Business Continuity for Data Management
The importance of data to a company’s daily operations cannot be overstated. Financial data, intellectual property, employee, customer and supplier sensitive information are so important that the federal and state governments have passed a number of laws and requirements around data security, protections and disclosure reporting. Critical to the securing and protection of company data is a business continuity plan (BCP). Developing a formal BCP can help companies respond to and reduce the impact of an incident that could potentially cause a critical interruption or loss to a company’s production and business operations.
Business interruptions may be related to natural or man-made disasters, power outages or technological incidents, such as a breach in data security or a distributed denial of service (DDoS) attack. In the case of a DDoS, multiple compromised systems target a user system, forcing it to shut down, thereby denying legitimate users access to its service. A data breach can result in the theft or corruption of a company’s financial data, intellectual property and/or personal identifiable information of its employees, customers and suppliers. Both a DDoS and data breach can disrupt a company’s production and operations, and result in a loss of profit, reputation and trust of customers, employees, suppliers and other third parties. For this reason, incorporating a cyber security program and incident response plan into a BCP is a good practice.
Studies suggest that business continuity plans that include IT security plans can help companies recover from a data breach incident more readily than companies without an IT security plan. Developing an IT security business continuity plan (BCP) is not a one-and-done. It is necessarily a continuous process as cyberspace, hackers and malicious software and schemes continually evolve and new threats continue to change the data security environment.
A four-step planning process to help develop an IT security BCP
Step one – threat assessment
An effective IT security BCP starts with a threat assessment that identifies the nature and likelihood of an event. Hackers using techniques targeted at business system users – like malware, phishing and misuse of credentials – are common vulnerabilities. Other vulnerabilities may involve an unintentional activity, such as an employee attaching a wrong file to an email, or sending an email to the wrong person, or misplacing or losing a laptop or other electronic device containing sensitive information. Your plan should include controls to mitigate the potential impact of losses caused by these acts or technological failures (accidental or intentional), as well as natural disasters (severe weather, tornados, hurricanes, and earthquakes, for example). Other risks, such as power outages and power grid failures also should be considered.
As you evaluate the impact of the events, assess if you have adequate strategies in place to prevent or reduce the impacts of the events. For those answered “no,” additional planning and controls will be needed.
Step two – business critical impact analysis
Next, conduct a business impact analysis to aid you in identifying and prioritizing the most critical business functions necessary to keep your operations up and running. The goal of the business impact analysis is not to plan for the resumption of every operation or function, but rather to plan for those that are necessary to maintain an acceptable level of operation.
A company's functions/operations can be described as “critical,” “essential” and “complementary” respectively in degree of importance and in terms of being necessary for continuing business operations in the event of a disaster. The distinctions between these three categories generally include, among other things, factors such as critical data or information, critical equipment, and time sensitivity, such as customer-imposed service deadlines.
Critical functions, data and information need to be restored first. To determine what is critical, a common methodology is to start the analysis by looking at where the revenue comes from in the company – your product or service and what your customer ultimately pays you to do for them. The operations, data and information that are vital to keeping your customers’ needs met and the revenue flowing are critical and must be restored quickly to avoid financial harm to the business.
After the critical functions, have been identified and assessed, your next priority is to identify and assess your essential functions. These are functions that need to be back in place to help ensure the ongoing health and well-being of your business over the long term. Essential functions typically have a little more flexibility in the amount of time you can take to restore the functions and in what order they should be restored.
Lastly are nonessential or complementary functions. These are items that start to return your business to the level of comfort and convenience it had prior to the disaster but are not considered either critical or essential for you to resume some credible level of operation.
Step three – prevention and mitigation strategies
Using the detailed information gained in the previous steps, you are now able to develop prevention and mitigation strategies to help prepare for, respond to and recover from the aftermath of an event.
Prevention and mitigation strategies work together as controls. Prevention efforts can help prevent or reduce the probability of occurrence. Preventive measures should be commensurate with the risk identified. Mitigation efforts include measures to limit or control the consequences from an incident that cannot be prevented.
An essential IT security BCP mitigation strategy should include a comprehensive backup plan for critical data, hardware, software and firmware is an important IT security mitigation strategy. Items to include, but not limited to:
- To enable prompt restoration of the network from back-up, the operating system, software programs, applications, critical information and any proprietary programs should be backed-up off site so they can be readily reloaded into replacement equipment.
- Specify who is responsible for creating backups, where the backups are stored, and who has access to those backups. If you are using third parties to store your back-ups, your contracts should specify the level of security that they must maintain and the time frames they have to deliver your backups. The procedures to rebuild servers and other important devices on your network should be fully documented and kept up to date.
- The plan should specify how often the different types of data, hardware, software and firmware should be backed up. As needed, keep a contact list of vendors that can replace your inventory of equipment and software programs.
- All back-ups should be stored at a remote location that cannot be impacted by the same event and are properly protected in a secured area with restricted access. All sensitive information should be encrypted.
- All access to backup environments, especially privileged/admin access, must be protected with Multi-Factor Authentication (MFA).
Step four – testing, practice and continuous improvement
Finally, test and exercise your plan routinely and evaluate its effectiveness. Key personnel (employees and third parties) knowledgeable of the backup and restoration processes can periodically conduct sample tests of the system backups to verify that the operating system, applications, and data from the backup can be restored.