{"id":490634,"date":"2010-03-30T16:19:00","date_gmt":"2010-03-30T20:19:00","guid":{"rendered":"tag:blogger.com,1999:blog-7196788127833928948.post-8179224524247156699"},"modified":"2010-03-30T16:19:00","modified_gmt":"2010-03-30T20:19:00","slug":"mitigating-risks-of-the-it-disaster-recovery-test","status":"publish","type":"post","link":"https:\/\/mereja.media\/index\/490634","title":{"rendered":"Mitigating Risks of the IT Disaster Recovery Test"},"content":{"rendered":"<p>The IT Disaster Recovery Test as part of the Business Continuity testing is becoming an annual event for most IT departments. It is mandated by a lot of regulators, nearly insisted upon by internal audit and ofcourse a very healthy thing to do.<\/p>\n<p>But performing the IT DRP test without proper risk management can put your organization at significant risk.<\/p>\n<p><a onblur=\"try {parent.deselectBloggerImageGracefully();} catch(e) {}\" href=\"http:\/\/1.bp.blogspot.com\/_Hu1rpxRsqcU\/S7JlGB1EupI\/AAAAAAAAAg4\/R3iG0RkeCns\/s1600\/1017jpg.jpg\"><img decoding=\"async\" style=\"display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 200px; height: 178px;\" src=\"http:\/\/1.bp.blogspot.com\/_Hu1rpxRsqcU\/S7JlGB1EupI\/AAAAAAAAAg4\/R3iG0RkeCns\/s200\/1017jpg.jpg\" alt=\"\" id=\"BLOGGER_PHOTO_ID_5454533252943755922\" border=\"0\" \/><\/a><br \/>To put things into perspective, let&#8217;s analyze the steps, risks and countermeasures of an IT Disaster Recovery test:<br \/><center><\/p>\n<table width=\"90%\" border=\"1\" bordercolor=\"#000000\" cellpadding=\"0\" cellspacing=\"0\">\n<tbody>\n<tr style=\"font-weight: bold;\">\n<td>DRP Test Step<\/td>\n<td>Activity<\/td>\n<td>Risks<\/td>\n<td>Countermeasures<\/td>\n<\/tr>\n<tr>\n<td>1. Failure of primary systems<\/td>\n<td>In order to perform a disaster situation, the Primary systems need to be caused to fail on some level<\/td>\n<td>\n<ol>\n<li>Databases not closed properly\/damaged due to forced shutdown or forced power failure<\/li>\n<li>Hardware components failing due to forced shutdown or power failure<\/li>\n<li>Spilt-brain cluster due to uncontrolled sequence of failures of servers and storage<\/li>\n<\/ol>\n<\/td>\n<td>\n<ol>\n<li>Full backup prior to the initiation of the DRP test<\/li>\n<li>Backup components and Vendor presence at ready during the entire test.<\/li>\n<li>Not performing a direct forced shutdown but forcing a network level isolation at the routers<\/li>\n<\/ol>\n<\/td>\n<\/tr>\n<tr>\n<td>2. Activation of Disaster Recovery systems<\/td>\n<td>Severing any relation between the DR and the primary systems and running the DR systems as temporary primary<\/td>\n<td>\n<ol>\n<li>Actual failure of primary system during the test<\/li>\n<li>Failure of the primary system while the DR system is concluded to be non-functional<\/li>\n<\/ol>\n<\/td>\n<td>\n<ol>\n<li>Full awareness of the test of every interested party &#8211; business  custodians, directors of divisions and top management to initiate the real Business Continuity Plan<\/li>\n<li>Full backup prior to the initiation of the DRP test at DRP site,  and full vendor support.<\/li>\n<\/ol>\n<\/td>\n<\/tr>\n<tr>\n<td>3. Reconfiguring the user environment<\/td>\n<td>Intervening in the end-user environment in a way that will make them use the DR system<\/td>\n<td>\n<ol>\n<li>Error in reconfiguration which may cause the end-user to input test data into the primary systems<\/li>\n<li>Error in reconfiguration which may cause the primary system to stop functioning.<\/li>\n<\/ol>\n<\/td>\n<td>\n<ol>\n<li>, 2. Scripted and documented steps of reconfiguration. All steps should be performed by 2 persons &#8211; one observing the others actions<\/li>\n<\/ol>\n<\/td>\n<\/tr>\n<tr>\n<td>4. Reverting to the primary systems<\/td>\n<td>Resuming the primary systems at some level and reestablishing the relation between the DR and the primary systems<\/td>\n<td>\n<ol>\n<li>Error in reconfiguration which may cause the primary system to stop  functioning.<\/li>\n<li>Copying of test data that was input into the DR test system back into the primary location3. Failure of primary systems during resumption<\/li>\n<\/ol>\n<\/td>\n<td>\n<ol>\n<li>Scripted and documented steps of reconfiguration. All steps should  be performed by 2 persons &#8211; one observing the others actions.<\/li>\n<li>Fully controlled and documented process of resumption, which guarantees that only the primary system is data master.<\/li>\n<li>Full backup prior to the initiation of the DRP test, Backup components and Vendor presence at ready during the entire  test.<\/li>\n<\/ol>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><\/center><\/p>\n<p><span style=\"font-weight: bold; font-style: italic;\">With all these risks, is it more prudent to never perform an IT DRP test? &#8211; Absolutely NOT, and here is why:<\/span><\/p>\n<ul>\n<li style=\"font-style: italic;\">Performing the IT DRP test actually confirms that things are running, and if something breaks, you are much more prepared for the next time.<\/li>\n<li><span style=\"font-style: italic;\">Not performing the test will just make you think everything is great, until the incident occurs. And the incident is just as certain as death and taxes<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: bold; font-style: italic;\">So, perform the IT DRP test regularly, but with a whole set of countermeasures for the possible risks which can happen during the test. Of course you will miss some risks, but if you plan for 10 and miss 1 is much better then not planning at all<\/span>!<\/p>\n<p>Talkback and comments are most welcome<\/p>\n<p>Related posts<br \/><a href=\"http:\/\/www.shortinfosec.net\/2008\/08\/iphone-failed-disaster-recovery.html\">iPhone  Failed &#8211; Disaster Recovery Practical Insight<\/a><br \/><a href=\"http:\/\/www.shortinfosec.net\/2008\/08\/business-continuity-analysis.html\">Business  Continuity Analysis &#8211; Communication During Power Failure<\/a><br \/><a href=\"http:\/\/www.shortinfosec.net\/2008\/07\/business-continuity-plan-for-brick.html\">Business  Continuity Plan for Brick &amp; Mortar Businesses<\/a><br \/><a href=\"http:\/\/www.shortinfosec.net\/2008\/07\/example-business-continuity-plan-for.html\">Example  Business Continuity Plan For Online Business<\/a><\/p>\n<div class=\"blogger-post-footer\"><img width='1' height='1' src='https:\/\/blogger.googleusercontent.com\/tracker\/7196788127833928948-8179224524247156699?l=www.shortinfosec.net' alt='' \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~r\/shortinfosec\/~4\/9_RVa59DbcU\" height=\"1\" width=\"1\"\/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The IT Disaster Recovery Test as part of the Business Continuity testing is becoming an annual event for most IT departments. It is mandated by a lot of regulators, nearly insisted upon by internal audit and ofcourse a very healthy thing to do. But performing the IT DRP test without proper risk management can put [&hellip;]<\/p>\n","protected":false},"author":5679,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-490634","post","type-post","status-publish","format-standard","hentry","category-news"],"_links":{"self":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/posts\/490634","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/users\/5679"}],"replies":[{"embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/comments?post=490634"}],"version-history":[{"count":0,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/posts\/490634\/revisions"}],"wp:attachment":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/media?parent=490634"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/categories?post=490634"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/tags?post=490634"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}