|
Disaster
Recovery Policy Statement
Disaster
recovery policy statement must be formulated and issued by the
senior management, to the organization which gives clear guidance on
the goals and objectives of the organization in the event of a
disaster.
Disaster
recovery policy statement -
minimum
At the bare minimum,
this statement must contain the following instructions:
- The organization
must develop a comprehensive Business Continuity strategy which
includes at least one disaster recovery plan.
- A formal Business
Impact Analysis must be undertaken in order to determine the
requirements for the disaster recovery
plan.
- A formal risk
assessment must be undertaken in order to determine the impact on
the organization in the event of loss of one or multiple systems.
- The disaster
recovery plan must be periodically tested in a simulated
environment to ensure that it can be implemented in emergency
situations and that the management and staff understand how it is
to be executed. After staged tests we must give thought to the
conduct of a full (unrehearsed or forewarned
test).
- The disaster
recovery plan must cover all essential and critical business
activities.
- The disaster
recovery plan is to be kept up to date to take into account
changing circumstances.
- All staff must be
made aware of the disaster recovery plan and their own roles
within.
A similar policy
statement to this must be communicated to all management and staff
as part of its information security policy management process.
Explore the Disaster Recovery
Toolkit
Contains 18 ready to use templates for successful
Disaster Recovery Planning / IT Service Continuity
Management
|