Monday, June 11, 2007

Vital records protection

Due to the cyclone of last week I have had quite some thoughts on DRP and BCP, and concluded that the scope of this should be pretty limited. Risk management is a good way of scoping (only records unavailability that causes a high risk needs to be considered as part of the scope), but this can be a slightly too narrow approach and may lead to short term gains and longer term problems. Therefore it is important to define for a company the vital records. A simple definition is: Without these records you can close the shop. So what are the main parameters in defining vital records?
  • Legal: By law you need to have these records - usually these records are related to agreements, contracts, financial transactions and people. Quite often these records have a legal retention date (think Sarbanes-Oxley act). Obviously these records need to be properly protected. The most important (and therefore vital documents) are the ones related to major agreements. The bulk type (invoices) need less protection.
  • Asset Integrity: Records on the structure and state of maintenance (integrity) of facilities are vital for any operation. Think drawings, designs, inspections. Quite often these records need to be retained indefinitely and they require a high level of protection in terms of protection against damage or loss. Quite often they're not confidential.
  • Confidentiality: Some records in the company are company secrets that can be the differentiator for doing business (think intellectual property, major strategic documents). These records need protection both from a confidentiality and a physical protection perspective.

So what to do? I think first of all it is important to have records in an open digital format, i.e. stored on a computer and easy to open with normal desktop tools (think PDF). Paper is great to work with, but digital is the only proper backup mechanism. So if you have paper than it is important to have at least good quality scans of all vital records. The scans need to be indexed properly and need to be made available online (with sufficient security of course). Obviously some records (like facility drawings) may have a more specific format (e.g. Autocad).

Further it is important to have the digital records protected physically against any disaster (flooding, storm, fire, ...) and the easiest way to establish this is having them stored in more than one place (preferably more than two). Note that these places need to be geographically apart. In some countries companies have decided to have their information backup abroad (especially recommended for more volatile places). So if you have your records in Amsterdam (or New Orleans), than it is wise to have a backup in place in a higher place (so not next door, but say in the Alps or the Rocky Mountains).

The backups have to be made on a regular basis (daily) and more importantly: you have to test if the backup can be restored! Note that the same security measures (on accessibility) need to be in place on the backup (so confidential data is also protected in the backup site).

So bottom line: it is important to know what is vital for your business and it is important to have good protection in place for them. Not just in terms of security, but also in terms of physical protection against disasters and the best protection for the latter is replication.

Labels: , , , ,

Saturday, June 09, 2007

Managing Risks and the world of Web 2.0

Quite some time ago I wrote about Information Management that it is actually all about managing risks. And our little cyclone has reminded me of this fact. We suddenly realised that most information in the company is actually not important (or let me rephrase, not important enough for business continuity)


So a lot of what we do in Information Management is more at the 'nice to have' end of the scale of things. But having written this statement does not mean that there are some nice things about IM / Web 2.0 that are now emerging as elements that can add value in the continuity of a business or be of help during recovery from a disaster.


The Web2.0 has brought us wiki's, blogs, ... and this is how they could help:
  • Wiki's can lead to more up to date procedural information, but can also help with collecting the learnings from a disaster event. Everybody can contribute! Many people know more than a few isolated auditors

  • Blogs can help during the disaster to share news and bring people up to date on the status of services and other things. I noticed for instance that AP, the news agency has started to use pictures from Bloggers in their news coverage. Mobile blogging is also possible, so why not use your phone for things like this?

  • The free online storage spaces for content (pictures, movies, but also documents etc) can act as a temporary business continuity site when your own services are down

But having these things playing a more vital role means that these Internet based services become more vital and therefore become part of the DRP/BCP (disaster recovery planning and business continuity planning). That's a way to become important!

So the infrastructure side of things needs a possible rethink as well. Usually data centers are setup as a single point of failure and having the Internet as a vital piece of communication technology does not allow for single points of failure. So setting up the companies infrastructure as a set of networked nodes is a model worth considering as well.

Labels: , , ,

Thursday, September 28, 2006

Managing Risk

Information Management (IM) is in the first place risk management. If there was no risk related to the information, then there is no reason to manage it. Making clear that IM is related to risks already will make it more likely that people change their behaviours with respect to information.

So one of the first measures to take in IM is to understand 'where do we feel the heat'. Only where there is heat, we should take measures, because putting a 50,000 dollar fence around a 5,000 dollar horse does not make sense.

So step 1. is: Understand what is valuable information

Step 2. is to understand where there are risks - think risks related confidentiality, integrity (quality) of the information, accessibility or legal issues

These risks can relate to all steps in the whole lifecycle of the information (during the steps when information is Created or acquired, QC-ed and stored, retrieved and used, reviewed and
disposed.

Then step 3. is to think about the impacts of these risks (financially, HSE, reputation, ... ) and the likelihood of occurence.

And finally you can check what controls are already in place to deal with these risks and see if they are sufficient.

This whole process looks like a pretty elaborate piece of work and the truth is - it is! Please note that when you get a consultant in, then you will a lot more elaborate version of this based on the internation standard from COBIT. I would say - don't even try to implement this, since your business will be broke before you have read all the recommendations.

But if you focus on the top valuable information and the top risks (highest impact), then you can create a pretty good story on what needs to be done to manage this information - with a clear link of running your business.

Labels: ,