Top Banner
© 2018 MHA CONSULTING. ALL RIGHTS RESERVED. THE BIA FROM THE IT PERSPECTIVE Michael Herrera, CEO, MHA Consulting March 25, 2018
39

THE BIA FROM THE IT PERSPECTIVE · 2021. 1. 5. · HOW IT CAN MAKE THE BIA A SUCCESS FOR ITSELF, BCM, AND THE BUSINESS. Be transparent when it comes to system/application RTAs, RPAs,

Mar 04, 2021

Download

Documents

dariahiddleston
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED.

    THE BIA FROM THE IT PERSPECTIVEMichael Herrera, CEO, MHA Consulting

    March 25, 2018

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 2

    19-year proven track record of

    applying industry standards and

    best practices across a diverse

    pedigree of clients.

    A simple mission: Ensure the

    continuous operations of our

    clients’ critical processes.

    SaaS Tools: BIA On-Demand,

    Compliance Confidence,

    Residual Risk.

    SAASCompliance

    and risk tools.

    CAPABLEComprehensive suite of services.

    20Average years

    industry experience.Years in

    operation.

    GLOBALDiverse, global

    client base.

    19

    Michael A. Herrera, CBCP Chief Executive OfficerPhoenix, Arizona www.mha-it.comhttps://bcmmetrics.com/

    KEY FACTS

    SENIOR LEADERSHIP

    MHA Consulting’s senior team has an average of over 20 years of industry relevant experience in the areas of Business Continuity, Disaster Recovery, and Project Management.

    COMPANY BACKGROUND

    http://www.mha-it.com/https://bcmmetrics.com/

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 3

    HEALTHCARE EDUCATION FINANCIAL INSTITUTIONS

    CONSUMER PRODUCTS INSURANCE TRAVEL & ENTERTAINMENT GOVERNMENT/UTILITY

    SERVICES

    DIVERSE, GLOBAL CLIENT BASE

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 4

    Business Recovery Strategies & Solutions

    Data Center Recovery Strategies

    Current State Assessment

    Policy & Standards

    Business Impact Analysis

    Threat & Risk Assessment

    BCMMETRICSTM

    BIA On-Demand (BIAOD)

    BCMMETRICSTM

    Compliance Confidence (C2)

    BCMMETRICSTM

    Residual Risk (R2)

    Training & Awareness

    Mock Disaster Exercises

    Plan Functional Walkthroughs

    Alternate Worksite Exercises

    Crisis Management

    Business Recovery

    IT Disaster Recovery

    Update Recovery Plans

    Update Current State Assessment

    Update Business Impact Analysis & Threat Assessment

    Third Party Assessments

    EXERCISES MAINTAIN & IMPROVEASSESS THE CURRENT

    ENVIRONMENTRECOVERY STRATEGIES &

    SOLUTIONSRESPONSE & RECOVERY

    PLANS

    ROBUST SUITE OF SERVICES

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED.

    AGENDA

    5

    • How to use what you learn about enterprise operations and what concerns your business partners.

    • How to examine and understand the business rationalization for RTOs and RPOs.

    • How to explore how business needs are (or are not) being met by IT.

    • Identify and explain any technical limitations to meeting the desired RTOs and RPOs.

    • How to align business needs and IT DR strategies/solutions.

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 6

    • Identifies impacts to the company if a business process cannot be performed over time.

    • It’s a point in time snapshot of the relative criticality of business processes and their dependent

    systems/applications.

    • Results drive recovery strategies/solutions and plan development for the business, IT, and critical

    3rd parties.

    WHAT IS A BIA?

    ABIA

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 7

    I n f o r m a l B I A s :

    WHAT IS A BIA?

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 8

    Is IT a key member of your BIA team?

    Who is starting or has started a BIA?

    Is IT educated on how the BIA works?

    Does IT fear the results of the BIA? Do you understand the current DR capability?

    Are there competing RTO matrices (e.g., BCM vs. IT)?

    Is IT transparent in its data and information?

    QUICK SURVEY

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 9

    Takes too much of their time.

    No seat at the table to help design it.

    Forced on them versus a joint venture.

    Don’t understand how it works.

    Done this before and nothing changes.

    WHY IT DISLIKES THE BIA

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 10

    Business doesn’t understand the ramifications.

    Lacks senior management approval.

    The business wants What????? When???

    We won’t or will never be able to do what they want.

    We already have a DR strategy/ RTOS/RPOs.

    WHY IT DISLIKES THE BIA

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 11

    I N F O R M A L B I A s

    IT has completed its own informal BIA using its best educated guess/experience.

    IT sets RTOs and RPOs, and builds/implements recovery strategies/solutions that

    do one of the following:

    • Meet or well exceed business recovery needs,

    • Are out of alignment with business needs, or

    • Have limited capability.

    WHAT WE OFTEN FIND

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 12

    BCM, IT, and the business work together.

    05 BIA is efficient and effective.01

    02

    03

    04

    Participants educated in the process.

    BIA is configured to get the right results.

    Clear understanding of IT DR capabilities.

    BIA-derived RTOs and RPOs make sense.06

    07 Management reviews and signs off on results to implement.

    CHARACTERISTICS OF A BEST OF CLASS BIA

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 13

    R T O / R T A R P O / R P A

    Recovery Time Objective

    • Desired state – business

    requirements.

    Recovery Time Actual

    • Current capability provided by IT.

    Recovery Point Objective

    • Desired state – business

    requirements.

    Recovery Point Actual

    • Current capability provided by IT.

    KEY TERMS

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 14

    HOW IT CAN MAKE THE BIA A SUCCESS FOR

    ITSELF, BCM, AND THE BUSINESS

    Do not fear the results. 01Provide resources to participate in the BIA.02

    Participate in the setup, pre-work and interviews.03BIA

    SUCCESS Educate BCM and the business on the current DR capabilities in terms they understand.

    04

    Provide a current systems/application inventory.

    05

    Help define a common RTO and RPO matrix for the business and IT.

    06

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 15

    HOW IT CAN MAKE THE BIA A SUCCESS FOR

    ITSELF, BCM, AND THE BUSINESS

    Be transparent when it comes to system/application RTAs, RPAs, etc. 07

    Talk in business process speak to the business versus IT speak.08

    Align the results with current DR capabilities.09BIA

    SUCCESS Ask BCM for the right reports from the BIA to drive their strategies and plans.

    10

    Use the BIA results to optimize DR strategy/solutions, roadmap, and budget.

    11

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 16

    I T A N D B C M W O R K A S O N E

    • IT provides resources that not only understand the business and its processes but they can

    translate it to the systems/applications technology.

    • IT resources are educated in the BCM and BIA processes and how those integrate with their

    DR capabilities.

    • BCM personnel are educated in the current IT DR process and understand its capabilities to

    recover the critical systems/applications.

    • BCM and IT work as a team throughout the BIA process.

    THE RIGHT RESOURCES

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 17

    IT provides input to and helps BCM establish appropriate RTO/RPO categories that make sense for the company and its mission.

    IT provides an up-to-date system and application inventory.

    If RTO/RPO categories already exist for BCM and/or IT, they agree on a common approach that works.

    IT helps determine what system/ application information needs to be gathered in the BIA.

    IT understands how the BIA tool will calculate the RTOs for the systems/applications.

    Agree on what the BIA results will mean to current and future IT recovery strategies/solutions.

    THE SETUP

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 18

    I n f o r m a l B I A s :

    THE SETUP - IMPACTS

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 19

    I n f o r m a l B I A s :

    THE SETUP – IMPACT RANGES

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 20

    What do you provide as recovery capabilities today? Do you have workarounds? Offline processing?

    What is the soonest you believe business processes and systems/applications need to be up? Do you have current RTOs/RPOs?

    Are you highly regulated or required contractually to

    meet specific recovery timelines?

    What is the mission (banking, healthcare, retail, etc.) of

    your company?

    What have you learned in past outages when business processes or systems/apps were really needed?

    CONSIDERATIONS FOR RTOs/RPOs

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 21

    THE SETUP – RTO & RPO CATEGORIES

    Recovery Time Objective is a measure of how fast you want your emergency system to be up and running.

    Recovery Point Objective is a measure of how much data you believe you can afford to lose.

    Recovery Service Level is a measure of what kind of computing needs are required in an emergency situation.

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 22

    I n f o r m a l B I A s :

    THE SETUP – RTO CATEGORIES

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 23

    I n f o r m a l B I A s :

    THE SETUP – RPO CATEGORIES

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 24

    I n f o r m a l B I A s :

    THE SETUP – SYSTEMS/APPS LIST

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 25

    I n f o r m a l B I A s :

    THE SETUP – SYSTEMS/APPS LIST

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 26

    Be prepared to discuss current DR strategies with the business units.

    Come prepared to provide input to the business units on

    their technology needs during the interviews.

    Not afraid to push back if the RTO/RPO results don’t make sense.

    Agree on the final BIA-derived results for the business unit.

    Participate in all of the BIA interviews (or at least the critical ones).

    INTERVIEWS

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 27

    INTERVIEWS

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 28

    I T A N A L Y Z E S R E S U L T S W I T H B C M

    Participate in the analysis of the BIA results with the BCM Office and the prioritization

    of systems and applications:

    • Internally hosted systems RTOs & RPOs

    • Externally hosted systems RTOs & RPOs

    DATA ANALYSIS

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 29

    DATA ANALYSIS

    Sheet

    Department System/Application RTO/RPO (Internal)

    Company: ATS TestDivision: Information TechnologyDepartment: All DepartmentsInterview Date: 02/17/2016 - 03/19/2018

    Department NameProcess NameSystem/Appl NameRTORPO

    Corporate - Physical SecurityPhysical Security System 24x7 Monitoring & ReportingS-2 SecurityRTO 0RPO 0: 4 Hours Maximum Permanent Data Loss

    Corporate - Procurement & Supply ChainInventory ManagementIMSRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Corporate - Procurement & Supply ChainLogisticsIMSRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Corporate - Procurement & Supply ChainPlanningIMSRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Corporate - Procurement & Supply ChainProcurementIMSRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Corporate Finance & AccountingAccountingAsteaRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Corporate Finance & AccountingAccountingBPARTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Corporate Finance & AccountingAccountingGreat PlainsRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Corporate Finance & AccountingAccountingIMSRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Corporate Finance & AccountingAccountingManagement ReporterRTO 4N/A

    Corporate Finance & AccountingAccountingSmartConnectRTO 4N/A

    Corporate Finance & AccountingAccountingWorkplaceRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Corporate Finance & AccountingFinancial Planning and ReportingGreat PlainsRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Corporate Finance & AccountingPayrollGreat PlainsRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Corporate Finance & AccountingTreasuryAxsisRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Corporate Finance & AccountingTreasuryBPARTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Corporate Finance & AccountingTreasuryGreat PlainsRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Corporate Finance & AccountingTreasuryPlatepassRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Corporate Finance & AccountingTreasuryReporting ServicesRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Corporate Finance & AccountingTreasuryVMSRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Account ManagementCustomer ReportingBPARTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Account ManagementCustomer ReportingFile Shares (DFS, ATSFS02)RTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Account ManagementCustomer ReportingPlatepassRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Account ManagementCustomer ReportingReportingRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Account ManagementCustomer ReportingUser ManagerRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Account ManagementCustomer ReportingViologicsRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Account ManagementLaunch New FleetsBPARTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Account ManagementLaunch New FleetsFile Shares (DFS, ATSFS02)RTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Fleet - Account ManagementLaunch New FleetsPlatepassRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Account ManagementLaunch New FleetsReportingRTO 4N/A

    Fleet - Account ManagementLaunch New FleetsUser ManagerRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Fleet - Account ManagementLaunch New FleetsViologicsRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Contact CenterCall CenterBPARTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Contact CenterCall CenterPlatepassRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Contact CenterCall CenterUser ManagerRTO 2RPO 3: >24 Hours Maximum Permanent Data Loss

    Fleet - Contact CenterCall CenterViologicsRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Contact CenterInteractive Voice Response (IVR)BPARTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Contact CenterInteractive Voice Response (IVR)PlatepassRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Contact CenterInteractive Voice Response (IVR)ViologicsRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Contact CenterResearchBPARTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Contact CenterResearchFile Shares (DFS, ATSFS02)RTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Fleet - Contact CenterResearchPlatepassRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Contact CenterResearchUser ManagerRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Fleet - Contact CenterResearchViologicsRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - FinanceFinancial Planning and ForecastingBPARTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - FinanceFinancial Planning and ForecastingCorporate File ServersRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Fleet - FinanceFinancial Planning and ForecastingPlatepassRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - FinanceFinancial Planning and ForecastingReportingRTO 4N/A

    Fleet - FinanceFinancial Planning and ForecastingUser ManagerRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Fleet - FinanceFinancial Planning and ForecastingVena Forecasting and WorkflowRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - FinanceFinancial Planning and ForecastingViologicsRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - FinanceReportingBPARTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - FinanceReportingCorporate File ServersRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - FinanceReportingGreat PlainsRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Fleet - FinanceReportingPlatepassRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - FinanceReportingReportingRTO 4N/A

    Fleet - FinanceReportingUser managerRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Fleet - FinanceReportingViologicsRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - FinanceSettlement/InvoicingBPARTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - FinanceSettlement/InvoicingCorporate File ServersRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Fleet - FinanceSettlement/InvoicingGreat PlainsRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - FinanceSettlement/InvoicingPlatepassRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - FinanceSettlement/InvoicingReportingRTO 4N/A

    Fleet - FinanceSettlement/InvoicingUser ManagerRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Fleet - FinanceSettlement/InvoicingViologicsRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Information TechnologyApplication Support2nd Rock SSRSRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Fleet - Information TechnologyApplication SupportBPARTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Information TechnologyApplication SupportCredit Card ApplicationRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Information TechnologyApplication SupportFile Shares (DFS, ATSFS02, Isilon)RTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Fleet - Information TechnologyApplication SupportFIS ApplicationRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Information TechnologyApplication SupportFMS ApplicationRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Information TechnologyApplication SupportPCI virtual desktop (Credit Card system troubleshooting)RTO 4N/A

    Fleet - Information TechnologyApplication SupportPlatepassRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Information TechnologyApplication SupportReportingRTO 4N/A

    Fleet - Information TechnologyApplication SupportSupport Job SchedulerRTO 4N/A

    Fleet - Information TechnologyApplication SupportToll Authority Screen Scrape ApplicationRTO 4N/A

    Fleet - Information TechnologyApplication Supportuser ManagerRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Fleet - Information TechnologyApplication SupportViologicsRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Information TechnologyApplication SupportWheels MacroRTO 4N/A

    Fleet - Information TechnologySoftware Development2nd Rock SSRS ReportingRTO 4N/A

    Fleet - Information TechnologySoftware DevelopmentABBYY Optical Character RecognitionRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Information TechnologySoftware DevelopmentBPARTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Information TechnologySoftware DevelopmentCredit Card ApplicationRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Information TechnologySoftware DevelopmentCrystal ReportsRTO 4N/A

    Fleet - Information TechnologySoftware DevelopmentEmail Service (iMail)RTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Fleet - Information TechnologySoftware DevelopmentFile Shares (DFS, ATSFS02, Isilon)RTO 4RPO 1: 12 Hours Maximum Permanent Data Loss

    Fleet - Information TechnologySoftware DevelopmentFISRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Information TechnologySoftware DevelopmentFMSRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Information TechnologySoftware DevelopmentFMS Membership ServiceRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Information TechnologySoftware DevelopmentFTPRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Information TechnologySoftware DevelopmentInterface ProcessorRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Fleet - Information TechnologySoftware DevelopmentJAMSRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Fleet - Information TechnologySoftware DevelopmentPlatepassRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Information TechnologySoftware DevelopmentSubversionRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Fleet - Information TechnologySoftware DevelopmentTeam CityRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Fleet - Information TechnologySoftware DevelopmentToll Authority Screen Scrape ApplicationRTO 4N/A

    Fleet - Information TechnologySoftware DevelopmentUser ManagerRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Fleet - Information TechnologySoftware DevelopmentViologicsRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - OperationsAutoexpresso Auto-AppealPlatepassRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - OperationsBATA Transponder ProcessPlatepassRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - OperationsException Processing & Research2nd Rock SSRS ReportingRTO 4N/A

    Fleet - OperationsException Processing & ResearchCorporate File Servers (DFS, ATSFS02)RTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - OperationsException Processing & ResearchPlatepassRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - OperationsException Processing & ResearchUser ManagerRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - OperationsException Processing & ResearchViologicsRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - OperationsFulfillmentCorporate File Servers (DFS, ATSFS02)RTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - OperationsFulfillmentFMSRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Fleet - OperationsFulfillmentPlatepassRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - OperationsHertz Transponder Deactivation, EZSPassPlatepassRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - OperationsIL Apportioned PlatesBusiness Developed MacroRTO 4N/A

    Fleet - OperationsIL Apportioned PlatesPlatepassRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - OperationsIL Apportioned PlatesViologicsRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - OperationsNon-IT Supported Software ApplicationsEnrollment EstimatesRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Fleet - OperationsNon-IT Supported Software ApplicationsJCI paper invoicesRTO 4N/A

    Fleet - OperationsNon-IT Supported Software ApplicationsLast known locationRTO 4N/A

    Fleet - OperationsNon-IT Supported Software ApplicationsNot FVO plate reportRTO 4N/A

    Fleet - OperationsNon-IT Supported Software ApplicationsNYC AdjuducationRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - OperationsNon-IT Supported Software ApplicationsPuerto Rico plate processingRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Fleet - OperationsNon-IT Supported Software ApplicationsRyder BillingRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - OperationsNon-IT Supported Software ApplicationsTolerance reportRTO 4N/A

    Fleet - OperationsNon-IT Supported Software ApplicationsTransponder fulfillmentRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Fleet - OperationsNon-IT Supported Software ApplicationsWheels Error reportingRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Fleet - OperationsPlatepass OperationsCorporate File Servers (DFS, ATSFS02, Isilon)RTO 4RPO 1: 12 Hours Maximum Permanent Data Loss

    Fleet - OperationsPlatepass OperationsCredit card applicationRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - OperationsPlatepass OperationsEmail Service (iMail)RTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Fleet - OperationsPlatepass OperationsFISRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - OperationsPlatepass OperationsFMSRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - OperationsPlatepass OperationsFMS Membership ServicesRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - OperationsPlatepass OperationsFTPRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - OperationsPlatepass OperationsGARRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - OperationsPlatepass OperationsInterface processorRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Fleet - OperationsPlatepass OperationsPlatepassRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - OperationsPlatepass OperationsReportingRTO 4N/A

    Fleet - OperationsPlatepass OperationsToll Authority Screen ScrapeRTO 4N/A

    Fleet - OperationsPlatepass OperationsUser ManagerRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Fleet - OperationsPlatepass OperationsViologicsRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - OperationsToll Account ReplenishmentPlatepassRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - OperationsViolation ProcessingAdhoc ReportingRTO 3N/A

    Fleet - OperationsViolation ProcessingBatch CreationRTO 3RPO 2: 24 Hours Maximum Permanent Data Loss

    Fleet - OperationsViolation ProcessingCorporate File Servers (DFS, ATSFS02)RTO 3RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - OperationsViolation ProcessingOCR SoftwareRTO 3RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - OperationsViolation ProcessingUser ManagerRTO 3RPO 3: >24 Hours Maximum Permanent Data Loss

    Fleet - OperationsViolation ProcessingViologicsRTO 3RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Product ManagementAnalysisCorporate File Servers (DFS, ATSFS02)RTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Fleet - Product ManagementAnalysisiFACS SummaryRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Product ManagementAnalysisPlatepassRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Product ManagementAnalysisUser ManagerRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Product ManagementAnalysisViologicsRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Product ManagementCheck Processing2nd Rock SSRS ReportingRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Product ManagementCheck ProcessingCorporate File Servers (DFS, ATSFS02)RTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Fleet - Product ManagementCheck ProcessingUser ManagerRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Fleet - Product ManagementCheck ProcessingViologicsRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Product ManagementElectronic Integrations2nd Rock SSRS ReportingRTO 4N/A

    Fleet - Product ManagementElectronic IntegrationsCorporate File Servers (DFS, ATSFS02)RTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Product ManagementElectronic IntegrationsiFACS SummaryRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Fleet - Product ManagementElectronic IntegrationsUser ManagerRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Fleet - Product ManagementElectronic IntegrationsViologicsRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - RTL Customer ServiceCall CenterRES PortalRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Fleet - RTL Customer ServiceCall CenterToll Roads PortalRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Fleet - RTL Customer ServiceChargebacksQuickBase DatabaseRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Fleet - RTL Customer ServiceChargebacksRES PortalRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Fleet - RTL Customer ServiceDisputes and ResearchRES PortalRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Fleet - RTL Customer ServiceInvoice PaymentHarris Bank Check Deposit SoftwareRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Fleet - RTL Customer ServiceInvoice PaymentRES PortalRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Fleet - RTL Customer ServiceToll Tag ManagementRES PortalRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Fleet - RTL Customer ServiceToll Tag ManagementRES Ticketing WebsiteRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - RTL Information TechnologyApplication SupportRES TicketRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - RTL Information TechnologyFMC InterfaceFile Magic Job ProcessingRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Fleet - RTL Information TechnologyFMC InterfaceIPSWITCHRTO 4RPO 1: 12 Hours Maximum Permanent Data Loss

    Fleet - RTL Information TechnologyFMC InterfaceSQL Job ProcessingRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Fleet - RTL Information TechnologyFMC InterfaceSQL ServerRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Fleet - RTL Information TechnologyRental Agency Car CustomersFile Magic Job ProcessingRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - RTL Information TechnologyRental Agency Car CustomersIPSWITCHRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - RTL Information TechnologyRental Agency Car CustomersSQL Job ProcessingRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - RTL Information TechnologyRental Agency Car CustomersSQL ServerRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - RTL Information TechnologyRTL ReportDB360RTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Fleet - RTL Information TechnologyRTL ReportRES ReportsRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Fleet - RTL Information TechnologyRTL ReportSQL AgentsRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Fleet - Sales & MarketingMarketing2nd Rock SSRS ReportingRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Sales & MarketingMarketingPlatepassRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Sales & MarketingMarketingUser ManagerRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Fleet - Sales & MarketingMarketingViologicsRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Sales & MarketingSalesBPARTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Sales & MarketingSalesCorporate File Servers (DFS, ATSFS02)RTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Fleet - Sales & MarketingSalesPlatepassRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Sales & MarketingSalesUser ManagerRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Fleet - Sales & MarketingSalesViologicsRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Sunshine IT OperationsIT Security – Anti-VirusESET Anti-VirusRTO 0N/A

    Fleet - Sunshine IT OperationsIT Security – Anti-VirusMicrosoft Security EssentialsRTO 0N/A

    Fleet - Sunshine IT OperationsIT Security – Anti-VirusSymantec EndpointRTO 0N/A

    Fleet - Sunshine IT OperationsIT Security – AuthenticationActive DirectoryRTO 0RPO 2: 24 Hours Maximum Permanent Data Loss

    Fleet - Sunshine IT OperationsIT Security – AuthenticationDomain ControllersRTO 0RPO 2: 24 Hours Maximum Permanent Data Loss

    Fleet - Sunshine IT OperationsIT Service Desk – Incident & Request ManagementDamewareRTO 1N/A

    Fleet - Sunshine IT OperationsIT Service Desk – Incident & Request ManagementGhostRTO 1N/A

    Fleet - Sunshine IT OperationsIT Service Desk – Incident & Request ManagementSpiceworks HelpdeskRTO 1RPO 2: 24 Hours Maximum Permanent Data Loss

    Fleet - Sunshine IT OperationsIT Service Desk – PatchingWindows Update ServicesRTO 4N/A

    Fleet - Sunshine IT OperationsNetwork – Administration & MonitoringNagiosRTO 0N/A

    Fleet - Sunshine IT OperationsPhone - System AdministrationCall ManagerRTO 0RPO 2: 24 Hours Maximum Permanent Data Loss

    Fleet - Sunshine IT OperationsPhone - System AdministrationPhone Server – PBXRTO 0RPO 2: 24 Hours Maximum Permanent Data Loss

    Fleet - Sunshine IT OperationsPhone - System AdministrationWatchGuard FirewallRTO 0RPO 2: 24 Hours Maximum Permanent Data Loss

    Fleet - Sunshine IT OperationsSysAdmin - Data BackupNetbackupRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Title & RegistrationAccounts Payable – State DMVsMS Access DatabaseRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Fleet - Title & RegistrationAccounts Payable – State DMVsQuickbooksRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Fleet - Title & RegistrationBilling / Invoicing CustomersATA OCRRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Title & RegistrationBilling / Invoicing CustomersMS Access Billing DatabaseRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Fleet - Title & RegistrationHertz LabelsUnity Label ApplicationRTO 4N/A

    Fleet - Title & RegistrationTitle & RegistrationATA OCRRTO 3RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Title & RegistrationTitle & RegistrationC.A.R.S. PortalRTO 3N/A

    Fleet - Title & RegistrationTitle & RegistrationSunshineState.com PortalRTO 3N/A

    Fleet - Title & RegistrationTitle & RegistrationSVRSRTO 3RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Title & RegistrationTitle & RegistrationUnityRTO 3RPO 0: 4 Hours Maximum Permanent Data Loss

    Fleet - Title & RegistrationTitle & RegistrationWinbatchRTO 3N/A

    SLGS - BU Application DevelopmentAsset Acquisition and DeliveryAsset Delivery ExternalRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    SLGS - BU Application DevelopmentAsset Acquisition and DeliveryAsset Delivery Internal (FTP)RTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    SLGS - BU Application DevelopmentAsset Acquisition and DeliveryCrossing Guard DesktopRTO 2RPO 1: 12 Hours Maximum Permanent Data Loss

    SLGS - BU Application DevelopmentAsset Acquisition and DeliveryTSAM (See List - Asset Acquisition and Delivery System)RTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    SLGS - BU Application DevelopmentSLGS - Axsis User AuthenticationUser ManagerRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    SLGS - BU Application DevelopmentSLGS - Billing, Payment and AccountingBPARTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    SLGS - BU Application DevelopmentSLGS - Billing, Payment and AccountingFile ProcessorsRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    SLGS - BU Application DevelopmentSLGS - Billing, Payment and AccountingJob SchedulerRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    SLGS - BU Application DevelopmentSLGS - Support / Dev ActivitiesDeployment UtilitiesRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    SLGS - BU Application DevelopmentSLGS - Support / Dev ActivitiesDevelopment ToolsRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    SLGS - BU Application DevelopmentSLGS - Support / Dev ActivitiesESCRTO 2RPO 3: >24 Hours Maximum Permanent Data Loss

    SLGS - BU Application DevelopmentSLGS - Support / Dev ActivitiesJenkinsRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    SLGS - BU Application DevelopmentSLGS - Support / Dev ActivitiesSVNRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    SLGS - BU Application DevelopmentSLGS - Support / Dev ActivitiesTroubleshooting UtilitiesRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    SLGS - BU Application DevelopmentViolation Process SystemADMSRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    SLGS - BU Application DevelopmentViolation Process SystemAxsis DB SystemRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    SLGS - BU Application DevelopmentViolation Process SystemAxsis ServicesRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    SLGS - BU Application DevelopmentViolation Process SystemAxsis Web ApplicationRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    SLGS - BU Application DevelopmentViolation Process SystemRoboHelpRTO 2RPO 3: >24 Hours Maximum Permanent Data Loss

    SLGS - BU Application DevelopmentViolation Process SystemSharePointRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    SLGS - Design, Engineering and ConstructionSLGS Design, Engineering and ConstructionAutoCADRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    SLGS - Design, Engineering and ConstructionSLGS Design, Engineering and ConstructionIMSRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    SLGS - Field OperationsInstallationsAxsisRTO 3RPO 0: 4 Hours Maximum Permanent Data Loss

    SLGS - Field OperationsInstallationsConsistency CheckRTO 3RPO 0: 4 Hours Maximum Permanent Data Loss

    SLGS - Field OperationsInstallationsIMSRTO 3RPO 0: 4 Hours Maximum Permanent Data Loss

    SLGS - Field OperationsInstallationsSharepointRTO 3RPO 2: 24 Hours Maximum Permanent Data Loss

    SLGS - Field OperationsMaintenanceAxsisRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    SLGS - Field OperationsMaintenanceConfluence/WikiRTO 4N/A

    SLGS - Field OperationsMaintenanceConsistency CheckRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    SLGS - Field OperationsMaintenanceSharepointRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    SLGS - Field OperationsRemovalAsteaRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    SLGS - Field OperationsRemovalAxsisRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    SLGS - Field OperationsRemovalConfluence/WikiRTO 4N/A

    SLGS - Field OperationsRemovalConsistency CheckRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    SLGS - Field OperationsRemovalSalesforceRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    SLGS - Field OperationsRemovalSharepointRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    SLGS - Field OperationsRemovalWorkplaceRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    SLGS - OperationsSLGS - Customer Service/Call CenterAxsisRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    SLGS - OperationsSLGS - Customer Service/Call CenterBPARTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    SLGS - OperationsSLGS - Customer Service/Call CenterIVRRTO 4N/A

    SLGS - OperationsSLGS - Mail RoomADMSRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    SLGS - OperationsSLGS - Violation ProcessingAxsisRTO 0RPO 0: 4 Hours Maximum Permanent Data Loss

    SLGS - OperationsSLGS - Violation ProcessingBPARTO 0RPO 0: 4 Hours Maximum Permanent Data Loss

    SLGS - OperationsSLGS - Violation ProcessingRoboHelpRTO 0RPO 3: >24 Hours Maximum Permanent Data Loss

    2018 BIA ™

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 30

    DATA ANALYSIS

    Sheet

    System/Application RTO/RPO Listing

    Company: ATS TestDivision: Information TechnologyDepartment: All DepartmentsInterview Date: 02/17/2016 - 03/19/2018

    System/Application Name3rd PartyLowest RTOLowest RPO

    S-2 SecurityYesRTO 0RPO 0: 4 Hours Maximum Permanent Data Loss

    SQL ServerNoRTO 0RPO 0: 4 Hours Maximum Permanent Data Loss

    Symantec EndpointNoRTO 0RPO 3: >24 Hours Maximum Permanent Data Loss

    TACACSNoRTO 0RPO 3: >24 Hours Maximum Permanent Data Loss

    VCenterNoRTO 0RPO 2: 24 Hours Maximum Permanent Data Loss

    WatchGuard FirewallNoRTO 0RPO 2: 24 Hours Maximum Permanent Data Loss

    Spiceworks HelpdeskNoRTO 1RPO 2: 24 Hours Maximum Permanent Data Loss

    Session Border ControllerNoRTO 1N/A

    Experience Portal ManagerNoRTO 1RPO 3: >24 Hours Maximum Permanent Data Loss

    GhostNoRTO 1N/A

    Elite Multi-Channel Desktop ClientNoRTO 1RPO 0: 4 Hours Maximum Permanent Data Loss

    DamewareYesRTO 1N/A

    Contact Management SystemNoRTO 1RPO 3: >24 Hours Maximum Permanent Data Loss

    Contact Management System Supervisor ClientNoRTO 1RPO 3: >24 Hours Maximum Permanent Data Loss

    CMS SupervisorYesRTO 2RPO 2: 24 Hours Maximum Permanent Data Loss

    Crossing Guard DesktopNoRTO 2RPO 1: 12 Hours Maximum Permanent Data Loss

    Deployment UtilitiesNoRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    Development ToolsNoRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    DMV InterfacesYesRTO 2RPO 2: 24 Hours Maximum Permanent Data Loss

    EMC (Soft Phone)YesRTO 2RPO 2: 24 Hours Maximum Permanent Data Loss

    File ProcessorsNoRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    CamfindYesRTO 2RPO 3: >24 Hours Maximum Permanent Data Loss

    CarfaxYesRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    Axsis DB SystemNoRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    Axsis ServicesNoRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    Axsis Web ApplicationNoRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    ARCGISYesRTO 2RPO 2: 24 Hours Maximum Permanent Data Loss

    Asset Delivery ExternalNoRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    Asset Delivery Internal (FTP)NoRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    ADMSNoRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    ADPYesRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    Advarion Contract DatabaseYesRTO 2RPO 2: 24 Hours Maximum Permanent Data Loss

    GITYesRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    ESCNoRTO 2RPO 3: >24 Hours Maximum Permanent Data Loss

    OrpixYesRTO 2RPO 3: >24 Hours Maximum Permanent Data Loss

    JAMSYesRTO 2RPO 3: >24 Hours Maximum Permanent Data Loss

    JenkinsNoRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    Job SchedulerNoRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    SharePointNoRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    SVNNoRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    PlatepassNoRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    QRadarNoRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    User ManagerNoRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    ViologicsNoRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    WOWZA CloudYesRTO 2N/A

    Troubleshooting UtilitiesNoRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    TSAM (See List - Asset Acquisition and Delivery System)NoRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    TFSYesRTO 2RPO 0: 4 Hours Maximum Permanent Data Loss

    TitletecYesRTO 3RPO 2: 24 Hours Maximum Permanent Data Loss

    UnityNoRTO 3RPO 0: 4 Hours Maximum Permanent Data Loss

    WorkplaceYesRTO 3RPO 2: 24 Hours Maximum Permanent Data Loss

    Wiki KnowledgebaseYesRTO 3RPO 0: 4 Hours Maximum Permanent Data Loss

    WinbatchNoRTO 3N/A

    Scan ViolationsYesRTO 3RPO 0: 4 Hours Maximum Permanent Data Loss

    C.A.R.S. PortalNoRTO 3N/A

    OCR SoftwareNoRTO 3RPO 0: 4 Hours Maximum Permanent Data Loss

    SVRSNoRTO 3RPO 0: 4 Hours Maximum Permanent Data Loss

    SunshineState.com PortalNoRTO 3N/A

    SalesforceYesRTO 3RPO 2: 24 Hours Maximum Permanent Data Loss

    PC Builds/ImagingNoRTO 3RPO 3: >24 Hours Maximum Permanent Data Loss

    ESC - AgiloftYesRTO 3RPO 3: >24 Hours Maximum Permanent Data Loss

    Image/Video RestoreNoRTO 3RPO 3: >24 Hours Maximum Permanent Data Loss

    IMSNoRTO 3RPO 0: 4 Hours Maximum Permanent Data Loss

    AsteaYesRTO 3RPO 0: 4 Hours Maximum Permanent Data Loss

    ATA OCRNoRTO 3RPO 0: 4 Hours Maximum Permanent Data Loss

    Adhoc ReportingNoRTO 3N/A

    Batch CreationNoRTO 3RPO 2: 24 Hours Maximum Permanent Data Loss

    Client Password ResetNoRTO 3RPO 0: 4 Hours Maximum Permanent Data Loss

    DataOneYesRTO 3N/A

    CVRYesRTO 3RPO 0: 4 Hours Maximum Permanent Data Loss

    Corporate File Servers (DFS, ATSFS02)NoRTO 3RPO 0: 4 Hours Maximum Permanent Data Loss

    Confluence/WikiYesRTO 3N/A

    Consistency CheckNoRTO 3RPO 0: 4 Hours Maximum Permanent Data Loss

    Corporate File ServersNoRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    ConcurYesRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Business Developed MacroNoRTO 4N/A

    Business InkYesRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Corporate File Servers (DFS, ATSFS02, Isilon)NoRTO 4RPO 1: 12 Hours Maximum Permanent Data Loss

    Corporate File Servers (HR Shared Drive)NoRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Credit card applicationNoRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Cyber SourceYesRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Crystal ReportsNoRTO 4N/A

    DB360NoRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Enrollment EstimatesNoRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    eResponseYesRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Email Service (iMail)NoRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    File Shares (DFS, ATSFS02)NoRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    File Shares (DFS, ATSFS02, Isilon)NoRTO 4RPO 1: 12 Hours Maximum Permanent Data Loss

    FISNoRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    FIS ApplicationNoRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    FMSNoRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    FMS ApplicationNoRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    FMS Membership ServiceNoRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    FMS Membership ServicesNoRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    FTPNoRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    GARYesRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Chase CheckPrintYesRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Bluebird AccessYesRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Bank of AmericaYesRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Authorize.netYesRTO 4N/A

    AutoCADNoRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    AutoConnectYesRTO 4N/A

    Avaya IVRYesRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    American ExpressYesRTO 4N/A

    ADP EtimeYesRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Adaptive InsightsYesRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Adaptive Insights ForecastingYesRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    2nd Rock SSRSNoRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    2nd Rock SSRS ReportingNoRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    ABBYY Optical Character RecognitionNoRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Interface processorNoRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    IPSWITCHNoRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    IVRNoRTO 4N/A

    iFACS SummaryNoRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Great PlainsYesRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Harris BankYesRTO 4N/A

    Harris Bank Check Deposit SoftwareNoRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    EZPassYesRTO 4N/A

    File Magic Job ProcessingNoRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    PCI virtual desktop (Credit Card system troubleshooting)NoRTO 4N/A

    Not FVO plate reportNoRTO 4N/A

    NYC AdjuducationNoRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Last known locationNoRTO 4N/A

    Management ReporterNoRTO 4N/A

    JCI paper invoicesNoRTO 4N/A

    MS Access Billing DatabaseNoRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    MS Access DatabaseNoRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Salesforce.comYesRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    SQL AgentsNoRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    SQL Job ProcessingNoRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Shift4YesRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    SmartConnectNoRTO 4N/A

    Support Job SchedulerNoRTO 4N/A

    State DMV SystemsYesRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    SubversionNoRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    System Center Configuration ManagerYesRTO 4N/A

    QuickbaseYesRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    QuickBase DatabaseNoRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    QuickBooksYesRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Ryder BillingNoRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Puerto Rico plate processingNoRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    ReportingNoRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Reporting ServicesNoRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    RES PortalNoRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    RES ReportsNoRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    RES TicketNoRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    RES Ticketing WebsiteNoRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Vena Forecasting and WorkflowYesRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Vena Forecasting and WorkflowYesRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Wells Fargo ClientLine (Website)YesRTO 4N/A

    Wheels Error reportingNoRTO 4RPO 3: >24 Hours Maximum Permanent Data Loss

    Wheels MacroNoRTO 4N/A

    Windows Update ServicesNoRTO 4N/A

    VMSNoRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Unity Label ApplicationNoRTO 4N/A

    Taleo Recruiting SystemYesRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Team CityNoRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    TSD AccessYesRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    TSD API AccessYesRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Tolerance reportNoRTO 4N/A

    Toll Agency WebsitesYesRTO 4N/A

    Toll Authority Screen ScrapeNoRTO 4N/A

    Toll Authority Screen Scrape ApplicationNoRTO 4N/A

    Toll Authority WebsitesYesRTO 4RPO 0: 4 Hours Maximum Permanent Data Loss

    Toll Roads PortalNoRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    Transponder fulfillmentNoRTO 4RPO 2: 24 Hours Maximum Permanent Data Loss

    2018 BIA ™

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 31

    G E T M A N A G E M E N T A P P R O V A L A N D S I G N O F F

    • The BCM Office and IT Disaster Recovery should agree on the results of the BIA and its process and system/applications RTOs and RPOs.

    • The results of the BIA report should be presented to your BCM Steering Committee or Sponsor for a final review, any revisions, and a formal approval.

    • Not getting management signoff/approval can and will impact the successful implementation of the BIA-derived RTOs and RPOs (based on our experience).

    • Once approved, the BIA report and its results should be used to drive recovery plans, strategies, solutions, and exercises across the business and technology.

    MANAGEMENT SIGNOFF

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 32

    MANAGEMENT SIGNOFF

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 33

    MANAGEMENT SIGNOFF

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 34

    MANAGEMENT SIGNOFF

    Recovery Time Objective is a measure of how fast you want your emergency system to be up and running.

    Recovery Point Objective is a measure of how much data you believe you can afford to lose.

    Recovery Service Level is a measure of what kind of computing needs are required in an emergency situation.

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 35

    I T T A K E S T H E L E A D I N D E C O N S T R U C T I N G T H E S Y S T E M / A P P L I C A T I O N R T O A N D R P O G A P S

    • Identify and inventory the technology (systems, applications, hardware, etc.) that make up the critical business processes in production as identified in the BIA.

    • Determine what is required (e.g., network, infrastructure, servers) to make up the differences in BIA-derived RTOs and RPOs versus current IT disaster recovery capabilities.

    • Construct a roadmap and budget with solutions and strategies to meet the BIA-derived RTO and RPO needs.

    • If IT can’t at least meet the RTO & RPO, look for reasonable timeframes to build upon. • Example, we can meet 48 hours in 2018, but with additional budget we can get to your RTO of 24

    hours in 2020.

    • Assess workarounds until the RTO and RPOs can be met or the business unit is willing to accept the risk.

    DECONSTRUCT THE GAPS

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 36

    I T t a k e s t h e l e a d i n d e c o n s t r u c t i n g t h e g a p s :

    DECONSTRUCT THE GAPS

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 37

    I T t a k e s t h e l e a d u s i n g t h e a p p r o v e d B I A r e s u l t s t o :

    • Compare BIA-derived system/app RTOs & RPOs to current capabilities.

    • Identify where expectations are met/exceeded and where gaps exist.

    • Document the results of the assessment for BCM.

    SYSTEM/APPLICATION ALIGNMENT

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED. 38

    • Involve IT from the beginning.• Understand IT DR capabilities.• Educate IT in the BIA process.• Build an RTO/RPO matrix that works.• Gather the right IT data.• Deconstruct the needs. • Get management approval of the results.• Build a roadmap for DR strategies/solutions. • Support DR strategies/solutions.

    SUMMARY

    TO MAKE THE BIA WORK FOR IT

  • © 2018 MHA CONSULTING. ALL RIGHTS RESERVED.

    MHA CONSULTING, INC.

    T H A N K Y O U

    www.mha-it.com

    (888) 689-2290

    (602) 708-1718

    [email protected]

    Michael Herrera, Chief Executive Officer

    THE BIA FROM THE IT PERSPECTIVESlide Number 2Slide Number 3Slide Number 4Slide Number 5Slide Number 6Slide Number 7Slide Number 8Slide Number 9Slide Number 10Slide Number 11Slide Number 12Slide Number 13Slide Number 14Slide Number 15Slide Number 16Slide Number 17Slide Number 18Slide Number 19Slide Number 20Slide Number 21Slide Number 22Slide Number 23Slide Number 24Slide Number 25Slide Number 26Slide Number 27Slide Number 28Slide Number 29Slide Number 30Slide Number 31Slide Number 32Slide Number 33Slide Number 34Slide Number 35Slide Number 36Slide Number 37Slide Number 38Slide Number 39