Expert Advice Community

Guest

Activity Recovery Strategy and Plan

  Quote
Guest
Guest user Created:   Nov 28, 2017 Last commented:   Nov 28, 2017

Activity Recovery Strategy and Plan

I am for the first time using your two templates that deal with these two areas of developing the plans. Both of these deal with each and every activity individually. It seems a lot of documents a lot of detail and I am wandering what the reason may be. With the kind of solutions around today where virtualization, replication, warm sites etc. recovery of ICT is almost a matter of flicking a switch. I am busy with a very large client with a complex environment and can see the need. I also recently did a small client with a simple environment where ICT is replicated at the alternate site, switched over and users are able to work, we have Simplicity in between. The need for individual focus in this way was not necessary so strategy and plan was one document. This could apply equally to a large environment if they choose such a solution.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Nov 28, 2017

Answer: The templates are designed this way so they can cover situations where an organization, for whatever reason, decides not to adopt such "flicking a switch" solutions, and thus it has to develop detailed p rocedures, but the templates are fully editable, and you can alter or delete sections you deem as unnecessary.

Considering the scenario you described, you may simplify or delete:
- sections 2, 3 and 4 from Activity Recovery Strategy Template.
- sections 3, 5 and 6 from Activity Recovery Plan Template

For these sections you may change the content for a single paragraph providing a general overview of the necessary steps.

Additionally, by your description you are considering ICT core infrastructure only, but you also have to consider situations where ICT recovery is needed when the work site is made unavailable (and you need to relocate personnel to other sites), or the ICT in that site is affected and the site is unable to communicate with the central ICT infrastructure (even warm sites require some activities to be performed to become fully operational).

This article will provide you further explanation about ICT recovery:
- Understanding IT disaster recovery according to ISO 27031 https://advisera.com/27001academy/blog/2015/09/21/understanding-it-disaster-recovery-according-to-iso-27031/

This material will also help you regarding business recovery:
- Book Becoming Resilient: The Definitive Guide to ISO 22301 Implementation https://advisera.com/books/becoming-resilient-the-definitive-guide-to-iso-22301-implementation/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Nov 28, 2017

Nov 28, 2017

Suggested Topics

Guest post Created:   Jan 12, 2016 ISO 27001 & 22301
Replies: 0
0 0

What RTO means ?