Business Continuity Planning: A Byte Of Prevention Is Worth A Gigabyte Of Cure-

Business Continuity Planning is a term popularizedenterprise alike. Not to mention direct revenue loss,
over the last two decades and has evolved fromcompensatory payments, lost future revenue, billing
planning in the event that there is an earthquake tolosses, investment revenue losses leading to impaired
planning in the event that there is an earth-shatteringfinancial performance, revenue recognition, affected
e-virus. How is the evolution of threats facingcash flow, lost discounts, payment guarantees, credit
business today relevant to your business? How muchrating, and even your company's stock price.
downtime can you afford on your network?Other expenses may include temporary employees,
Moreover, how should we be thinking about planningequipment rental, overtime costs, and related travel
for these threats to our business systems and criticalexpenses. Also, consider a damaged reputation with
data, and what steps should we be taking to protectcustomers, suppliers, financial markets, business
ourselves? As my father once told, "Preparation andpartners, and perhaps even careers lost. A survey by
planning prevent poor performance (I took the libertythe FBI and Computer Security Institute ( found that
of editing the explicative).in 2001 the financial loss due to security breaches
What is Business Continuity Planning? Businessamong 186 surveyed companies was nearly $378
continuity planning is the process whereby businessesmillion, compared to $266 million reported by 249
ensure the maintenance or recovery of operations,respondents in 2000. The average security breach
including services to customers, when confrontedcost was, therefore, approximately $2.0m in 2001, up
with adverse events such as natural disasters,from $1.0m in 2000. But this is only a fraction of the
technological failures, human error, malicious code,true cost.
viruses and/or cyber terrorism. The objectives of aAlbert Einstein once said, "Intellectuals solve problems,
business continuity plan (BCP) are to minimize financialgeniuses prevent them."
loss to the company; continue to serve customersHere are some steps to keeping your network
and mitigate the negative effects disruptions canavailable and maintaining your company's business
have on a business' strategic plans, reputation,continuity.
operations, market position, and ability to remain inTo effectively determine the specific risks to an IT
compliance with applicable laws and regulations. Insystem during service interruption, a risk assessment
order to ensure that your business remains healthyof the IT system environment is required. A
through difficult and unforeseen interruption, it is ofthorough risk assessment should identify the system
paramount importance to have robust businessvulnerabilities, threat, and current controls and
continuance plan BCP.attempt to determine the risk based on the likelihood
In the past, documents, critical data, and informationand threat impact. Because risks can vary over time
systems were largely stored and managed on paperand new risks may replace old ones as a system
and therefore the threat of a natural disaster, civilevolves, the risk management process must by
unrest, or accidental fire were the greatest problemsongoing and dynamic.
facing the secure storage of and accessibility to theConduct a DAP (Digital Asset Protection) Workshop:
systems and data vital to a business. The idea ofA DAP Workshop helps to identify and prioritize
remote pirates entering your facility through socketscritical IT systems and components. Executive
in your walls and tampering with, even interactingManagement should be involved to help identify
with information systems was an idea limited topreventive controls and review measures taken to
talking computers in Sci-Fi films. Yet the threat of areduce the effects of system disruptions that can
cyber crime attacker became a reality in due time.increase system availability and reduce contingency
From the "I Love You" virus to the "Slammer"life cycle costs.
attack, threats are quite apparently evolving fromConsider a Security Assessment which can identify
angry students torching documents on campus in thecritical systems whose loss could cause a major
60's to cyber-hackers un-leashing worms and virusesimpact to the company. This security assessment
that could compromise event the most sophisticatedprocess should be repeated on a regular basis to
networks. In the past, Barney Fife with a flashlightmaintain the health of the organization. Security
and a walkie-talkie may have sufficed for someAssessments identify threats and vulnerabilities so
businesses, but today security is an integral part ofthat appropriate controls can be put into place to
business, information, and accounting systems.either prevent incidents from happening or to limit
Today, companies increasingly depend onthe effects of an incident.
computer-supported information processing andBuild strong architecture, consider redundant
telecommunications. The increasing dependency oncommunications paths, lack of single points of failure,
computers and telecommunications for operationalenhanced fault tolerance of network components
support poses the risk that a lengthy loss of theseand interfaces, power management systems with
capabilities could seriously affect the overallappropriately sized backup power sources, load
performance of the company. Information technologybalancing, and data mirroring and replication to ensure
and automated information systems are vitala uniformly robust system
elements in most business processes. IT systems areIn conclusion, consider the evolution of security in
vulnerable to a variety of disruptions, ranging fromrelation to the evolution of car safety, in the 1950's
mild (e.g., short-term power outage, disk drive failure)they added seat belts to cars, today most cars
to severe (e.g., equipment destruction, fire) from acome standard with air-bags, anti-lock brakes,
variety of sources such as natural disasters topower-steering and other tools to help you run safely
terrorists actions, viruses, mal-ware, spy-ware andand smoothly. In fact you don't leave the house
ad-ware.planning to get in accident, but you definitely want to
Because these IT resources are so essential to anbe ready in the event of an accident. The same can
organization's success, it is critical that the servicesbe said for your business and information systems,
provided by network systems are able to operatewe do not enter the office each day planning to be
effectively without excessive interruption. Downtimeattacked and disrupted from serving our customers,
impairs productivity: Employees individual productionbut if it happens; won't you be glad that you chose
can be drastically affected, when multiplied by theto wear your seat belt? Please buckle-up and drive
number of hours out, times the burdened hourly rate;your business safely!
it can equal a huge loss for the small business and