|
Home::Data Recovery
Business Continuity and Disaster Recovery - Risk Analysis and Control
Author : Robert Mahood
In the risk evaluation phase, there are a number of key areas that must be covered. One of the most important is to understand probable threats. In an ideal world, which most of us have noticed does not exist, we would identify and protect ourselves against all threats to ensure that our business continues to survive. Obviously, we are constrained by other factors such as budgets, time and priorities and need to apply cost benefit analysis to ensure we are protecting the most critical business functions. A second important step is to identify all probable threats and prioritize them. Threats, typically, can be classified in several ways such as internal/external, man-made/natural, primary/secondary, accidental/intentional, controllable/not controllable, warning/no warning, frequency, duration, speed of onset etc. While classifying threats is helpful in terms of understanding their characteristics and potential controls, grouping and understanding by business impact is also important. Obviously, the same impact can result from a number of different threats. Identifying mission critical business processes and systems is another fundamental building block of the business continuity plan. After your critical business processes and systems and probable threats are established, the next step is to identify vulnerabilities and loss potential. This requires an extensive scan of the organization to identify vulnerabilities and then analysis to understand those vulnerabilities which would have the greatest impact on your critical business processes and the organization. This starts to clarify and quantify potential losses, which helps to establish priorities. Following the identification of the most probable threats and vulnerabilities, an analysis of existing controls is needed. This spans physical security as well as people, processes, data, communications and asset protection. Some controls such as physical security and data backup are obvious. Other controls required are often less obvious, but they can be identified through the risk evaluation process. Once the key building blocks of critical business functions, most probable threats, vulnerabilities and controls are identified, the next stage is to develop an understanding of the probability of threats factored by the severity or impact of the threats. This leads to the business impact analysis phase which establishes priorities for protection. The goal is to minimize threats, impacts and downtime and to mitigate any losses. Fundamentally, the goal is to protect your people, protect your data, protect your vital communications, protect your assets and to protect your brand and reputation. Overall, of course, the goal is to ensure your business continues to operate and to do it in a cost-effective way meeting standards of reasonable and prudent judgment. About The Author Robert Mahood has significant technology and management experience in data communications, internet, storage, disaster recovery and data recovery. He is currently the president of Midwest Data Recovery. www.midwestdatarecovery.com bmahood@midwestdatarecovery.com, 312 907 2100 or 866 786 2595 Spam emails More free articles Related articles
|
More related feeds |
AT&T Study: Nearly One in Five North Carolina Businesses Does Not ... AT&T offers a wide array of business continuity services, encompassing disaster planning, risk management, recovery preparedness and communications readiness. AT&T Business Continuity Services are comprehensive, providing enterprises ...Business Continuity and Disaster Recovery - Risk A Business Continuity and Disaster Recovery - Risk Analysis and Control. by: Robert Mahood. In the risk evaluation phase, there are a number of key areas that must be covered. One of the most important is to understand probable threats. ... Business Continuity and Disaster Recovery - Risk Analysis and Control Identifying mission critical business processes and systems is another fundamental building block of the business continuity plan. After your critical business processes and systems and probable threats are established, the next step is ... Continuity and Disaster Recovery in Business - Risk Analysis and ... Identification of your mission critical business systems and processes would be another essential building block of planning business continuity. Once the important business systems and process as well as the possible threats have been ... Business Continuity and Disaster Recovery - Busine Organizations often think in terms of disaster recovery. Business continuity and the business impact analysis is more focused on keeping the business up and running and less focused on recovery after a disaster. ... Business Continuity and Disaster Recovery - Risk Analysis and Control In the risk evaluation phase, there are a number of key areas that must be covered. One of the most important is to understand probable threats. In an ideal world, which most of us have noticed does not exist, we would identify and ... Networking reflective journal week 1 (sem2) Large organisations may develop separate disaster recovery plans for different subsystems of their IT services. Conduct a risk analysis The business process of the organisation will be identified at this stage with input from users, ... Risk Analysis And Control: Vital To Records Protection ... The purpose of risk control is to safeguard vital records. Where vital records protection is part of a broader business continuity and disaster recovery plan, risk control measures may also safeguard facilities, computer hardware and ... Up-to-Date Earning the Certs the Market Demands The CISSP is divided into the following domains: access control, application security, business-continuity and disaster-recovery planning, cryptography, information security and risk management, legal, regulations, compliance and ... Business Continuity and Disaster Recovery - Risk Analysis and Control In the venture assessment phase, there are a sort of key areas that staleness be covered. One of the most essential is to see plausible threats. In an saint world, which most of us hit detected does not exist, we would refer and protect ...
|
|
|