business processes
Determine alternate processing modes for critical and vital services
Develop the Disaster Recovery plan for IS systems recovery
Develop BCP for business operations recovery and continuation
Test the plans
Maintain plans
Disaster Recovery
Disaster Recovery
Testing
An Incident Occurs…
Call Security Emergency Response
Officer (SO) Team: Human life:
or committee First concern
member
Phone tree notifies
relevant participants
Security officer
declares disaster
Public relations
interfaces with media
(everyone else quiet)
SO follows
pre-established
Mgmt, legal
protocol
council act
IT follows Disaster
Recovery Plan
Concerns for a BCP/DR Plan
Evacuation plan: People’s lives always take first priority
Disaster declaration: Who, how, for what?
Responsibility: Who covers necessary disaster recovery functions
Procedures for Disaster Recovery
Procedures for Alternate Mode operation
Resource Allocation: During recovery & continued operation
Copies of the plan should be off-site
Disaster Recovery Responsibilities
General Business IT-Specific Functions
First responder: Software
Evacuation, fire, health… Application
Damage Assessment Emergency operations
Emergency Mgmt Network recovery
Legal Affairs Hardware
Transportation/ Database/Data Entry
Relocation/Coordination Information Security
(people, equipment)
Supplies
Salvage
Training
Criticality Analysis
Rank processes by criticality criteria
MTD (maximum tolerable downtime)
RTO (recovery time objective)
RPO (recovery point objective)
Cost of downtime or other metrics
Qualitative criteria
Reputation, market share, goodwill
Testing Objectives
Main objective: existing plans will result in successful recovery of
infrastructure & business processes
Also can:
• Identify gaps or errors
• Verify assumptions
• Test time lines
• Train and coordinate staff
Auditing BCP
Includes:
Is BIA complete with RPO/RTO defined for all services?
Is the BCP in-line with business goals, effective, and current?
Is it clear who does what in the BCP and DRP?
Is everyone trained, competent, and happy with their jobs?
Is the DRP detailed, maintained, and tested?
Is the BCP and DRP consistent in their recovery coverage?
Are people listed in the BCP/phone tree current and do they have a copy of BC manual?
Are the backup/recovery procedures being followed?
Does the hot site have correct copies of all software?
Is the backup site maintained to expectations, and are the expectations effective?
Was the DRP test documented well, and was the DRP updated?
Summary of BC Security Controls
• RAID
• Backups: Incremental backup, differential backup
• Networks: Diverse routing, alternative routing
• Alternative Site: Hot site, warm site, cold site, reciprocal agreement, mobile
site
• Testing: checklist, structured walkthrough, simulation, parallel, full interruption
• Insurance
Thanks