business continuity - are you ready for disaster? · yes! now we are ready for disaster.....

18
Business Continuity - Are you Ready for Disaster? Sara McAneney IT Security Officer Trinity College Dublin Date 12/11/2015

Upload: others

Post on 22-Aug-2020

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Business Continuity - Are you Ready for Disaster? · Yes! Now we are ready for disaster.. Infrastructure Readiness Business Area BCP IT Department BCP • Roles & Responsibilities

Business Continuity - Are you Ready for Disaster?

Sara McAneneyIT Security Officer Trinity College Dublin

Date 12/11/2015

Page 2: Business Continuity - Are you Ready for Disaster? · Yes! Now we are ready for disaster.. Infrastructure Readiness Business Area BCP IT Department BCP • Roles & Responsibilities

Trinity College Dublin, The University of Dublin

The Spectrum of Disaster Readiness

Denial Partially scoped/documented/tested

Fully Scoped/documented/tested

€€

Page 3: Business Continuity - Are you Ready for Disaster? · Yes! Now we are ready for disaster.. Infrastructure Readiness Business Area BCP IT Department BCP • Roles & Responsibilities

Trinity College Dublin, The University of Dublin

Defining Disaster

.

Page 4: Business Continuity - Are you Ready for Disaster? · Yes! Now we are ready for disaster.. Infrastructure Readiness Business Area BCP IT Department BCP • Roles & Responsibilities

Trinity College Dublin, The University of Dublin

Defining Disaster

Hardware failure

Software Failure

Power failure Cooling failure

Malware Cyber attack Industrial

Action

Public transportation

disruption

Epidemic Storm EarthquakeAct of

Terrorism

Act of Sabotage

Act of War Human Error

Page 5: Business Continuity - Are you Ready for Disaster? · Yes! Now we are ready for disaster.. Infrastructure Readiness Business Area BCP IT Department BCP • Roles & Responsibilities

Trinity College Dublin, The University of Dublin

Where to start?

Risk Analysis

• Identify the risks impact x likelihood

Business Impact Analysis

• Prioritise Key Business Services

• Recovery time objective (RTO)

• Recovery Point objective (RPO)

Page 6: Business Continuity - Are you Ready for Disaster? · Yes! Now we are ready for disaster.. Infrastructure Readiness Business Area BCP IT Department BCP • Roles & Responsibilities

Trinity College Dublin, The University of Dublin

Risk analysis

Page 7: Business Continuity - Are you Ready for Disaster? · Yes! Now we are ready for disaster.. Infrastructure Readiness Business Area BCP IT Department BCP • Roles & Responsibilities

Trinity College Dublin, The University of Dublin

Key Business Systems

Page 8: Business Continuity - Are you Ready for Disaster? · Yes! Now we are ready for disaster.. Infrastructure Readiness Business Area BCP IT Department BCP • Roles & Responsibilities

Trinity College Dublin, The University of Dublin

Infrastructure & Environment

2 Data Centres

Only 300 metres apart

Data Backup Offsite

On tape - slow recovery

Resilient Link to Internet

Single points of failure on campus

Page 9: Business Continuity - Are you Ready for Disaster? · Yes! Now we are ready for disaster.. Infrastructure Readiness Business Area BCP IT Department BCP • Roles & Responsibilities

Trinity College Dublin, The University of Dublin

DR Action Plan

A Project to :

• Provision a Disaster Recovery Site

• Improve Resilience on Campus

• Ensure all Facilities covered for Fire Suppression, Backup Power etc

• Back Data up Offsite to Disk

Page 10: Business Continuity - Are you Ready for Disaster? · Yes! Now we are ready for disaster.. Infrastructure Readiness Business Area BCP IT Department BCP • Roles & Responsibilities

Trinity College Dublin, The University of Dublin

Disaster Recovery Infrastructure

Page 11: Business Continuity - Are you Ready for Disaster? · Yes! Now we are ready for disaster.. Infrastructure Readiness Business Area BCP IT Department BCP • Roles & Responsibilities

Trinity College Dublin, The University of Dublin

Finished?

Page 12: Business Continuity - Are you Ready for Disaster? · Yes! Now we are ready for disaster.. Infrastructure Readiness Business Area BCP IT Department BCP • Roles & Responsibilities

Trinity College Dublin, The University of Dublin

Business Continuity Plan for IT Services

Roles and Responsibilities

Emergency Contacts

Supplier Contacts

Vital DocumentsCommunications

PlanCredential Storage

Facility Access Details

Recovery Plans for supporting

infrastructure DHCP,DNS etc.

Page 13: Business Continuity - Are you Ready for Disaster? · Yes! Now we are ready for disaster.. Infrastructure Readiness Business Area BCP IT Department BCP • Roles & Responsibilities

Trinity College Dublin, The University of Dublin

Finished?

BCP extends out of IT…

Page 14: Business Continuity - Are you Ready for Disaster? · Yes! Now we are ready for disaster.. Infrastructure Readiness Business Area BCP IT Department BCP • Roles & Responsibilities

Trinity College Dublin, The University of Dublin

Yes! Now we are ready for disaster..

Infrastructure Readiness

Business Area

BCP

IT Department

BCP

• Roles & Responsibilities• Credential Management• Data Verification• Testing prior to returning

application to live operation

Page 15: Business Continuity - Are you Ready for Disaster? · Yes! Now we are ready for disaster.. Infrastructure Readiness Business Area BCP IT Department BCP • Roles & Responsibilities

Trinity College Dublin, The University of Dublin

Evolving DR landscape

Cloud adoption offers opportunities

• Disaster recovery as a service (DRaaS)

• Recovery using infrastructure as a service (IaaS)

• Recovery using backup as a service (BaaS)

Cloud brings new complexity

• SaaS applications

• Service levels

• New Test scenarios for the BCP

Page 16: Business Continuity - Are you Ready for Disaster? · Yes! Now we are ready for disaster.. Infrastructure Readiness Business Area BCP IT Department BCP • Roles & Responsibilities

Trinity College Dublin, The University of Dublin

Magic Quadrant for DRaaS – Gartner

“The majority of early DRaaS adopters are small organizations whose data centre infrastructure is typically less than 100 servers.” Gartner 2015

Page 17: Business Continuity - Are you Ready for Disaster? · Yes! Now we are ready for disaster.. Infrastructure Readiness Business Area BCP IT Department BCP • Roles & Responsibilities

Trinity College Dublin, The University of Dublin

Shadow IT

What systems/applications

are in use

Where is our institutional data

being stored

What contingency is in place for these

systems?

Who is responsible for this?

How can this we reconcile this with

our compliance commitments?

“Average an organization is using 953 cloud services… with less than 1% of those services authorized by the enterprises' IT departments.”

Sky High Networks 2015

Page 18: Business Continuity - Are you Ready for Disaster? · Yes! Now we are ready for disaster.. Infrastructure Readiness Business Area BCP IT Department BCP • Roles & Responsibilities

Thank You