Search
Recommended Products
Related Links


 
 

 

 

Informative Articles

A Customer complaint management system
Background The company was experiencing an increase in the number of customer complaints and an increase in the cost of processing them and we were hired to analyze the current situation and develop recommendations to increase the effectiveness of...

A Fresh Start for Family Finances in 2005
While 40% to 50% of us make New Year’s resolutions on January 1—a ritual that has existed since ancient times—approximately 60% to 80% of us have already broken them by the end of February, according to researchers. It’s still not too late,...

Asset Searching for Recovery Actions - The Decision Maker’s Most Critical Tool – Part 1
As certified fraud examiners (CFE), we all know the nuts and bolts of our respective areas of specialty, and hopefully, we are all growing professionally at an astounding pace. Crime does, unfortunately, pay – just not for the criminal. After...

Business Continuity Testing starts with the risks
Business Continuity Testing starts with the risks All business continuity analysis should be risk based, and risk prioritised to deal with the important business risks first. This means that any risks to your business need to be identified,...

ESecurity
ESecurity Current Situation Up until recently, security was very much like teenage sex in that it was typified by lots of talk but no action. Companies declared their sites as secure simply because the credit card payment page was protected by...

Identity Theft: The road back
A couple of weeks ago, a friend of mine mentioned that one of his co-workers recently recovered his stolen identity. I asked how long the process took. "Only two years" he replied. Compared to the six year nightmare suffered by one of my business...

Microsoft SQL 2000 Disaster Recovery with SANRAD V-Switch - Planning Guide
Designing a disaster recovery system requires planning and consideration of the available options that will best fit your company's needs, SLA and budget. With SANRAD DR Solution there is no need to use Log shipping (which requires extra...

Secure Your Data - Windows Data Backup Computer Software
In nowadays computers have entered almost every imaginable domain in our lives - from our homes to space shuttles. As they hold more and more precious data - in material or merely sentimental way - securing that data is not only option, but a must....

The Essential Data Recovery Report
Your worst nightmare just became a horrifying reality. You keep hearing that little voice in your head mockingly shout “you should have backed that stuff up” The voice keeps echoing throughout your head as you perform a quick inventory all of the...

Welcome to the world of Knoppix
Knoppix is a bootable CD with a collection of GNU/Linux software, automatic hardware detection, and support for many graphics cards, sound cards, SCSI and USB devices and other peripherals. Knoppix can be used as a Linux demo, educational CD, rescue...

 
 
 
Business Continuity and Disaster Recovery - Risk Analysis and Control


In the risk evaluation phase, there are a number of key areas that must be covered. One of the most important is to understand probable threats. In an ideal world, which most of us have noticed does not exist, we would identify and protect ourselves against all threats to ensure that our business continues to survive. Obviously, we are constrained by other factors such as budgets, time and priorities and need to apply cost benefit analysis to ensure we are protecting the most critical business functions.

A second important step is to identify all probable threats and prioritize them. Threats, typically, can be classified in several ways such as internal/external, man-made/natural, primary/secondary, accidental/intentional, controllable/not controllable, warning/no warning, frequency, duration, speed of onset etc. While classifying threats is helpful in terms of understanding their characteristics and potential controls, grouping and understanding by business impact is also important. Obviously, the same impact can result from a number of different threats.

Identifying mission critical business processes and systems is another fundamental building block of the business continuity plan. After your critical business processes and systems and probable threats are established, the next step is to identify vulnerabilities and loss potential. This requires an extensive scan of the organization to identify vulnerabilities and then analysis to understand those vulnerabilities which would have the greatest impact on your critical business processes and the organization. This starts to clarify and quantify potential losses, which helps to establish priorities.

Following the identification of the most probable threats and vulnerabilities, an analysis of existing

 


controls is needed. This spans physical security as well as people, processes, data, communications and asset protection. Some controls such as physical security and data backup are obvious. Other controls required are often less obvious, but they can be identified through the risk evaluation process.

Once the key building blocks of critical business functions, most probable threats, vulnerabilities and controls are identified, the next stage is to develop an understanding of the probability of threats factored by the severity or impact of the threats. This leads to the business impact analysis phase which establishes priorities for protection.

The goal is to minimize threats, impacts and downtime and to mitigate any losses. Fundamentally, the goal is to protect your people, protect your data, protect your vital communications, protect your assets and to protect your brand and reputation. Overall, of course, the goal is to ensure your business continues to operate and to do it in a cost-effective way meeting standards of reasonable and prudent judgment.

Bob Mahood


Midwest Data Recovery Inc.


www.midwestdatarecovery.com


bmahood@midwestdatarecovery.com


312 907 2100 or 866 786 2595

Robert Mahood has significant technology and management experience in data communications, internet, storage, disaster recovery and data recovery. He is currently the president of Midwest Data Recovery. www.midwestdatarecovery.com


bmahood@midwestdatarecovery.com