Planning a Recovery That Isn't a Disaster
Our overwhelmed security manager wants her disaster recovery plan to be more than an exercise in filling in the blanks.
Computerworld - Trouble Ticket
At issue: The disaster recovery plan isnt worth the paper its printed on.
Action plan: Devise something of real value despite tight resources.
Every January, I have to update my agencys disaster recovery plan. The good news is that the state only requires me to fill in some forms. I could be done in half an hour. The bad news? Should one of the states major cities ever be struck by terrorists, this so-called disaster recovery plan would leave us looking like FEMA after Hurricane Katrina hit.
Im not the sort of person whos content to satisfy the minimum requirements when I know how inadequate they are. This year, Im considering revamping the entire plan, including testing it and training people on it.
But Im shaking my head while I write these words. If youve been reading this column lately, then you already know why. My state is experiencing a budget crisis, and Ive been bemoaning my lack of resources, especially the time and staff I need to do everything that needs to get done. Do I really think I can throw another big project in on top of managing a network and all of our information security?
My problem is that I cant help but identify with those nameless FEMA employees I have conjured up in my imagination. There were probably plenty of them who knew that what the agency had down on paper and stored away in dusty binders was pretty much useless because it hadnt been tested. I dont want to think I knew it would be this way after the fact. Lives are at stake, and I cant live with the potential consequences.
That means doing something more than the minimum this year, even though Ill probably have to do it on my own time.
I can start by assessing what I know. It could be that Im not informed about the states readiness to respond to a catastrophe. After all, my agency provides social services, not public safety. If a city blows up, who cares if social services shut down? The top priorities would be saving lives, searching for victims, discovering what happened, apprehending perpetrators and calming the public. My agency isnt involved in any of that.
Still, the state is more than one city, and we cant let everyone else down. Basically, we need to try to ensure that we can continue to operate, even if our main facility is destroyed or simply inaccessible.
Baby Steps
But first things first. As in any disaster recovery plan, employee safety is the No.1 priority. At the very least, I can update the employee roster so that locating employees (or their next of kin) wont be difficult. Then I can update the evacuation plans and perhaps expand them. Anything I do here is going to be an improvement, since the current plan is the equivalent of a fire drill.


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Driving Secure Enterprise File Sharing and Syncing in the Enterprise
- GroupLogic's new activEcho is the industry's only secure Enterprise File Sharing and Synching solution that balances the need for simplicity for the end...
- The Enterprise File Sharing Option
- Enterprises and IT departments need to address several critical security issues when considering file sharing and syncing products. Many of today's solutions do...
- Security Strategies to Virtualizing Internet-Facing Applications
- The IT organization at Intel has set a goal to transition their enterprise to a private cloud for their Office and Enterprise applications....
- Cloud Security Planning Guide
- Cloud security considerations span protecting hardware and platform technologies in the data center to enabling regulatory compliance and defending cloud access through different...
- Cloud Security Vendor Round Table
- This vendor round table guide will help you to evaluate different cloud technology vendors and service providers based on a series of questions... All Security White Papers
- Live Webcast
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute - Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
- Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - Security Certifications 101 - BlackBerry and all those acronyms what do they mean and why they matter?
- FIPS, Common Criteria, CAPS, AISEP, NFC, NIST, Fraunhofer SIT, CESG, DSD - these are just some of the government and industry certifications which...
- BlackBerry PlayBook OS 2.0 Security Overview
- The presentation provides an overview of BlackBerry PlayBook OS 2.0 security capabilities and features, including: BlackBerry® Balance™ technology, BlackBerry® Bridge, data-at-rest protection, and...
- BlackBerry NFC Security Overview
- The presentation on NFC security will provide an overview of the security protections built into the BlackBerry platform to protect users, application developers...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts