IT DRILLDOWN
 
NEWSLETTERS
 

CIO.com updates, insights and advice on technology, management and your career.

 
 
 
LEADERSHIP
 
CIO Executive Programs
The Leader in Face-to-Face Education for Senior Executives

Offering regional and national programs, CIO (and CSO) events bring together some of the most respected names and thought leaders in information technology and security. Presented by CIOs and other senior level executives, these invitation-only programs offer timely topics and strong networking. Learn More »

 
CIO Executive Council
A Peer-Advisory Service and Professional Association for CIOs

Social Responsibility's Strategic Benefits

December 15, 11:30 AM - 12:30 PM US/Eastern (GMT-5)

Join Ed Granger-Happ, CIO of Save the Children, for a discussion of how creating an organization that is socially responsible improves staffing, retention, leadership development and overall corporate health.

Working With and Communicating to Your Board of Directors

January 13, 2009, 4:00 PM - 5:00 PM US/Eastern (GMT-5)

CIO panelists who will share tips and experiences working with their boards: Twila Day of SYSCO; Jeff O'Hare, West Corp.; Marc West, formerly with H&R Block.

IT's Role in Growing Mid-Market Companies

January 14, 4:00 PM - 5:00 PM ET (GMT-5)

Mid-market Council members will share their companies' stories and challenges in driving or coping with growth. Panelists represent Veterinary Pet Insurance, Medicis Pharmaceutical, and Intrax Cultural Exchange.

More / Register »

Learn more about the CIO Executive Council »



 
 
RESOURCE CENTER
 
 
 
SUBSCRIBE TO CIO
 
Are you involved in setting the direction for your company's IT budget or strategy?

Apply today for a FREE subscription to CIO Magazine!

 
 

ABC: An Introduction to Business Continuity and Disaster Recovery Planning

Good business continuity plans will keep your company up and running. This primer helps make sure you've covered all the bases.

 

PAGE 2

What’s the difference between disaster recovery and business continuity planning?
What does a disaster recovery and business continuity plan include?
How do I get started?
Is it really necessary to disrupt business by testing the plan?
What kinds of things have companies discovered when testing a plan?
What are the top mistakes that companies make in disaster recovery?
I still have a binder with our Y2K plan. Will that work?
Can we outsource our contingency measures?
How can I sell this business continuity planning to other executives?
How do I make sure the plans aren’t overkill for my company?
Related articles from CSO magazine

Where do I start?

A good first step is a business impact analysis (BIA). This will identify the business's most crucial systems and processes and the effect an outage would have on the business. The greater the potential impact, the more money a company should spend to restore a system or process quickly. For instance, a stock trading company may decide to pay for completely redundant IT systems that would allow it to immediately start processing trades at another location. On the other hand, a manufacturing company may decide that it can wait 24 hours to resume shipping. A BIA will help companies set a restoration sequence to determine which parts of the business should be restored first.

Here are 10 absolute basics your plan should cover:

   1. Develop and practice a contingency plan that includes a succession plan for your CEO.
   2. Train backup employees to perform emergency tasks. The employees you count on to lead in an emergency will not always be available.
   3. Determine offsite crisis meeting places for top executives.
   4. Make sure that all employees-as well as executives-are involved in the exercises so that they get practice in responding to an emergency.
   5. Make exercises realistic enough to tap into employees' emotions so that you can see how they'll react when the situation gets stressful.
   6. Practice crisis communication with employees, customers and the outside world.
   7. Invest in an alternate means of communication in case the phone networks go down.
   8. Form partnerships with local emergency response groups-firefighters, police and EMTs-to establish a good working relationship. Let them become familiar with your company and site.
   9. Evaluate your company's performance during each test, and work toward constant improvement. Continuity exercises should reveal weaknesses.
  10. Test your continuity plan regularly to reveal and accommodate changes. Technology, personnel and facilities are in a constant state of flux at any company.

Hold it. Actual live-action tests would, themselves, be the "disruptive events." If I get enough people involved in writing and examining our plans, won't that be sufficient?

Let us give you an example of a company that thinks tabletops and paper simulations aren't enough. And why their experience suggests they're right.

When CIO Steve Yates joined USAA, a financial services company, business continuity exercises existed only on paper. Every year or so, top-level staffers would gather in a conference room to role-play; they would spend a day examining different scenarios, talking them out-discussing how they thought the procedures should be defined and how they thought people would respond to them.

Live exercises were confined to the company's technology assets. USAA would conduct periodic data recovery tests of different business units-like taking a piece of the life insurance department and recovering it from backup data.

Yates wondered if such passive exercises reflected reality. He also wondered if USAA's employees would really know how to follow such a plan in a real emergency. When Sept. 11 came along, Yates realized that the company had to do more. "Sept. 11 forced us to raise the bar on ourselves," says Yates.

Yates engaged outside consultants who suggested that the company build a second data center in the area as a backup. After weighing the costs and benefits of such a project, USAA initially concluded that it would be more efficient to rent space on the East Coast. But after the attack on the World Trade Center and Pentagon, when air traffic came to a halt, Yates knew it was foolhardy to have a data center so far away. Ironically, USAA was set to sign the lease contract the week of Sept. 11.

Instead, USAA built a center in Texas, only 200 miles away from its offices-close enough to drive to, but far enough away to pull power from a different grid and water from a different source. The company has also made plans to deploy critical employees to other office locations around the country.

Yates made site visits to companies such as FedEx, First Union, Merrill Lynch and Wachovia to hear about their approach to contingency planning. USAA also consulted with PR firm Fleishman-Hillard about how USAA, in a crisis situation, could communicate most effectively with its customers and employees.

Finally, Yates put together a series of large-scale business continuity exercises designed to test the performance of individual business units and the company at large in the event of wide-scale business disruption. When the company simulated a loss of the primary data center for its federal savings bank unit, Yates found that it was able to recover the systems, applications and all 19 of the third-party vendor connections. USAA also ran similar exercises with other business units.

For the main event, however, Yates wanted to test more than the company's technology procedures; he wanted to incorporate the most unpredictable element in any contingency planning exercise: the people.

USAA ultimately found that employees who walked through the simulation were in a position to observe flaws in the plans and offer suggestions. Furthermore, those who practice for emergency situations are less likely to panic and more likely to remember the plan.

Loading...
 
 
ABCs
 

Just the basics, please. Sometimes we all need a refresher or we need to make sure our team and our colleagues are all on the same page.

Over 25 tutorials on everything from business intelligence to virtualization.

 
 
FEATURED SPONSORS
 
 
 
SPONSORED LINKS
 

The Right and Wrong Master Data Management Strategies to Start Small and Grow Big

Paving the Way for Trusted Collaboration

First-hand look at this never before seen research

Effectively Managing High-Performing, Business-Critical Web Applications

Managing Service Level Agreements to Achieve Business Goals

APM Solutions: A Window into Complex Web Applications

APM Solutions Offer Insight into Complex Web Applications

Ponemon Study: How Much Does a Data Breach "Cost"?

Enabling the Global Enterprise Webcast: Learn why businesses are turning to wide-area data services

Effective Security with a Continuous Approach to ISO 27001 Compliance

High-performance computing is no longer just for Big Business

IT Service Management: Metrics That Matter

Deliver Social Computing Business Value

Make Hidden Trends, Inter-Relationships and Influences Visible.

7 Requirements of Data Loss Prevention

A Guide to Understanding Hosted and Managed Messaging

Google Apps Premier Edition Helps Indoff Manage E-mail More Effectively

CapGemini Cut Call Center Costs with Google Apps Premier Edition

Comprehensive Review of Security and Vulnerability Protections for Google Apps

Web 2.0 The New Face of the Web

Universal Search in Healthcare Organizations

Google Case Study: Agile Software

Universal Search in High Tech Organizations

Providing Universal Search for Business

Google Case Study: Kimberly-Clark

Webcast: Mitigate Operational Risk- Real Answers for Tough Times

Fulfill Your Remote Access Strategy for Mobile Users

State of the Market: Application Performance Management

Proactively Identify and Resolve Performance Issues

Union Bank of California Improves its Online Banking Services

The Link Between APM and Customer Satisfaction

Providing Around-the-Clock Customer Satisfaction

Five Best Practices for Enterprise Collaboration Success

Optimizing Infrastructure Control

Expand High-Performance Computing (HPC) Capabilities

Power the Platform of Choice for Virtualization in the Enterprise

The Nokia and Cisco mobility solution that has created true business transformation.

The ECM Paradox: Extending Local Flexibility to Strengthen Central Control

Customer Insight Yields Sales, Marketing Gains

Best Practices in Choosing and Consuming Managed Security Services

A Guide to Messaging Archiving

2008 Google Communications Intelligence Report

The Impact of Messaging and Web Threats

Comparing Google and Other Leading Messaging Security Solutions

Deploying a Google Search Appliance is Not your Typical IT Implementation

Google Case Study: Pioneer Investments

The Case for Universal Search

Universal Search in Financial Services Organizations

Google Case Study: Sunnybrook Health Sciences

Learn About the Features of the Google Universal Search Solution.