Você está na página 1de 3

Information Technology

Disaster Recovery
Planning for IT System
Kamran Abbas is a CA finalist and is currently involved as Technical Consultant to Ministry of
Finance (GoP) on Medium Term Budgetary Framework (MTBF) a new, scientific approach to
national budget.

What is Disaster Recovery Planning Classically, disaster recovery planning covers a defined
The Disaster Recovery Planning is a significant element period of time, enabling the organization to carry on
of business continuity planning. Business Continuity operations at the same time as the old data center is
Planning (BCP) is the progression of creating, testing and repaired or a new data center is assembled. When a
maintaining an enterprise-wide plan to recover from any major disaster occurs, organizations need to have an
form of disaster. alternate site to set up computer systems and install
applications software before data from backup tapes can
be restored.
Disaster Recovery Planning (DRP) for Information
Technology has become a vital feature of business
The plan should deal with the fact that servers, unlike
continuity planning. It is essential that the organization
desktop computers, cannot be readily purchased off the
takes the development and maintenance of the disaster
shelf. And given that it may be unrealistic to recuperate all
recovery plan seriously. It is not a job that can be ignored
computer applications in a diminutive time span, the plan
until someone finds adequate time to deal with it. An should prioritize the recovery of applications. Most
unfortunate event can occur at any time. If you were to organizations cannot function without electronic
ask an assorted group of organizations what would communication i.e., e-mail, so re-establishing e-mail
happen if their computer systems were destroyed by service is usually a top priority. Most of the organizations
some type of disaster, a wide-ranging reply would be that also rely on their web sites to provide services, both
the company preserves backup tapes of data stored inside and externally. For such organizations, a sufficient
offsite. A vast majority of businesses would have nothing Internet connection would be part of the initial disaster
more than that. recovery steps. It is good practice for the organization's
top management to show an apparent commitment for
The critically vital feature of disaster recovery planning is establishing and maintaining an effective disaster
to assess the possible risks to the organization should recovery planning process.
computer systems be inaccessible or inoperable for an
extended period of time. DRP should encompass every All layers of management and employees should be
kind of business interruption from the slightest two- informed that a disaster recovery plan is required in order
second power outage or spike-up to the most horrible to make sure that indispensable functions of the
likely natural disaster or terrorist attack (recall 9/11/01). organization are able to continue in the event of disaster.

September-December 2007 The Pakistan Accountant 37


Information Technology

Every organization should set up for possible radical Phase 1: Critical Analysis of Processes
situations, and should consider what type of back-up and w Identify which business divisions and processes are
preventive strategies would be appropriate for each facet critical and contribute most to the delivery of the
of their activities. company's services and products;

The difficulties and financial cost of back-up procedures w Identify the requirements necessary to support these
and systems may well depend upon the identified speed
processes during an extended outage;
with which systems or business processes need to be
restored. This should be premeditated in advance.
w Establish the type of disasters you are planning for;
The Policy for Disaster Recovery
w Identify the purpose;
Planning
The strategic level of the organization should issue a lucid
w Identify which computer applications need to be
policy statement on disaster recovery planning. The
recovered first;
policy statement should contain the following instructions:
Phase 2: The Development of Recovery Plan
w The organization should device a comprehensive w Identify, prioritize, and sequence the tasks that need to
disaster recovery plan. be performed during recovery, such as setting up
servers, arranging for power and Internet connections,
w A formal risk assessment should be undertaken in order installing systems software, installing application
to determine the requirements for the disaster recovery software, and restoring data from backup tapes;
plan.
w Identify roles and responsibilities, document who does
w The disaster recovery plan should be tested at regular what, how, and when;
intervals to ensure that it can be implemented in crisis
situations and that the management and staff know how w Identify the resource required for recovery plan such as
it is to be executed. location, power requirements, server requirements, and
human resources;
w The disaster recovery plan should encompass all
essential and critical business activities. w Prepare the disaster recovery procedure manual.

w The disaster recovery plan is to be kept up to date. Phase 3: Testing of Plan


The concluding step is to test the recovery plan to verify
that it is appropriate and workable. For multifaceted
w All staff must be made aware of the disaster recovery
systems, active testing may go through several iterations,
plan and their own roles within. as errors and omissions in the disaster recovery
procedures are discovered and corrected. Testing must
w The key persons to be contacted during the disaster be repeated at least once a year to keep the procedures
should be identified. current.

Overall Approach to DRP Phase 4: Documentation of the Plan


The overall approach to Disaster Recovery Planning The documentation needs to include the logical and
(DRP) is as follows: physical configuration of all the servers, network routers,
switches and individual desktop configurations. Write
down any patches that have been applied to the server
w Strategic level commitment secured and the applications each server runs. Create images of
w Kick off the management process each type of workstation and store them away. Also, make
w Classify the threats and risks sure the name and contact information for each person
w Manage the risks as part of risk management responsible for supporting your network devices is
w Business impact analysis documented and readily accessible.
w Develop strategies
w Test, identify and maintain the plan Also, document the backup process and how data and
w Maintain a crisis management team configurations are to be restored. Write down the
frequency of backups, how they are performed and where
tape cartridges will be stored. Review how you get tapes
Phased Approach to Disaster Recovery to remote sites. Also determine how long it will take you to
Plan as developed by IBM get tapes back in the event of a failure. At some point, in
The following is the Phased Approach to IT disaster a relaxed business period, test the backup and recovery
recovery planning recommended by IBM: process.

September-December 2007 The Pakistan Accountant 38


Information Technology

Store the disaster recovery plan in a number of onsite, as commonly known as "Vendor-Subscription." This involves
well as off-site locations. But most importantly, keep your an agreement with a recovery services vendor for the
documentation up-to-date. guaranteed delivery of computer hardware to the
customer's alternate recovery site. This strategy is
Disaster Recovery Strategies generally less expensive than other two.
The following are four universal strategies to disaster
recovery: 4. Acquisition
The least receptive strategy involves purchasing the
1. Duplicate systems required computer hardware, data, and communications
The rapid recovery strategy calls for a duplicate set of equipment at the time of the disaster. This strategy has
computer hardware, data, communications equipment, the lowest operating costs, as there is virtually no cost
power supply, and an Internet unless a disaster happens. Costs of
connection, ready for acquiring equipment at the time of a
commencement at an alternate site. If a disaster hits disaster are potentially the most
With this strategy, recovery times expensive, as a premium price may
are measured in minutes or hours. the production be paid to get quick delivery.
This is also called “mirror site”. Recovery times for this strategy are
site, the Duplicate usually measured in weeks.
It is basically a redundant setup
elsewhere, running in parallel to the system enters in Maintenance of Disaster
computer systems in production. All
transactions are automatically and continues the Recovery Plan
recorded by the production systems The increase in technological based
and the Duplicate system. operation. A mirror processes over the recent past
years has significantly increased
If a disaster hits the production site,
the Duplicate system enters in and
site is the most the level of dependency upon the
availability of systems and
continues the operation. A mirror
site is the most expensive solution
expensive solution information for the business to
function properly. These changes
are likely to continue, and it is likely
but provides the best disaster
protection; however, not many
but provides the that the only certainty is that the
pace of change will continue to
organizations can pay for or need
this strategy.
best disaster increase.

2. Hot-site service
protection; It is necessary for the disaster
recovery plan to keep pace with
A hot-site is an agreement with a
recovery services provider to
however, not these changes in order for it to be of
use in the event of a disruptive
access a physical location equipped
with the necessary hardware. This
many emergency.
strategy has comparatively high
continuing operating costs and the
organizations can To ensure this, the disaster
recovery plan update process must
shorter the guaranteed time period,
the more costly the payment.
pay for or need be properly planned, executed and
controlled. Further, whenever
Typically, hot-site service provides
recovery within a few hours to a few
this strategy. changes are made to the plan they
are to be fully tested and
days. There are more advanced appropriate amendments should be
offerings that range from having a shared room that you made to the training materials.
get access to on a first come first served basis to a room
that is dedicated solely to your company. The drawback of It is worth noting that Disaster Recovery Planning is not
the first come first serve solution is that if more than one only necessary for IT applications but it should be
company has a calamity at the same time, you may not developed for every critical business process.
have a facility to go to. On the other hand dedicated
facility will be more expensive but it will be yours to use
when required. Hot-site service is designed to bridge the Make sure that the Plan Can
organization for several weeks while a replacement data Run On Its Own
centre is built. It may happen that when disaster strikes, the staff who
wrote the recovery plan may not be available to execute
3. The vendor subscription it. You have to make sure that your Disaster Recovery
Another disaster recovery strategy is a subscription for Plan will work with or without the internal key people who
surefire shipment of servers and other critical equipment - wrote it.

September-December 2007 The Pakistan Accountant 39

Você também pode gostar