The key to surviving an IT-disabling disaster is a business continuity strategy, a set of policies and procedures for reacting to and recovering from such an event, and the main component of a business continuity strategy is a disaster recovery plan.
What would you do if a storm flooded your data center? Or how would you respond if a power outage blacked out your servers? How would you recover your data and keep the business running after an unforeseen disaster? When disasters strike unprepared companies the consequences range from prolonged system downtime and the resulting revenue loss to the companies going out of business completely. Yet many IT organizations don't have the business continuity strategy in place to deal with such scenarios.
Towards a Business Continuity Strategy
In this article, DevX and Cole Emerson, President of Cole Emerson & Associates, Inc., a business continuity consulting firm, and chairman of the board of DRI International, administrators of a global certification program for business continuity/disaster recovery planners, walk through the basics of creating an effective disaster recovery plan.
Step 1 of Disaster Recovery Planning: Risk Analysis
The first step in drafting a disaster recovery plan is conducting a thorough risk analysis of your computer systems. List all the possible risks that threaten system uptime and evaluate how imminent they are in your particular IT shop. Anything that can cause a system outage is a threat, from relatively common manmade threats like virus attacks and accidental data deletions to more rare natural threats like floods and fires. Determine which of your threats are the most likely to occur and prioritize them using a simple system: rank each threat in two important categories, probability and impact. In each category, rate the risks as low, medium, or high.
For example, a small Internet company (less than 50 employees) located in California could rate an earthquake threat as medium probability and high impact, while the threat of utility failure due to a power outage could rate high probability and high impact. So in this company's risk analysis, a power outage would be a higher risk than an earthquake and would therefore be a higher priority in the disaster recovery plan.