Disaster Recovery Plan Template Business Continuity

DRP BCP Template

ISO 27000, SOX, PCI-DSS & HIPAA Compliant

The Standard for Disaster Recovery and Business Continuity - Over 3,000 Companies World Wide have chosen this DRP/BCP Template

Order DRP BCPSample DRP BCPDRP Customers     

This Disaster Recovery Plan (DRP) can be used as a Disaster Planning template for any size of enterprise. The Disaster Recovery template and supporting material have been updated to be Sarbanes-Oxley and HIPAA compliant. The Disaster Planning Template comes as both a Word document and a static fully indexed PDF document. The DRP/BCP Template includes:

  • Disaster Recovery Plan and Business Continuity Template (WORD and PDF)
  • Business and IT Impact Analysis Questionnaire
  • Work Plan
  • Disaster Recovery / Business Continuity Audit Program
  • Pandemic Planning Checklist

MTO Disaster Timeline

Preparation for Disaster Recovery / Business Continuity in light of SOX has two primary parts. The first is putting systems in place to completely protect all financial and other data required to meet the reporting regulations and to archive the data to meet future requests for clarification of those reports. The second is to clearly and expressly document all these procedures so that in the event of a SOX audit, the auditors clearly see that the DRP exists and will appropriately protect the data.

Order DRP BCPSample DRP BCP     

New are (Version History):

  • Backup & Backup Retention Policy
  • Disaster Recovery Audit Program
  • Compliance with the ISO 27000 Series Standards (formerly ISO 17799 now ISO 27001 & ISO 27002), Sarbanes-Oxley, PCI-DSS, and HIPAA
  • Web Site Disaster Recovery Planning Form
  • Project Status Report Form
  • Personnel Location Report
  • Department Disaster Recovery Activation Workbook
    • Quick Reference Guide
    • Team Alert List (Form)
    • DRP Team Responsibilities
    • DRP Team Checklist
    • Critical Function(s) Definition
    • Normal Business Hour Response Procedures
    • After Hours Response Procedures
    • DRP Location(s) Definition
    • DRP Recovery Procedures
    • Notification Procedures
    • Notification Call List (Form)
  • Updated Business and IT Impact Analysis Questionnaire
  • Vendor Disaster Recovery Questionnaire
  • Vendor Phone List Form Updated
  • Key Customer Notification Form
  • Critical Resources to be Retrieved Form
  • Business Continuity Off-Site Materials Form
  • Business Continuity Audit Program

Enterprise & World License

Disaster Recovery - Business Continuity Template
Table of Contents

1.0   Plan Introduction

  • Mission and Objectives
  • Disaster Recovery / Business Continuity Scope
  • Authorization
  • Responsibility
  • Key Plan Assumptions
  • Disaster Definition
  • Metrics
  • Disaster Recovery / Business Continuity and Security Basics

2.0   Business Impact Analysis

  • Scope
  • Objectives
  • Critical Time Frame
  • Application System Impact Statements
  • Information Reporting
  • Best Data Practices
  • Summary

3.0    Backup Strategy

  • Site Strategy
  • Data Capture and Backups
  • Backup and Backup Retention Policy
  • Communication Strategy and Policy
  • ENTERPRISE Data Center Systems
  • Departmental File Servers
  • Wireless Network File Servers
  • Data at Outsourced Sites (including ISP’s)
  • Branch Offices (Remote Offices & Retail Locations)
  • Desktop Workstations (In Office)
  • Desktop Workstations (Off site including at home users)
  • Laptops
  • PDA’s and Smartphones

4.0   Recovery Strategy

  • Approach
  • Escalation Plans
  • Decision Points

5.0   Disaster Recovery Organization

  • Recovery Team Organization Chart
  • Disaster Recovery Team
  • Recovery Team Responsibilities

6.0  Disaster Recovery Emergency Procedures

  • General
  • Recovery Management
  • Damage Assessment and Salvage
  • Physical Security
  • Administration
  • Hardware Installation
  • Systems, Applications & Network Software
  • Communications
  • Operations

7.0  Plan Administration

  • Disaster Recovery Manager
  • Distribution of the Disaster Recovery Plan
  • Maintenance of the Business Impact Analysis
  • Training of the Disaster Recovery Team
  • Testing of the Disaster Recovery Plan
  • Evaluation of the Disaster Recovery Plan Tests
  • Maintenance of the Disaster Recovery Plan

8.0   Appendix

  • Plan Distribution
  • ENTERPRISE Sales Offices
  • Disaster Recovery Team Call List
  • Vendor Phone/Address List
  • Off-Site Inventory
  • Personnel Location Form
  • Hardware/Software Inventory
  • People Interviewed
  • Preventative Measures
  • Sample Application Systems Impact Statement
  • JOB Descriptions
    • Disaster Recovery Manager
    •  Manager Disaster Recovery and Business
    • Continuity
    • Pandemic Coordinator
  • Application Inventory and Business Impact Analysis Questionnaire
  • Key Customer Notification List
  • Resources Required for Business Continuity
  • Critical Resources to Be Retrieved
  • Business Continuity Off-Site Materials
  • Work Plan
  • Audit Disaster Recovery Plan Process
  • Vendor Disaster Recovery Planning Questionnaire
  • Departmental DRP and BCP Activation Workbook
  • Web Site Disaster Recovery Planning Form
  • General Distribution Information
  • Business Pandemic Planning Checklist

Order DRP

Premium Edition Disaster Business Continuity Template

The premium edition contains 15 full job descriptions. They are:

  • Chief Information Officer
  • Chief Security Officer
  • Chief Compliance Officer
  • VP Strategy and Architecture
  • Director Disaster Recovery and Business Continuity
  • Director e-Commerce
  • Manager Disaster Recovery
  • Manager Disaster Recovery and Business Continuity
  • Disaster Recovery Coordinator
  • Disaster Recovery - Special Projects Supervisor
  • Manager Database
  • Capacity Planning Supervisor
  • Manager Media Library Support
  • Manager Site Management
  • Pandemic Coordinator

Order DRPSample DRP

DRP BCP Template General Description

The DRP template is over 200 pages and includes everything needed to customize the Disaster Recovery Plan to fit your specific requirement.  The electronic document includes proven written text and examples for the following major sections of a disaster recovery plan:

  • Plan Introduction
  • Business Impact Analysis - including a sample impact matrix
  • DRP Organization Responsibilities pre and post disaster - DRP / BCP checklist
  • Backup Strategy for Data Centers, Departmental File Servers, Wireless Network servers, Data at Outsourced Sites, Desktops (In office and "at home"), Laptops and PDA's.
  • Recovery Strategy including approach, escalation plan process and decision points.
  • Disaster Recovery Procedures in a check list format
  • Plan Administration Process
  • Technical Appendix including definition of necessary phone numbers and contact points
  • Job Descriptions
    • Disaster Recovery Manager
    • Manager Disaster Recovery and Business Continuity
    • Pandemic Coordinator
  • Work Plan to modify and implement the template. Included is a list of deliverables for each task. (Risk Assessment and Vulnerability Assessment)
There is a extensive section that shows how a full test of the DRP can be conducted.  It includes

  • Disaster Recovery Manager Responsibilities
  • Distribution of the Disaster Recovery Plan
  • Maintenance of the Business Impact Analysis
  • Training of the Disaster Recovery Team
  • Testing of the Disaster Recovery Plan
  • Evaluation of the Disaster Recovery Plan Tests
  • Maintenance of the Disaster Recovery Plan

Click on the link below to get the DRP/BC sample pages now and make it part of your disaster recovery toolkit.

Order DRPSample DRP

Backup Matrix - Sample from Template

Backup Matrix

Order DRP BCPSample DRP BCP


Testimonials

Testimonial - Dave Baker - City of Hamilton -I have found the DRP template invaluable!

Testimonial - Bob Rifenbury -MCSE/CCNA Launch Testing Lab -The DRP Template saved me about 6 months of work!

Testimonial -  Kelly Keeler - Martin's Point Health Care -I have received and I began using the template immediately. IT IS GREAT! Made this process a snap for me. Cut my documentation time down from.  weeks to hours! This document has made, what began to be an overwhelming process turn into a snap!

Testimonial - Juan Stamos - Mexico City Corporation -We had a DRP in place, but needed a more user friendly structure.  The Disaster Recovery Template (Gold edition) has that structure.  It was very easy to quickly move our DRP into Janco's DRP Template -- a real added value.


This template is not for resale or re-distribution - Disaster Plan Template, Disaster Recovery Planning Template Disaster Recovery Template, Disaster Recovery

 

Order DRP BCPSample DRP BCP

 

 

 

 

Disaster Recovery / Business Continuity - DRP / BCP News




Security and DRP play a role in CIO Infrastructure Design

IT Infrastructure, Strategy, & Charter TemplateDesigning IT Infrastructure requires CIOs to consider the globalized world they are now in. It is necessary and valuable for CIOs to understand the fundamental trends that are pushing businesses to redesign their operations around this new reality.  Factors they need to consider are:

  • Security - With the growing importance of digital applications and data, the sources of threats to enterprise data have multiplied dramatically. Everything from natural disasters to criminals to corrupt sources within the company might try to steal or corrupt data. While businesses do everything that they can to stop these threats in the first place, they still must be prepared to recover from these threats as quickly as possible.
  • Business Continuity and Disaster Planning - As businesses have expanded the need for anytime, anywhere application access has become a requirement. At the same time, “follow the sun” (global 24/7) operations have shrinking maintenance windows and a need for applications to be running at all times. Delay or loss of data for any reason – system failure, natural disasters – has a domino-like effect across the entire organization, at any time of the day or night.
  • Flexibility - Most businesses now operate across international borders and CIOs must be able to respond to opportunities and challenges faster than ever before. CIOs are usually battling well-resourced organizations that may be based where the opportunity originated, or another globalizing company that is reaching out for new opportunities. In order to compete, a business has to be faster to deliver a product or service as good, or better, than that of potentially any other company in the world.
  • Simplicity - Increases in technology have typically led to increased complexity. While per unit costs of technology are always decreasing, in aggregate companies see an increase in cost. With the pressure on IT to act less as a cost center and more as a way to increase the profitability of business units, just adding more storage, more bandwidth, or additional technologies throughout the organization is no longer an acceptable approach to managing information technology. Successful CIOs are investing in numerous technologies including; continuous data protection, virtualization, and wireless connectivity.  They are trying slim down IT’s footprint while increasing their business’s competitive advantages. The CIO is typically in a difficult position, assessing where to try and cut costs while still moving forward with a plan to continually enhance IT services to the business.
- more info



Nature can distroy anything that man can make

Nothing man-made can withstand the forces of nature. In certain regions of the country, natural disasters are not a question of if, but of when. The main headquarters of many companies are located in North Carolina, right in the heart of Hurricane Alley. In addition, Southern California is earthquake and brush fire central.

 

Disaster PlanningSecurity PoliciesDRP Audit Program

 

They know a hurricane, earthquake, or brush fire is going to be coming along at some point; it is inevitable.  At the worst, you are looking at physical damage to facilities and systems, or flooding. At minimum, it will knock out power and your network circuit. Even if power and network stay up, just the fact that you do not have physical access to your system may prevent you from doing a crucial operational task.

- more info



How a CIO should chose a backup site

 Disater Plan Site SelectionDisasters cost money, interrupt business operations and may cause the enterprise or government agency to fail, which makes planning a business continuity issue. Disasters can interfere with or even terminate IT and communications services. It does not matter whether the disaster affects the enterprise, government or service provider. Floods, fire, volcanoes, earthquakes and other events can destroy a primary and backup site if they are too close together.

Telecom service providers can offer expert advice on where to locate a backup facility and should position themselves with CIOs to offer both consulting and services. After all, they have experience planning for their own primary and backup facilities, as well.

A CIO's selection of the backup site location will always have risks and liabilities attached to the decision. Adequate and reliable communications to the backup site and communications between the primary and backup sites are what most service providers can successfully offer to the CIO.

      

In choosing a backup site, CIO's must first determine how big a disaster plan for and budget for it. The level of disaster planning increases as you goes down the following list:

  • Building closed/evacuated
  • Loss of power
  • Loss of communications
  • Facility damaged/destroyed
  • Community disaster (10-to-30 mile range)
  • Regional disaster (30-to100 mile range)
- more info



Successful Disaster Planning and Business Continuity Planning Processes

DRP/BCP Security Templates

The success of most business depends on Information Technology. However, business and technology environments are becoming more complex. Being prepared to respond to non-typical events - both planned and unexpected - that threaten to disrupt essential business systems and processes, is a major corporate concern.

A recent survey found that disaster recovery planning is a priority for many organizations. Eighty-six percent of IT executives said they have a disaster recovery plan in place at their organization. While the economy has affected IT budgets overall, 43 percent of IT respondents indicated the economy has not affected their disaster recovery investment (including planning) - with another 33 percent, saying investment in disaster recovery has become more important.

Organizations cannot control whether or not they will be affected by a natural disaster, power outage or other unplanned incident, but they can work to help ensure their business is prepared to respond to and recover from these events with minimal impact. Disaster recovery planning is an organizational requirement that can help reduce risk and help companies effectively respond to situations that threaten to disrupt essential business processes.

Janco Associates has found that enterprises that are successful:

  • Focus on employee safety. Every disaster recovery plan needs to begin by addressing the physical safety and psychological well-being of employees. That means the plan must include alternative locations where employees can go if a primary work site is unavailable, as well as incident notification and escalation strategies. In addition, the plan needs to be well communicated throughout the organization so everyone knows how to respond in a disaster situation.
  • Business and IT Impact  Conduct a business and IT impact analysis. Carry out a thorough analysis of people, information, application, and other resources to build an understanding of the consequences - financial and operational - of losing vital components. Take particular care to uncover interdependencies across the organization that is critical to staying in business. This analysis will provide a solid foundation for establishing recovery priorities and timeframes in your plan, allowing you to make informed decisions on where and how much to invest in disaster recovery.
  •  Plan with business operations in mind. Involve all key stakeholders in the planning process, including IT, business leaders, human resources, corporate communications, and physical and information security managers. Be sure that in planning you coordinate with other business units in your organization to avoid potential conflicts, such as multiple business units depending on the same facility as a secondary site in response to an interruption.
  •  Make the disaster recovery plan a living document. Business processes and IT systems undergo constant change in every organization. Your disaster recovery plan needs to keep pace with new workflows, business applications, and computer systems. Disaster recovery planning software can provide best practice methodologies to help you navigate through planning decisions and plan updates. In addition, regular testing will help you demonstrate your ability to recover and pinpoint areas for plan improvements.
- more info



Disaster recovery and business continuity planning issues

Disaster recovery and business continuity management and contingency planning are essential especially in these economic times. However, the creation, testing, and updating  of a sound disaster recovery and continuity and contingency plan is costly and complex.

For example, initially it is necessary to understand the underlying risks and the potential impacts of disaster. This is the primary building block upon which sensible and cost effective business continuity plan or disaster recovery plan is built. When the plan itself is created, there are the maintenance and testing phases, to ensure that the plan remains current. Even having arranged all these matters there are the external auditors to consider - and of course, there is the not so small matter of ISO 27000, SOX, HIPAA, and PCI-DSS compliance.

The industry standard solution is the Disaster Recovery and Business Continuity Template by Janco Associates. The template includes all of the right tools to assist with business impact analysis and risk analysis. You can quickly create a core plan (some of Janco's clients have created an operational plan in less than thirty days), maintain the plan, audit the DRP BCP, and create a cost effective budget to support the disaster recovery business continuity process.

- more info