




版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
BusinesscontinuityandDisaster 业务连续性 ReasonsforMakingBCPPartoftheandBusiness BusinessContinuity The设备故障Utility火灾/ Fire/水 Naturaldisasters(earthquakes,snow/hail/ice,lightning,热
Heat/HumidityElectromagneticemanationsHostileactivityTechnology FromDataProErrors&omissionsFire,water,electricalDishonestemployees
Disgruntledemployees10%Outsiderthreats GoalofThegoalistoassisttheorganization/businesstocontinuefunctioningeventhoughnormaloperationsaredisruptedIncludesstepstoBeforea Duringa Aftera ReasonsforMakingBCPPartoftheandBusinessContinuity BusinessContinuity MakingBCPPartofthe andBusinesscontinuityshouldbeapartofthesecurityprogramandbusinessdecisionsasopposedtobeinganentitythatstandsoffinacornerbyitself. Whenproperlyintegratedwithchangemanagementprocesses,itstandsmuchbetterchanceofbeingcontinuallyupdatedandimprovedBusinesscontinuityisafoundationalpieceofaneffectivesecurityprogramandiscriticaltoensuringrelevanceintimeofneed. ReasonsforMakingBCPPartoftheandBusinessContinuity BusinessContinuity Business nningAmajorrequirementforanythingthathassuchfar-reachingramificationsbusiness 像BCP这样影响深远的事项,是主要的需求是管理层的支持Itiscriticalthatmanagementunderstandswhattherealthreatsareto theconsequencesofthosethreats,andthepotentiallossvaluesforeach没有管理层的支持,就不会Itisimportantthatmanagementsettheoverallgoalsof nning,andshouldhelpsettheprioritiesofwhatshouldbedealtwith管理层设定BCP的整体目标很重要 ReasonsforMakingBCPPartoftheandBusinessContinuity BusinessContinuity BusinessContinuityProjectRecoveryndesignandContinual ProjectScope nMarksthebeginningoftheBCPItentailscreatingthescopefor
意味着创建计划的范 BCPShouldbeformedandgiventheresponsibilitytocreate,implementandtest 应成立并给予职责来创建、实施和测试计informationsystemsandsecurity由来自高管、所有业务部门 人员和安全管理员的代表组成SeniorManagement’sIsultimateresponsibleforallfourphasesof 高管负最终责任businesscontinuitycoordinator BusinessContinuityProjectRecoveryndesignandContinual 2.2BIABIA(Business 是帮助业务部门了解中 对业务带来的影响影响可能是financial( suchastheinabilitytorespondtocustomer) BIA的三个主要目关键程度排序CriticalityEverycriticalbusinessunitprocessmustbeidentifiedandprioritizedandtheimpactadisruptiveeventmustbe中断时间估计DowntimeEstimatestheMTD umTolerableDowntimethatthebusinesscantoleratestillremaina 资源需求确认ResourceTheresourcerequirementsforthecriticalprocessesarealsoidentifiedatthistime,themosttime-sensitiveprocessesreceivingthemostresource BIA步Selectindividualstointerviewfordatagathering.访谈以收集信Createdata-gatheringtechniquessurveysquestionnairesqualitativeandtativeapproaches). Identify ’scriticalbusinessfunctions.识别关键业务职Identifytheresourcesthesefunctionsdependupon.识别职能依赖Calculatehowlongthesefunctionscansurvivewithoutthese 识别脆弱性Calculatetheriskforeachdifferentbusinessfunction.计算每项业务的风findingsandreportthemtomanagement.文档化并向管理层报 互相MostBCPsaredevelopedtocovertheenterpriseasawhole,insteadofdealingwithonlyportionsoftheorganization. nsneedtobecompatiblewiththeenterprisewidePreventive SARS为例的 上游
可能发生的情无法与机构继续合作终止合约
后备方建立机构内原料、件供货商
评估机构内原料的安(或减低库存)客户
0.2.1无法与机构继续合作终止0.3.1客户因sars导致 评估标准1低2中3高 1低20天以2中11203高110 低中高123低1123中2246高3369 Unix,NT服务器Database 员工终端和LAN&
PBXNT或Unix服务器
00BusinessContinuityProjectRecoveryndesignandContinual RecoveryBusinessProcessFacilitySupplyandTechnologyTheEnd-UserDataBackupRecoveryand BusinessProcessTheBCPteammustunderstandthefollowingaboutcriticalbusinessRequiredRequiredInputandoutputWorkflowRequiredtimeforThiswillallowtheteamtoidentifythreatsandthecontrolstoensuretheleastamountofprocessinterruption.这将允许团队识 RecoveryBusinessProcessFacilitySupplyandTechnologyTheEnd-UserDataBackupRecoveryand FacilityHotWarmColdredundant–rollinghot hotTertiarySites第三的,第三位的(backuptotheReciprocalAgreements FacilityHotSiteReadywithinhoursforoperation几小时内就可准备就Highlyavailable高度可Usuallyusedforshort-termsolutionsbutavailableforlongerstays通常用于短期解决Annualtestingavailable可每HotSiteLimitedonhardwareandsoftwarechoices有限的硬件和软件选WarmandColdSiteAvailableforlongertimeframesbecauseofthereducedcosts因减少了成本可用于长时Practicalforproprietaryhardwareorsoftwareuse对使用专有硬件和软件是实用WarmandColdSite Not yavailable不是立即能使101perational Resourcesforoperationsnot yavailable运营资源不是立即可获FacilityItisimportanttounderstandthatthedifferentsitetypeslistedhereareprovidedbyservicebureaus,meaninga paysamonthlysubscriptionfeetoanother forthisspaceandAhotsiteisasubscriptionservice.Aredundantsiteisasiteownedandmaintainedbythe ,meaningthedoesnotpayanyoneelsefortheAredundantsitemightbe“hot”innature,meaningitisreadyforproductionquickly,buttheCISSPexamdifferentiatesbetweenahotsite(subscriptionservice)andaredundantsite(ownedbythe RecoveryBusinessProcessFacilitySupplyandTechnologyTheEnd-UserDataBackupRecoveryand SupplyandTechnologyHardwareSoftwareHuman SupplyandTechnologyHardwareTheteamhasidentifiedtheequipmentrequiredtokeepthecriticalfunctionsupandrunning.Thismayincludeservers,userworkstations,routers,switches,tapeback-updevices,hubs,andmore.mustmakeadecisionbetweendependinguponthevendororpurchasingredundantsystemsandstoringthemasbackupsshouldidentifylegacydevices遗留下来又难以更新的老化的;过时commercialofftheshelfCOTS)现货商品/非专门设计的商identifythenecessary SupplyandTechnologySoftwaresoftware SupplyandTechnology ationmayneedtoincludeinformationonhowtoinstallimages,configureoperatingsystemsandservers,andproperlyinstallutilitiesandproprietarysoftware. ationcouldincludeacallingtree,whichoutlineswhoshouldbecontacted,inwhatorder,andwhoisresponsibleforngthecalling. ationmustalsocontaincontactinformationforspecificvendors,emergencyagencies,offsitefacilities,andanyotherentitythatmayneedtobecontactedinatimeofneed. SupplyandTechnologyHumanexecutive --ifsomeoneinaseniorexecutivepositionretires,leaves,oris“deputyrolesOften,largerorganizationsalsohavea indicatingthattwoormoreoftheseniorstaffcannotbeexposedtoaparticularriskatthesametime.Forexample,theCEOand cannottravelonthesame RecoveryBusinessProcessFacilitySupplyandTechnologyTheEnd-UserDataBackupRecoveryand TheEnd-UserThefirstissuepertainingtousersishowtheywillbenotifiedofthedisasterandwholthemwheretogoandAtreestructureofmanagerscanbedevelopedsothatonceadisasterhits,the thetopofthetreecallstwomanagers,andtheyinturncallthreemanagers,andsoonuntilallmanagersarenotified.Then,oneortwopeoplemustbeinchargeofcoordinatingtheissuespertainingtoThefolksinchargeofdirectingshouldbereadilyidentifiable—bywearinganhatandvest,forexample—andshouldbelocatedinareaswheretheycanbeseenbyTheBCPteamneedstoidentifyuserrequirements,suchaswhetheruserscanworkstand-alonePCsorneedtobeconnectedinanetworktofulfillspecificTheBCPteamalsoneedstoidentifyhowcurrentautomatedtaskscanbecarriedmanuallyif esnecessary.Ifthenetworkisgoingtobedownfor12hours,t0:1ecessary RecoveryBusinessProcessFacilitySupplyandTechnologyTheEnd-UserDataBackupRecoveryand DataBackupfulldifferentialincrementalElectronicBackupChoosingaSoftware
Full
事务冗余(transactionElectronicBackupElectronicvaulting电子备份传送Referstothetransferofbackupdatatoanoff-sitelocation.Thisisprimarilyaprocessof thedatathroughcommunicationslinestoaserveratan 站 ElectronicBackupRemote 日志Rmunicationlineisusedtotransmitlivedataasit把日志或者处理记录传 站 //
RecoveryBusinessProcessFacilitySupplyandTechnologyTheEnd-UserDataBackupRecoveryand
isanewtypeofcoveragethatinsureslossescausedbydenial-of-serviceattacks,malwaredamages,hackers,electronictheft,privacy-relatedlawsuits,andmore.businessinterruptionif isoutofbusinessforacertainlengthoftime, willpayforspecifiedexpensesandlostaccountsreceivableinsuranceIfa cannotcollectonitsaccountsreceivableforonereasonoranother,thistypeofcoveragecoverspartorallofthelossesand RecoveryBusinessProcessFacilitySupplyandTechnologyTheEnd-UserDataBackupRecoveryand RecoveryandThefollowingaresomeexamplesofteamsthat maytoconstruct一个公司可能需要创建以下团队Damageassessment 损失评•Legal•Mediarelations•Networkrecovery•Relocation•Restoration•Salvage•Security munications
法务通信 BusinessContinuityProjectRecoveryndesignandContinual ndesignand Goalsfor nsThegeneralstructureofabusiness DifferentTypesof ndesignand Goalsfor ResponsibilityPrioritiesImplementationandtesting ndesignandThegeneralstructureofabusiness
ndesignandD
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 出血的护理措施
- 超市员工保密协议书
- 驿站转让违约协议书
- 餐厅经营股东协议书
- 铁路应聘就业协议书
- 兄弟俩共同分家协议书
- 餐饮项目外包协议书
- 道路合作施工协议书
- 餐厅物业转让协议书
- 裁员赔偿保密协议书
- 大学写作智慧树知到期末考试答案章节答案2024年丽水学院
- QBT 2530-2001 木制柜行业标准
- 卫生监督乡村医生培训课件
- 医院保安服务项目实施方案
- 《槟榔的危害》课件
- 高考前家长会课件
- 外阴及阴道炎症护理课件
- 2024年中国智慧港口行业市场全景评估及未来投资趋势预测报告(智研咨询)
- 围产期奶牛的饲养管理(内训)
- 2024年江苏武进经济发展集团招聘笔试参考题库含答案解析
- 音视频系统培训资料-(内部)
评论
0/150
提交评论