Example Business Continuity Plan
Based upon DS4.2 from COBIT (Control Objectives for Information Technology)
Prepared by: Micheal Axelsen FCPA[1]
Director, Applied Insight Pty Ltd
Provided as is, without warranty, for businesses to consider as a very early starting point in the preparation of a business continuity plan. This work is based upon material delivered to University business students.
Question One: Research Issue – Personal Data Protection
Assume a fire has destroyed your bedroom. Identify the items in your room that would be irreplaceable if this scenario eventuated. Draw up a business continuity plan for your bedroom and yourself.
Identify what you would need to do to ensure that irreplaceable items are better protected in the future. Identify the steps you would need to take immediately after the fire to recover from this disaster.
Worked Solution
Note that in COBIT 4.1, regarding the IT aspects we would need to identify an IT continuity plan. Firstly, we need to understand our business requirements – what our key business functions and processes are (DS4.2).
So, the business continuity plan draws upon our risk management framework (for argument’s sake, AS/NZS 4360:2004):
- Identify key business functions and processes.
- Identify ‘major’ disruption by reference to risk appetite
Consider what the definitions of economic loss might be that are insignificant, minor, moderate, major, or catastrophic (e.g. catastrophic might be $1,000,000 whilst insignificant might be $500). - Identify potential business impacts
- What actions can be taken to address requirements for:
- Resilience (reduce likelihood or consequence of the risk)
- Alternative processing (work-arounds in the event access is denied)
- Recovery capability of critical IT services (recovery of critical IT services)
- Identify usage guidelines, roles and responsibilities, procedures, communication processes, and the testing approach
1
A rough approach might look like this:
Business Continuity Plan
Risk Appetite: The business has determined that it can withstand a $3,000 level of disruption.
Assumptions: Catastrophic events (e.g. fire, flood) would result in similar business impacts. Actions to reduce impact will work equally as well for low-impact events (e.g. localised flooding, loss of internet connection).
Note: Some things are deliberately missing – who can spot something?
Key business functions / Business impact if unavailable / Resilience / Actions / Procedures & ResponsibilitiesClient Acquisition:
- Marketing website material (two websites, and and supporting collateral
If content lost, would take months to re-create, if at all possible. / Host with reliable ISP with strong financial background (Yahoo)
Host on a common ISP platform. / Take XML download of posts/content monthly. Add to backup processes. / MSA
- Current marketing plan
Reputable provider with SLA (WebCentral)
Enables sync across devices and internet access. / None identified. / MSA
Service Delivery
- Methodologies and client outputs
Affects efficiency and effectiveness as these are all key to service delivery. / Store in a single place and protect that well (i.e. hard drive) and incorporate into backup processes. / Backup process:
- Use SyncBack for each laptop daily – files are stored in three places (PMD, Dell, HP).
- Daily backup from Dell to external USB using MS Backup & Sync (monthly resets to keep disk space low).
- Monthly backup of entire system to a third 500gb pocket media drive kept at separate office 5 km away.
- Precedents and models
Affects efficiency and effectiveness as these are all key to service delivery. / Store in a single place and protect that well (i.e. hard drive) and incorporate into backup processes. / See backup process / MSA
- Templates
Affects efficiency and effectiveness as these are all key to service delivery. / Store in a single place and protect that well (i.e. hard drive) and incorporate into backup processes. / See backup process / MSA
- Research Notes
Affects efficiency and effectiveness as these are all key to service delivery. / Store in a single place and protect that well (i.e. hard drive) and incorporate into backup processes.
Store research notes in Evernote software (paid subscription) – enables sync across devices and mobile access.
Maintained in three places (Dell, online, and HP Mini-Note). / None required – rely upon Evernote SLA. / MSA
Administrative Support
- MYOB Accounting System
- Access to email
Reputable provider with SLA (WebCentral) / None. / MSA
- Task list
Reputable provider with SLA (WebCentral)
Enables sync across devices and internet access with only an internet connection. / None. / MSA
- Mobile telephone
- VOIP phone
Divert VOIP phone to mobile in emergency using password details noted in Evernote. / MSA
- Accounting records (Paper)
- Bookmarks
- Critical passwords
Will be able to regain access with PC and internet connection. / None. / MSA
- Suncorp Token Key
IT Infrastructure
- Dell Laptop (15”) (approximately $3K)
Preferred Vendor: Dell / MSA
- HP Laptop Mini-Note 2133 (approximately $1K)
Preferred Vendor: HT / MSA
- HP Scanjet bubblejet printer
Order three year on-site warranty. / In event of loss, identify with insurance provider and order replacement.
Preferred Vendor: HT / MSA
- Pocketmedia Drive
Preferred Vendor: HT / MSA
- External USB HDD (WD)
Preferred Vendor: HT / MSA
- Broadband connection
Or just wifi surf someone else’s open wireless connection . / MSA
- CD Media (to reinstall software)
1
[1]Micheal may be contacted on 0412 526 375 or .