Àâòîðèçàöèÿ
Ïîèñê ïî óêàçàòåëÿì
Butterworth-Heinemann — Business Continuity and Disaster Recovery Planning for IT Professionals
Îáñóäèòå êíèãó íà íàó÷íîì ôîðóìå
Íàøëè îïå÷àòêó? Âûäåëèòå åå ìûøêîé è íàæìèòå Ctrl+Enter
Íàçâàíèå: Business Continuity and Disaster Recovery Planning for IT Professionals
Àâòîð: Butterworth-Heinemann
Àííîòàöèÿ: Powerful Earthquake Triggers Tsunami in Pacific. Hurricane Katrina Makes Landfall in the Gulf Coast. Avalanche Buries Highway in Denver. Tornado Touches Down in Georgia. These headlines not only have caught the attention of people around the world, they have had a significant effect on IT professionals as well.
As technology continues to become more integral to corporate operations at every level of the organization, the job of IT has expanded to become almost all-encompassing. These days, it's difficult to find corners of a company that technology does not touch. As a result, the need to plan for potential disruptions to technology services has increased exponentially.
That is what Business Continuity Planning (BCP) is: a methodology used to create a plan for how an organization will recover after a disaster of various types. It takes into account both security and corporate risk management tatics.
There is a lot of movement around this initiative in the industry: the British Standards Institute is releasing a new standard for BCP this year. Trade shows are popping up covering the topic.
* Complete coverage of the 3 categories of disaster: natural hazards, human-caused hazards, and accidental and technical hazards.
* Only published source of information on the new BCI standards and government requirements.
* Up dated information on recovery from cyber attacks, rioting, protests, product tampering, bombs, explosions, and terrorism.
ßçûê:
Ðóáðèêà: Ðàçíîå /
Ñòàòóñ ïðåäìåòíîãî óêàçàòåëÿ: Ãîòîâ óêàçàòåëü ñ íîìåðàìè ñòðàíèö
ed2k: ed2k stats
Ãîä èçäàíèÿ: 2007
Êîëè÷åñòâî ñòðàíèö: 456
Äîáàâëåíà â êàòàëîã: 11.12.2007
Îïåðàöèè: Ïîëîæèòü íà ïîëêó |
Ñêîïèðîâàòü ññûëêó äëÿ ôîðóìà | Ñêîïèðîâàòü ID
Ïðåäìåòíûé óêàçàòåëü
Acceptance, risk 263—264
Access, managing data 30—31
Accidents and technological hazards 22—23
Accounts receivable, and business disruptions 127
Activation phase, BC/DR plan 295—296
Administration and mitigation strategies 281
Administration, support team, BC/DR 305
Analysis See business impact analysis (BIA)
Appendices, BC/DR plan 322—324 329
Assessments of BC/DR training 363—364
Assessments, impact 257
Assessments, risk See risk assessment
Assessments, vulnerability See vulnerability assessment
Assets and risk transference 213
Assets, reviewing critical system priorities 280
Auditing and testing and training activities 360—361
Auditing BC/DR plans 113—114 393—394 399—400 405
Auditing, performing security audits 381—384
Availability, confidentiality, and integrity (CIA) 174
Avian flu, and risk assessment 165—168
Avoidance, risk 264—265
backing up data 64 280—287 290
BC/DR (business continuity/disaster recovery) planning See also BC/DR plans BC/DR
BC/DR (business continuity/disaster recovery) planning, cost of planning vs. failure 11—17
BC/DR (business continuity/disaster recovery) planning, executive support for 23
BC/DR (business continuity/disaster recovery) planning, introduction to 2—5
BC/DR (business continuity/disaster recovery) planning, people, process, and technology of 5—10
BC/DR plans, business continuity, maintenance and review phases 301—302
BC/DR plans, business disruption phases 295—298
BC/DR plans, change management 392—396 404—405
BC/DR plans, communication plans 317—319
BC/DR plans, crisis communications 332—336
BC/DR plans, defining tasks, assigning resources 311—316 327
BC/DR plans, developing, maintaining 31—35
BC/DR plans, distribution, appendices 322—324
BC/DR plans, making business case for 40—42 119—120 121
BC/DR plans, plan components 64—96
BC/DR plans, project to create See BC/DR projects
BC/DR plans, training and testing 367—381 384—388
BC/DR plans, triggers, recovery phases 298—301
BC/DR projects, clearly defined objectives, requirements, scope 60—62
BC/DR projects, close out 401—402 406
BC/DR projects, introduction to 54—55
BC/DR projects, key contributors, responsibilities 96—105 117—118
BC/DR projects, plan components 117
BC/DR projects, project definition 66 106—111 115 118
BC/DR projects, project manager 59
BC/DR projects, project plan 112—114
BC/DR projects, project team, organization 75—89 329—330
BC/DR projects, success criteria 68—69 115
BC/DR projects, success, elements of 55—64 116
BC/DR projects, user involvement 58—59
bcp See business continuity planning
Biological hazards 172—173
Bird flu 165—168
Blum, Justin 180
Budget, BC/DR projects 65—66 80—84
Buildings and risk mitigation strategies 278
Buildings in floodplains 154
Buildings, -specific failures 178—179
Buildings, emergency plans for 357—358
Buildings, fire, and risk assessment 152—153
Buildings, fireproofing costs 140
Business continuity and disaster recovery (BC/DR) See also BC/DR plans BC/DR
Business continuity and disaster recovery (BC/DR), phases of 295—302 326
Business continuity and disaster recovery (BC/DR), planning See business continuity planning
Business continuity plan 75
Business continuity planning (BCP) and disaster planning 12—15
Business continuity planning (BCP), basics of 31—36
Business continuity planning (BCP), described 3
Business continuity, activities 351—352 354 356
Business continuity, described 37
Business continuity, introduction to 2—5
Business continuity, training 361—375
Business disruptions, impacts of 236—238
Business disruptions, phases, and BC/DR plan 295—297
Business impact analysis (BIA) and risk assessment 175—176
Business impact analysis (BIA) in vulnerability assessment 201
Business impact analysis (BIA), data points 238—243 257
Business impact analysis (BIA), described 34 112 258—259
Business impact analysis (BIA), determining impacts 236—238 257
Business impact analysis (BIA), gathering data for 231—236 256—257
Business impact analysis (BIA), identifying business functions 226—231 256
Business impact analysis (BIA), impact criticality 216—225 255—256
Business impact analysis (BIA), inputs and outputs 224
Business impact analysis (BIA), introduction to 210 254
Business impact analysis (BIA), overview of 211—215 254—255
Business impact analysis (BIA), preparing report 252—253
Business impact analysis (BIA), small business example 245—251
Business, components of 5—10 37—38
Business, continuity See business continuity
Business, financial aspects of disruptions 124—130
Business, fraud, theft 27—30
Business, functions, BIA data points 238—243
Business, functions, identifying 226—231 256
Business, requirements, BC/DR projects 107—109
California, earthquakes in 159—160
California, notice of security breach laws 46—47
Case studies, crisis communications 331—336
Case studies, financial impacts of disasters and disruptions 123—131
Case studies, legal obligations regarding data security 43—50
Cash flow, business disruption impacts 125 128—129
CDC (U.S.Centers for Disease Control) 165
Change control, change management, BC/DR change management 392—396
Change control, change management, BC/DR plans 321—322 328 397—398 404—405
Change control, change management, BC/DR projects 88 93—94
Change notifications 396
Checklists for key processes 372
Checklists, emergency response activation 346—347
Checklists, threat 182—184
Chemical, fire suppression systems 152—153
Chemical, hazards and risk assessment 172—173
ChoicePoint data security incident 44—45 47 124
CIRP (cyber incident response plan) 77
CIRT (computer incident response team) 362—363
Clarke, Richard A. 180
Close out, BC/DR projects 94—95 401—402 406
Coca Cola 104—105
Cold sites, IT recovery 283
Cold weather related hazards 19
Communication, BC/DR plans 317—319 327—328
Communication, BC/DR projects 89—90 97
Communication, during crisis 344
Compliance, and critical process assessment 228
Computer Emergency Response Team (CERT) 350—351 353—354
Computer incident response team (CIRT) 347—351 353—354 362—363
Confidentiality, integrity, and availability (CIA) 174—175
Conn, Deanna 43 101
Constraints, BC/DR projects 68
Contact information, BC/DR 309—311
Contamination of food, water 181—182
Continuity of operations plan 76
Continuity, business See business continuity
Continuous availability 4
Contractual arrangements for BC/DR services 312—316
Costs of BC/DR planning 11—15 378—379
Costs of continuous availability 4
Costs, BC/DR project budget 65—66
Costs, BC/DR project estimates 70
Costs, financial aspects of business disruptions 124—130
Costs, risk mitigation strategies 263 270—271
Credibility, and business disruptions 236 237
Crime, cyber 176—178
Crisis communication plans 76—77 332—336
Crisis management team (CMT) 341 343—346 355
Crisis management, communication teams 297—298 303
Critical data, mitigation strategy for 274—278
Critical path, BC/DR projects 91—92
Customer Relations Management (CRM) systems 88—89 244
Customer service, and mitigation strategies 281
Customers, DC/DR communication plans 318
cyber crime 176—178
Cyber incident response plan (CIRP) 77
Cyber threats 174—179
Cyclones 162—164
Damage assessment team 297 304
Data security, breaches, questions about 51—52
Data security, ChoicePoint incident 44—45
Data security, federal laws regarding 48—50
Data security, state laws regarding 45—48
data, backing up 64
Data, critical, mitigation strategy for 279
Data, eletronic data threats 23—31
Data, gathering for business impact analysis 231—236
Data, loss of sensitive, legal liability for 41
Data, loss, and risk management 178
Data, managing access 30—31
Data, points, business impact analysis 238—243
Data, random reviews 28
Data, searches 187—188
Data, security See data security
Database administrator (DBA) 214
Deffeyes, Kenneth 181
Definition, project plan 66 106—111
Dependencies, IT, and BIA data points 238—243
Design, reliable system 32
Desktop solutions, IT recovery 285—286
Developing, BC/DR training programs 364—365
Developing, risk mitigation strategies 273—278
Development, and research, critical processes, functions 230
Diagrams, risk 188—190
Disaster recovery, described 37
Disaster recovery, emergency response and 346—347
Disaster recovery, introduction to 2—5
Disaster recovery, phases of 295—302
Disaster recovery, plans 76
Disaster recovery, training 361—375
Disasters See also specific disaster
Disasters, costs of 11
Disasters, phases, and BC/DR plan 295—297
Disasters, types of 17—31 38—39
Disk systems, IT recovery 284
Disputes, labor 170
Downstream losses 212—213
Drought, and risk assessment 158—159
E-mail, and mitigation strategies 280
Earnest, Debbie 379
Earnings, financial aspects of business disruptions 129—130
Earthquakes and risk assessment 138 159—162
Earthquakes, readiness kit 206
Electrical storms 156—158
Electronic data threats 23—31
Electronic vaulting, IT recovery 285
Emergency preparation in BC/DR plan 113
Emergency Response Teams (ERTs) 297 341—343 361—362
Emergency response, recovery, business continuity phase 351—352
Emergency response, recovery, crisis management team 343—346
Emergency response, recovery, disaster recovery 346—347
Emergency response, recovery, IT recovery tasks 347—351
Emergency response, recovery, overview of emergency management 338—339
Emergency response, recovery, plans 339—343 354—355
employees See also people
Employees and business disruptions 236
Employees and business impact analysis 215
Employees, BC/DR key personnel 302—311
Employees, DC/DR communication plans 317—319
Employees, physical/personnel team 306—307
Encrypted data, notice of security breach laws 46 51 52
Environmental impacts of business disruptions 237
Epidemics 165—168
Equipment and mitigation strategies 281
Equipment, procurement team 307
ERTs (emergency response teams) 297 341—343 361—362
Escalation procedures, BC/DR project 87
Estimates, making for BC/DR projects 70
Evaluating BC/DR training 370
event logs 319—320 325—326 328
Executive support for BC/DR planning 23
Executive support for BC/DR project 55—58
Executives as BC/DR plan stakeholders 78—79
Exercises, BC/DR training 373
Expense insurance 213
Facilities and mitigation strategies 281—282
Facilities, assessing critical processes, functions 226—227
FACTA (Fair and Accurate Credit Transactions Act of 2003) 48—49
Fair Credit Reporting Act (FCRA) 44—45
FEMA (Federal Emergency Management Agency) 338 19
Field exercises, BC/DR training 374
Finance department and BC/DR projects 100
Finance department and Crisis Management Teams (CMTs) 345—346
Finance department, assessing critical processes, functions 227
Financial aspects of business disruptions 236
Fire suppression systems 138
Fire, and risk assessment 151—153
Fireproof buildings 140
Fires, drought and 158—159
Fires, human-caused 168—179
Float, and critical path 91
Floods, and risk assessment 153—154
Food contamination and risk assessment 181—182
Fraud 27
FTC’s suit against ChoicePoint 44—45
Functional requirements, BC/DR projects 109—110
Geologic hazards 20
Gramm — Leach — Bliley Act (GLBA) 25
H.R. bill 4127 (proposed), data security 49
Hardening systems 382
Hash, John S. 139
Hazards, chemical, biological 172—173
Hazards, human-caused 20—22
Hazards, natural 18—20
Heaviside, Katherine 13
HIPAA (Health Insurance Portability and Accountability Act) 25—26
Hoenig, Patty 331
Homicide, workplace 170—171
Hot sites, IT recovery 283
Hubbert, M.King 181
Human Resources (HR) and BC/DR projects 99
Human Resources (HR) and business disruptions 237
Human Resources (HR) and business impact analysis 215
Human Resources (HR) and Crisis Management Teams (CMTs) 344—345
Human Resources (HR), assessing critical processes, functions 227—228
Human Resources (HR), BC/DR team 306
Human Resources (HR), processes, flowchart 8—9
Human threats, risk management component 168—179
Human-caused hazards 20—22
Hurricane Katrina 18—19 163 341
Hurricanes 162—164
Identifying business functions 226—231 256
Impact analysis and risk assessment 139—140
Impact analysis, business See business impact analysis
impact assessment 140
Impact criticality, criticality categories 216—218
Impact criticality, recovery time requirements 218—225
Implementation of BC/DR projects 92—94
Important business processes, functions 217—218
Influenza 165—168
Information technology See IT
Infrastructure and risk mitigation strategies 278
Infrastructure in risk assessment 141—143
Infrastructure in vulnerability assessment 197—198
Infrastructure, BC/DR project 84—85
Infrastructure, critical, mitigation strategy for 279—280
Insider fraud, theft 27—30
Inspections, spot 28
Insurance and Crisis Management Teams (CMTs) 345
Insurance, expense 213
Insurance, key man 214
Integrity, confidentiality, and availability (CIA) 174—175
Interdependencies and business impact analysis 212
Ðåêëàìà