It should be noted that the subsection describing the emergency phase applies equally to a disaster affecting the Adminstration Building or other building on campus, the functional area that provides support for the maintenance of the critical system.
The emergency phase begins with the initial response to a disaster. During this phase, the existing emergency plans and procedures of Campus Police and Physical Plant direct efforts to protect life and property, the primary goal of initial response.
Security over the area is established as local support services such as the Police and Fire Departments are enlisted through existing mechanisms. If the emergency situation appears to affect the main data center or other critical facility or service , either through damage to data processing or support facilities, or if access to the facility is prohibited, the Duty Person will closely monitor the event, notifying BCMT personnel as required to assist in damage assessment.
Once access to the facility is permitted, an assessment of the damage is made to determine the estimated length of the outage. If access to the facility is precluded, then the estimate includes the time until the effect of the disaster on the facility can be evaluated. The recovery process then moves into the back-up phase. The Business Continuity Management Team remains active until recovery is complete to ensure that the Institute will be ready in the event the situation changes.
In the initial stage of the back-up phase, the goal is to resume processing critical applications. Processing will resume either at the main data center or at the designated hot site, depending on the results of the assessment of damage to equipment and the physical structure of the building.
During this period, processing of these systems resumes, possibly in a degraded mode, up to the capacity of the hot site. However, if the damaged area requires a longer period of reconstruction, then the second stage of back-up commences. See Page 33 for a list of the designated recovery sites.
The time required for recovery of the functional area and the eventual restoration of normal processing depends on the damage caused by the disaster.
The time frame for recovery can vary from several days to several months. In either case, the recovery process begins immediately after the disaster and takes place in parallel with back-up operations at the designated hot site. The primary goal is to restore normal operations as soon as possible. Specifically, each function of these systems was evaluated and allocated a place in one of four risk categories, as described below.
Note: Category IV functions are important to MIT administrative processing, but due to their nature, the frequency they are run and other factors, they can be suspended for the duration of the emergency.
Recovery for these systems too must be based upon an assessment of the impact of their loss and the cost of their recovery. Composed of sub-teams the Institute Support Teams , the Business Continuity Management Team as a whole plans and implements the responses and recovery actions in the event of a disaster disabling either a functional area, Central Administration or the main data center. Also responsible for ongoing maintenance, training and testing of the Business Continuity Plan.
Provides alternate voice and data communications capability in the event normal telecommunication lines and equipment are disrupted by the disaster. Evaluates the requirements and selects appropriate means of backing up the MIT telecommunications network. Provides for physical security and emergency support to affected areas and for notification mechanisms for problems that are or could be disasters. Extends a security perimeter around the functional area affected by the disaster.
Provides coordination with public emergency services Cambridge Police, etc. Coordinates all services for the restoration of plumbing and electrical systems and structural integrity. Assesses damage and makes a prognosis for occupancy of the structure affected by the disaster. Director, Personnel Department. Coordinates all activities of the recovery process with key attention to the personnel aspects of the situation.
This includes releasing staff from areas affected, initiating emergency notification systems and working with the MIT News office on dissemination of information about the recovery effort. Communicates with the news media, public, staff, faculty, and student body who are not involved in the recovery operation.
Represents the Office of the President. Represents the Vice President for Financial Operations. To oversee the development, maintenance and testing of recovery plans addressing all Category I and II business functions. The Team is composed of key management personnel from each of the areas involved in the recovery process.
The team interfaces with and is responsible for all business continuity plans and planning personnel at MIT. On a quarterly basis, the team will meet to review FARM Team plans that have been completed in the last quarter. On an annual basis, the Team will review the overall status of the recovery plan, and report on this status through the Information Security Officer, to the Administrative Computing Steering Committee.
Individual Team members will prepare recovery procedures for their assigned areas of responsibility at MIT. They will ensure that changes to their procedures are reflected in any interfacing procedures. They will also participate in emergency preparedness drills initiated by the Safety Office or other appropriate campus organizations.
The Business Continuity Plan procedures supplement, and are subordinate to those in the Black Book, which takes precedence in the case of any difference. Following assessment of the damage, the team is then responsible for salvage operations in the area affected. Headed by the Administrative Officer for Physical Plant and activated during the initial stage of an emergency, the team reports directly to the Business Continuity Management Team, evaluates the initial status of the damaged functional area, and estimates the time to reoccupy the facility and the salvageability of the remaining equipment.
During an emergency situation, the individual designated in the Black Book will take operational responsibility for implementation of damage assessment. Following assessment, the team is responsible for salvaging equipment, data, and supplies following a disaster; identifying which resources remain; and determining their future utilization in rebuilding the data center and recovery from the disaster.
Identification of all equipment to be kept current. A quarterly report will be stored off-site. The listing will show all current information, such as engineering change levels, book value, lessor, etc. Configuration diagrams will also be available. Emergency equipment, including portable lighting, hard hats, boots, portable two-way radios, floor plans and equipment layouts will be maintained by Physical Plant.
A listing of all vendor sales personnel, customer engineers and regional sales and engineering offices is to be kept and reviewed quarterly. Names, addresses and phone numbers normal, home, and emergency are also to be kept. To provide for all facets of a positive security and safety posture, to assure that proper protection and safeguards are afforded all MIT employees and Institute assets at both the damaged and backup sites.
The team will consist of the Campus Police Department Supervisor and appropriate support staff. The Campus Police Team will interface with the following teams or organizational units, relative to security and safety requirements:. Identify the number of Campus Police personnel needed to provide physical security protection of both the damaged and backup sites. Identify the type of equipment needed by Campus Police personnel in the performance of their assigned duties.
Identify and provide security protection required for the transport of confidential information to and from both off-site and backup sites. Coordinate with the appropriate MIT Department.
The most difficult time to maintain good public relations is when there is an accident or emergency. Public relations planning is required so that when an emergency arises, inquiries from the news media, friends and relatives of staff, faculty, and students can be handled effectively.
While we cannot expect to turn a bad situation into a good one, we can assist in making sure facts presented to the public are accurate and as positive as possible given the situation. It is in our best interest to cooperate with the media as much as possible, so that they will not be forced to resort to unreliable sources to get information that could be untrue and more damaging to the Institute than the facts.
All public information must be coordinated and disseminated by their staff. Refrain from releasing information on personnel casualties until families have been notified. Once families have been notified, names of those personnel should be released quickly to alleviate the fears of relatives of others. Provide factual information to the press and authorities as quickly as facts have been verified, and use every means of communications available to offset rumors and misstatements. Avoid speculating on anything that is not positively verified, including cause of accident, damage estimates, losses, etc.
Fire Officials normally release their own damage estimates. Situations calling for implementation of the Emergency Public Information Plan may include, but are not limited to:. The News Office alternates are listed in Appendix A. In their absence the responsibility will revert to the Senior Manager on the scene. Copies of all status reports to the Business Continuity Management Team or Administrative Computing Steering Committee will be forwarded to the Public Information Officer for potential value in information distribution for good public relations.
They will work with the Personnel Department in dissemination of information to staff. Existing relationships with local media will be utilized to notify the public of emergency and recovery status.
The Public Information Officer will maintain up-to-date contact information for the media and other required parties. A facility will be identified to be used as a press room.
Arrangements will be made to provide the necessary equipment and support services for the press. In addition to all of these positive effects of having a DRP, it also helps with the following:. Most businesses cannot afford to be non-profitable and lose critical operations for an extended period of time. DRPs help to ensure that all operations can be restored in a quick, responsive manner. Assess the risk and impact associated with losing business functions in a disaster.
Look at historical or company background information to determine if any disasters have affected the organization in the past, and how they were consequently handled. Perform a gap analysis to compare what is currently being done to prevent or handle a disaster against what should be done, and see if there are missing components. Next, identify any existing preventive controls to mitigate disasters. A DRP is comprised of many different human resources who are leveraged when a disaster or emergency strikes.
These participants are usually grouped into teams to cover a variety of important responsibilities included in a DRP. The plan development team helps craft the plan and assigns responsibilities to the other resources. The IT and application teams deal with disaster strategies that disrupt that portion of the business, and the emergency response team focuses on the overall emergency response process of the entire organization.
Within the emergency response team is a primary crisis manager and a company spokesperson who both focus on communicating and acting on emergency response procedures. An emergency contact helps in altering the rest of the business of the disaster, specifically to vendors or suppliers who may work remotely. Because a DRP is an important document for any business or organization to have, creating the most accurate, clear, and actionable plan can be daunting.
The following tips can help:. Once you have completed the plan, ask the following questions to ensure that your DRP is coherent, comprehensive, and easy to implement:. For more direction in creating the most appropriate and actionable DRP for your business, refer to these recovery plan examples to gain familiarity and understanding of how to write and what to include in a DRP.
To gain an even better idea of how to create the best disaster recovery plan, and detail why every business should have one, refer to these helpful resources and reports:.
Empower your people to go above and beyond with a flexible platform designed to match the needs of your team — and adapt as those needs change. The Smartsheet platform makes it easy to plan, capture, manage, and report on work from anywhere, helping your team be more effective and get more done. Report on key metrics and get real-time visibility into work as it happens with roll-up reports, dashboards, and automated workflows built to keep your team connected and informed.
Try Smartsheet for free, today. In This Article. Disaster Recovery Plan Template. See how Smartsheet can help you be more effective. IT Disaster Plan Template. Data Disaster Recovery Plan Template. Disaster Recovery Communication Plan Template. Payroll Disaster Recovery Plan Template. School Disaster Management Plan Template. Disaster Management Plan Template. Disaster Drill Evaluation Template.
Disaster Call Tree Template. Manufacturing Disaster Recovery Plan Template. Disaster Recovery Runbook. Application Disaster Recovery Plan Template. What Is a Disaster Recovery Plan? In addition to all of these positive effects of having a DRP, it also helps with the following: Ensure employees and team members can react rapidly and restore activity effectively, in light of an emergency or disaster.
Capture, summarize, and organize critical information needed to restore business operations. Develop, test, and document a detailed, easy-to-understand plan. Secure contingency plans, and ensure they are cost effective.
Build resilience within the business. Download our disaster recovery template here. Writing a disaster recovery plan for your small business [free template] Friday, June 12, by Tilly Holland The practice of preparing for downtime, and of taking steps to ensure a speedy return to normality, is called disaster recovery DR planning. What is a disaster recovery plan, anyway? Your disaster recovery plan should take into account the following: IT services: Which business processes are supported by which systems?
What are the risks? Suppliers: Which external suppliers would you need to contact in the event of an IT outage? Your data recovery provider , for example. Locations: Where will you work if your standard premises are rendered inaccessible?
Testing: How will you test the DR plan? Training: What training and documentation will you provide to end-users? RTO: The maximum amount of time that should be allowed to elapse before the backup is implemented and normal services are resumed.
Structuring the perfect disaster recovery plan Even a small business DR plan can be a lengthy and complex document. Also includes a revision history to track changes.
0コメント