In addition to developing a test plan to ensure the effectiveness of your DRP, it is necessary to develop an audit procedure to survey the plan for its effectiveness. The audit process ensures that the plan is adequate as well as current.
The effectiveness of a Disaster Recovery Plan is diminished by changes in the environment that the plan was created to protect. These changes can take many forms. The following are some major factors that tend to reduce the plan’s effectiveness:
- Equipment Acquisition -- Such changes should lead to a re-evaluation of the risk-analysis planning done for previous configurations.
To ensure your plan is still adequate, thorough testing and auditing of the plan should be made to accommodate and verify that your plan still works in these ever-changing environments.
- Staff Changes -- The skills of the Information Systems and Business Units staff is constantly changing.
As part of ongoing business operations, new positions are created, others are eliminated and the people that staff these positions are also subject to movement both within and outside the organization. The audit should ensure that any changes in key positions or names which are in the plan are highlighted and brought to the attention of appropriate management.
- Shifting Processing Priorities -- As the workload of the Information Systems Facility shifts, the protection and recovery requirements in the plan might change significantly.
Fortunately, an audit and review of processing priorities should highlight these types of changes.
- Increasing Application Complexity -- As an application matures and work units or company processes become increasingly dependent on an automated process, some backup procedures (particularly manual ones) are no longer feasible.
- Legislation Changes -- There is an increasing demand brought on by legislation for information retention both internally and externally. The disaster recovery effort must address these issues.
The audit should be an independent and objective appraisal of the Disaster Recovery Plan for both the Data Center and Business Units as time, technology and logistics change. The audit process should be expected to accomplish the following:
Expected Outcome
- Identify and evaluate security controls (both physical and data)
- Inventory of critical assets
- Calculation of risk
- Provide management an opportunity to improve and update the plan
- Provide a stimulus to keep management from becoming complacent
- Uncover areas of vulnerability as they relate to management planning, controls and information security, etc.
- Classification of severity of findings
- Remediation recommendations
- Provide management with an evaluation of the enterprise’s preparedness in the event of a major business disruption
- Identify issues that may limit interim business processing and restoration of the same
- Benchmark analysis of results vs industry
- Cost-benefit analysis of risk remediation efforts
Factors to consider when determining frequency include the following
- Rate of change in the Information Systems Facility (vendor and own site)
- Frequency of other audits
- Number and Size of Mission Critical Systems
- Number of problems that occur while testing the plan
- Level of outside threat to the operation
- Frequency of Changes in regulations