Skip the navigation

U.S. regulators issue disaster recovery guidelines

By Lucas Mearian
April 11, 2003 12:00 PM ET

Computerworld - Three U.S. regulatory agencies have released disaster recovery guidelines for financial institutions notable for their lack of any recommended minimum distance between primary and secondary data centers and their recognition that achieving many of the goals could take years.
The Federal Reserve, the Office of the Comptroller of the Currency and the Securities and Exchange Commission on April 8 issued a white paper describing objectives for disaster recovery and business continuity plans that should be set in place.
The agencies stated that they expect organizations that fall within the scope of the white paper to "adopt the sound practices within the specified implementation time frames."
The regulators focused mostly on what they described as "core clearing and settlement organizations," or the largest brokerages, custodian banks and clearing firms, saying they should substantially achieve disaster recovery and sound business continuity practices by the end of 2004.
In the event of a wide-scale disaster, the nation's financial system "rests on the rapid recovery and resumption of the clearing and settlement activities that support critical markets," the agencies said.
The guidelines include the recommendation of recovering operations "within the business day on which a disruption occurs, with the overall goal of achieving recovery and resumption within two hours after an event."
"The paper's business continuity objectives, sound practices and timetables will clearly improve the resilience of the U.S. financial markets," Donald Kittell, executive vice president of the Securities Industry Association, stated in a press release.
The document also said that the focus of financial firms should be on "appropriate back-up capacity necessary for recovery and resumption of clearing and settlement activities for material open transactions in the wholesale financial markets."
The agencies' business continuity objectives include rapid recovery and timely resumption of critical operations following wide-scale disruptions or loss of staff in "at least one major operating location," and a high level of confidence through ongoing testing that plans are "effective and compatible."
In August, an interagency white paper that was released on strengthening the resilience of the U.S. financial system was soundly criticized by banks and brokerages for its suggestion that there be a minimum distance of 200 to 300 miles between a primary and backup data center (see story).
Many firms considered it technically unfeasible. For example, Fibre Channel, the most common network protocol used between data centers, has a distance limit of about 62 miles, or 100 kilometers.
"We were pleased, because they took into account the dialogue agencies had with the industry after the first white paper came out[in August]. That's the key point. We're all working together," said Margaret Draper, a spokeswoman for the Securities Industry Association in New York.
Draper said the white paper could eventually become the basis for industry-specific rules that would be administered by self-regulatory organizations, such as the National Association of Securities Dealers Inc. and the New York Stock Exchange.
Regulators said firms should also maintain sufficient geographically dispersed resources to meet recovery and resumption objectives.
But the agencies stated that they aren't recommending that firms move their primary offices or data centers outside of metropolitan locations, because they understand that financial firms need to maintain processing sites near the financial markets.

Read more about Business Continuity in Computerworld's Business Continuity Topic Center.



Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Business Continuity White Papers
An Interactive Guide: Bring Your Own Device
BYOD presents significant security and management challenges to IT departments who want to take advantage of the trend, but still protect corporate assets....
Malware Security Report: Protecting Your Business, Customers, and the Bottom Line
Protect your business and customers by understanding the threat from malware and how it can impact your online business. This paper highlights how...
Security Predictions for 2012
With all of the crazy 2011 security breaches, exploits and notorious hacks, what can we expect for 2012? Last year's Websense Security Labs...
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
All Business Continuity White Papers
Business Continuity Webcasts
Data Protection and Information Governance
Today, legal hold and information governance are increasingly becoming drivers for data protection. However, few organizations knows what information they have, where to...
Data Protection and Disaster Recovery with iSCSI and VMware
Get this on demand webcast now
Optimizing Networks for the Cloud
Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
All Business Continuity Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs