Attachment # 00011124 - Omega_Sample_BIA_Template.docx

Omega_Sample_BIA_Template.docx (35.47 KB)
Raw Preview of Attachment:
(refer to the detailed question and attachment below)
This sample template is designed to assist the user in performing a Business Impact Analysis (BIA) on an information system. The template is meant only as a basic guide and may not apply equally to all systems. The user may modify this template or the general BIA approach as required to best accommodate the specific system. In this template, words in italics (or curly braces and italics) are for guidance only and should be deleted from the final version. Regular text is intended to remain.1.OverviewThis Business Impact Analysis (BIA) is developed as part of the contingency planning process for the {system name}{system acronym}. It was prepared on {insert BIA completion date}.1.1PurposeThe purpose of the BIA is to identify and prioritize system components by correlating them to the business process(es) the system supports and by using this information to characterize the impact on the process(es) if the system were unavailable.The BIA is composed of the following three steps.Determine business processes and recovery criticality. Business processes supported by the system are identified, and the impact of a system disruption to those processes is determined along with outage impacts and estimated downtime. The downtime should reflect the maximum that an organization can tolerate while still maintaining the mission.Identify resource requirements. Realistic recovery efforts require a thorough evaluation of the resources required to resume business processes and related interdependencies as quickly as possible. Examples of resources that should be identified include facilities, personnel, equipment, software, data files, system components, and vital records.Identify recovery priorities for system resources. Based upon the results from the previous activities, system resources can more clearly be linked to critical business processes and functions. Priority levels can be established for sequencing recovery activities and resources.This document is used to build the {system name} ISCP and is included as a key component of the ISCP. It also may be used to support the development of other contingency plans associated with the system, including, but not limited to, the Disaster Recovery Plan (DRP) or Incident Response Plan (IRP).2.System DescriptionProvide a general description of system architecture and functionality.Indicate the operating environment, physical location, general location of users, and partnerships with external organizations/systems. Include information regarding any other technical considerations that are important for recovery purposes, such as backup procedures. Provide a diagram of the architecture, including inputs and outputs and telecommunications connections.3.BIA Data CollectionData collection can be accomplished through individual/group interviews, workshops, e-mail, questionnaires, or any combination of these.3.1Determine Process and System CriticalityStep one of the BIA process—Working with input from users, managers, business process owners, and other internal or external points of contact (POC), identify the specific business processes that depend on or support the information system.Business ProcessDescriptionPay vendor invoiceProcess of obligating funds, issuing check or electronic payment and acknowledging receiptIf criticality of business processes has not been determined outside of the BIA, the following subsections will help to determine criticality of business processes that depend on or support the information system.3.1.1 Identify Outage Impacts and Estimated DowntimeThis section identifies and characterizes the types of impacts that a system disruption is likely to create in addition to those identified by the FIPS level, as well as the estimated downtime that the organization can tolerate for a given process. Impact categories should be created and values assigned to these categories in order to measure the level or type of impact a disruption may cause. An example is provided. The template should be updated to reflect what is appropriate for the organization.Outage ImpactsImpact categories and values should be created in order to characterize levels of severity to the organization that would result for that particular impact category if the business process could not be performed. These impact categories and values are samples and should be updated to reflect what is appropriate for the organization.The following impact categories represent important areas for consideration in the event of a disruption or impact.Impact category: {insert category name} Impact values for assessing category impact:Severe = {insert value}Moderate = {insert value}Minimal = {insert value}Example impact category = CostSevere—Temp staffing, overtime, fees are greater than $1 millionModerate—Fines, penalties, liabilities potential $550kMinimal—New contracts, supplies $75kThe table below summarizes the impact on each business process if {system name} were unavailable, based on the following criteria.Business ProcessImpact Category{insert}{insert}{insert}{insert}ImpactPay vendor invoiceEstimated DowntimeWorking directly with business process owners, departmental staff, managers, and other stakeholders, estimate the downtime factors for consideration as a result of a disruptive event.Maximum Tolerable Downtime (MTD). The MTD represents the total amount of time leaders/managers are willing to accept for a business process outage or disruption and includes all impact considerations. Determining MTD is important because it could leave continuity planners with imprecise direction on (a) selection of an appropriate recovery method and (b) the depth of detail which will be required when developing recovery procedures, including their scope and content.Recovery Time Objective (RTO). RTO defines the maximum amount of time that a system resource can remain unavailable before there is an unacceptable impact on other system resources, supported business processes, and the MTD. Determining the information system resource RTO is important for selecting appropriate technologies that are best suited for meeting the MTD.Recovery Point Objective (RPO). The RPO represents the point in time, prior to a disruption or system outage, to which business process data must be recovered (given the most recent backup copy of the data) after an outage.The table below identifies the MTD, RTO, and RPO (as applicable) for the organizational business processes that rely on {system name}. Values for MTDs and RPOs are expected to be specific time frames, identified in hourly increments (i.e., 8 hours, 36 hours, 97 hours, etc.).Business ProcessMTDRTORPOPay vendor invoice72 hours48 hours12 hours (last backup)Include a description of the drivers for the MTD, RTO, and RPOs listed in the table above (e.g., mandate, workload, performance measure, etc.).Include a description of any alternate means (secondary processing or manual work-around) for recovering the business process(es) that rely on the application. If none exists, so state.3.2Identify Resource RequirementsThe following table identifies the resources that compose {system name} including hardware, software, and other resources such as data files.System Resource/ComponentPlatform/OS/Version (as applicable)DescriptionWeb Server 1Optiplex GX280Web Site HostAssume that all identified resources support the business processes identified in Section 3.1 unless otherwise stated.3.3Identify Recovery Priorities for System ResourcesThe table below lists the order of recovery for {system name} resources. The table also identifies the expected time for recovering the resource following a “worst-case” (complete rebuild/repair or replacement) disruption.■ Recovery Time Objective (RTO). RTO defines the maximum amount of time that a system resource can remain unavailable before there is an unacceptable impact on other system resources, supported business processes, and the MTD. Determining the information system resource RTO is important for selecting appropriate technologies that are best suited for meeting the MTD.PrioritySystem Resource/ComponentRecovery Time ObjectiveWeb Server 1Optiplex GX28024 hours to rebuild or replaceA system resource can be software, data files, servers or other hardware and should be identified individually or as a logical group.Identify any alternate strategies in place to meet expected recovery time objectives. This includes backup or spare equipment and vendor support contracts.

Question

Disaster Recovery? Forensics and Security

Question # 00617258
Subject: General Questions
Due on: 09/27/2020
Posted On: 09/25/2020 12:51 AM
Tutorials: 0
Rating:
4.9/5
Question Dot Image

Objective

The purpose of this two-part project is to familiarize the student with recovery planning, starting with the BIA and continuing with a system recovery plan. By completing the two documents, the student will gain practical knowledge of two key components of the contingency planning process. The project will enable the student to see and understand the required standards in practice, as well as the details that should be covered within the recovery planning processes.

Detailed Requirements

Project Deliverable #1 (Due Week 4)—COs B and C

  • Project documents are located in Course Resources
  • Using the Omega Case Study, complete the BIA template for their SAP system. Note, the BIA template is Appendix B of the NIST SP 800-34 Rev. 1 document.
  • Provide a one- to two-page analysis summarizing the results to the executive management team of Omega. The summary should highlight the priority of business functions, along with the potential for loss in the event of a disaster or sustained outage.

 

Project Deliverable #2 (Due Week 7)—CO D

  • Project documents are located in Course Resources
  • Using the Omega Case Study, complete the Information System Contingency Plan template for their SAP system. Note, the ISCP template is Appendix A.3 of the NIST SP 800-34 Rev. 1 document.
  • Provide a three- to five-page analysis summarizing the plan to the executive management team of Omega. The summary should effectively describe the recovery process in a manner that will allow the Senior Leadership to understand the timing, resources, and recovery options.

Guidelines

Project Deliverable #1 — Week 4, Business Impact Analysis (BIA) 

  • Using the Omega Case Study, the BIA template must be completed for the Production SAP system.
  • The analysis paper must be one to two pages long and must conform to APA standards. See Course Resources in the Introduction & Resources area under Modules for access to Writing Source, where you'll find videos on writing for research projects.
  • At least two authoritative, outside references are required (anonymous authors or web pages are not acceptable). These should be listed on the last page titled References.
  • Appropriate citations are required. See the Syllabus regarding plagiarism policies.
  • This will be graded on quality of research topic, quality of paper information, use of citations, grammar and sentence structure, and creativity.
  • The paper is due during Week 4 of this course.

Project Deliverable #2 — Week 7, System Recovery Plan 

  • Using the Omega Case Study, create the system contingency plan template for the Production SAP system.
  • The analysis paper must be three to five pages long and must conform to APA standards. See Course Resources in the Introduction & Resources area under Modules for access to Writing Source, where you'll find videos on writing for research projects. We also have the Tutor Source resource, which is accessible in Introduction & Resources.
  • At least two authoritative, outside references are required (anonymous authors or web pages are not acceptable). These should be listed on the last page titled References.
  • Appropriate citations are required. See the Syllabus regarding plagiarism policies.
  • This will be graded on quality of research topic, quality of paper information, use of citations, grammar and sentence structure, and creativity.
  • The paper is due during Week 7 of this course.

 

Dot Image
enorense Posted By :
Questions: 1 Tutorials: 0
Attachments