Disaster Recovery Plan Template
Disaster Recovery Plan Template
Disaster Recovery Plan Template
Plan
Template
Notice: Copyright Stay In Business.com - Stay In Business is the legal owner of the template. This may be used
only by the purchaser for business purposes only. The template may not be sold, shared, copied or transmitted to
any third party without the written expressed consent of Stay In Business.
Table of Contents
Section 1 - Goals of a Disaster Recovery Plan.................................................................3
Section 2 - Personnel........................................................................................................4
Section 3 - Application Profile............................................................................................5
Section 4 - Inventory Profile..............................................................................................6
Section 5 - Information Services Backup Procedures.......................................................8
Section 6 - Disaster Recovery Procedures.......................................................................9
Disaster Action Checklist...............................................................................................9
Section 7- Recovery Plan-Mobile Site.............................................................................13
Mobile site setup plan..................................................................................................14
Disaster Plan for Communications...............................................................................14
Electrical service..........................................................................................................14
Section 8 - Recovery Plan - Hot Site...............................................................................15
Hot-site system configuration.......................................................................................16
Hot-site solutions..........................................................................................................16
Section 9 - Restoring the Entire System.........................................................................17
Section 10 - Rebuilding Process.....................................................................................18
Section 11 - Testing the Disaster Recovery Plan............................................................19
Conducting a Recovery Test Check List...................................................................19
Areas to be Tested Check List..................................................................................20
Section 12 - Disaster Site Rebuilding..............................................................................22
Section 13 Infectious/Communicable Diseases Plan...................................................24
Situational Analysis......................................................................................................30
BCDR Plan Deactivation..............................................................................................38
Section 14 BCDR Plan for Data Security Breach.........................................................40
Plan Activation and Notification....................................................................................44
Situational Analysis......................................................................................................47
Personnel.....................................................................................................................52
Section 15 - Record of Plan Changes.............................................................................54
Page 2
Page 3
Section 2 - Personnel
The following is a list of all IT personnel who are involved with information technology
aspects. This list should be updated frequently.
Data Processing Personnel
Name
Position
Address
Telephone
Note: Attach a copy of your organization chart to this section of the plan.
Page 4
Critical?
Yes/No
Fixed
Asset?
Yes/No
Manufacturer
Comments
Comment legend:
1. Runs daily.
2. Runs weekly on ________.
3. Runs bi weekly on ______ and ______
4. Runs monthly on ________.
5. Other _______________
Page 5
Page 6
Inventory Profile
Manufacturer
Description
Model
Serial
Number
Own or
Leased
Cost
Miscellaneous Inventory
Description
Quantity
Comments
Note: This list should include all equipment and miscellaneous items that are crucial to restarting
operations
Page 7
Page 8
Monitor progress
Page 9
Senior Management
Name
Position
Address
Telephone
Page 10
Follow-Up Checklist
B.
Obtain emergency cash and setup transportation to and from the backup
site, if necessary
Check all data being taken to the backup site before leaving and leave an
inventory profile at a home location
Plan for transportation of any additional items needed at the backup site
Page 11
Page 12
At the point where telephone lines come into the building (mark entry point),
break the current linkage to the administration controllers (mark point).
These lines are rerouted to lines going to the mobile site. They are linked to
modems at the mobile site. The lines currently going from (begin point to
end point would then be linked to the mobile unit via modems.
8. When the trailer arrives, plug into power and do necessary checks.
9. Plug into the communications lines and do necessary checks.
10. Begin loading system from backups (see Section 9. Restoring the Entire
System).
11. Begin normal operations as soon as possible
Daily jobs
Daily saves
Weekly saves
Page 13
Electrical service
Attach the electrical service diagram here.
Page 14
Notify (name of contact and name of company) of the nature of the disaster and
of its desire for a hot site.
Begin making necessary travel arrangements to the site for the operations team.
Confirm that all needed tapes are available and packed for shipment to restore
on the backup system.
Review the checklist for all necessary materials before departing to the hot site.
Make sure that the disaster recovery team at the disaster site has the necessary
information to begin restoring the site. (See Section 12 - Disaster Site
Rebuilding).
After arriving at the hot site, contact home base to establish communications
procedures.
1. Plan the schedule to backup the hot-site system in order to restore on the homebase computer.
Page 15
Hot-site solutions
FatPipe Networks has developed a host of products that ensure the highest level of
WAN reliability, redundancy, and maximum bandwidth for disaster recovery planning,
including data mirroring and remote storage. As the inventor and multiple patents holder
of Router Clustering technology -- which aggregates multiple data lines from the same
or separate ISPs -- FatPipe provides dynamic, intelligent and automatic failover of
downed WAN connections.
FatPipe Networks also makes available several other solutions for corporations that are
implementing or wanting to enhance their current disaster recover/continuity plans.
FatPipe offers dual power supply units for power backup and auto-failover units. The
failover unit can be placed at the customer premise or at a remote location, such as a
remote storage site or disaster recovery site.
In addition, FatPipe provides site load balancing capabilities, where traffic can be
shared between one or more remote site units utilizing all lines available at each
location. This is used when inbound connectivity to Internet accessible servers is
critical. This technology utilizes FatPipes Site Load Balancing feature. The servers
located in geographically separate locations can have identical or similar information in
two or more locations. For more information www.fatpipeinc.com
Page 16
Page 17
Page 18
Yes No Applicable
Not
Applicable
Comments
Page 19
Not
Yes No Applicable Applicable
Comments
Page 20
Page 21
Page 22
Floor plan
Include a copy of the proposed floor plan here.
Vendors
Vendors - Include vendor information here.
Company Name
Contact
Address
Telephone
Page 23
Section 13
Infectious/Communicable Diseases
Plan
Recent events such as the Ebola outbreak have made it imperative for companies to
start thinking about policies and procedures in case an employee is infected. For
companies that have employees that travel - a well thought out plan is essential.
Each business is different. The following gives a guideline of the elements of a BCDR
plan. Each business should modify this to suit needs.
Executive Management
List names and contact information of the following personnel here. Also include their
area of responsibility
1. BCDR plan coordinator
2. Manager - Human Resources
3. Manager - Financial
4. Manager Legal
5. Manager Technical and Data Security
6. Manager Site and building security
7. Manager Industrial Health and Safety
8. Other list names, contact information and area of responsibility
Also discuss plan goals, Recovery Point and Recovery Time Objectives. Management
should also communicate to employees in general, their support of the plan and
introduce various key personnel who will be tasked with continuity and recovery
operations.
1. Plan Objectives
The aim of this plan is to allow (company name) to respond effectively in a safe
manner and recovery from an Infectious/Communicable disease outbreak. The
main objectives are:
Page 24
Treatment options
4. City, County, State and National Health Agency Roles and Assistance
Contact agencies and determine who will be the point person at the
agency during outbreaks gather and record contact information
All local and state ordinances and laws should be understood. Your
BCDR plan should not violate these.
Sharing your plan with agencies and asking for their opinion is a good way
to fine tune plans develop personal relationships
Page 25
Medical they can assist with all health and health safety issues.
5. Planning Assumptions
Several assumptions have to be made when developing these plans. From the
extent of the outbreak to its severity to personnel, reasonable assumptions have
to be made. However, assumptions made should be listed and rationale given if
applicable. Some of the assumptions that should be considered are
Duration of outbreak
Staff Make a reasonable assumption about the number of staff that could
be infected. This will determine staff availability for vital and critical
functions.
A list of vendors and contact information should be developed for various services and
products. Remember to determine lead times needed for each.
Plan Activation and Notification
1. Plan Activation
The activation of the entire plan or only a part are dependent on a variety of
factors. IF any or all of the following are met the plan should be activated.
a. Any public health agency issues an alert or warning in the same general
area as the business.
Page 26
BCDR Team
(Insert message here)
Sample message: The BCDR plan for (name disease) has been activated.
Report for your assignments per the BCDR plan. In case you need to refer to
the BCDR plan, copies of the plan can be obtained at (name source
website, cloud etc). You should call our DR number (give emergency number
here) immediately to check in.
Customers
(Insert message here)
Sample message: Dear (name) this is to inform you that we have activated
our BCDR plan due to (give reason). We will strive to ensure you will see little
or no disruption. Please call the hot line we have set up (give number) for
further information. One of our specialists, assigned to ensure our valued
customers are not inconvenienced will also be contacting you shortly to
discuss the situation and inform you of the actions we will take to minimize
the effects of the disaster. We thank you for your understanding and
coorporation.
Vendors
(Insert message here)
Sample message: Dear (name) this is to inform you that we have activated
our BCDR plan due to (give reason). We will strive to ensure you will see little
or no disruption. Please call the hot line we have set up (give number) for
further information. One of our specialists, assigned to ensure our valued
vendors are not inconvenienced will also be contacting you shortly to discuss
the situation and inform you of the actions we will take to minimize the effects
of the disaster. We thank you for your understanding and coorporation.
Other
(Insert message here)
The following will be the organization and structure of the response to the
Infectious/Communicable disease emergency. All or parts may be activated and
modified as needed during the emergency
2. Response Management
Once the Infectious/Communicable diseases BCDR plan has been activated, the
Incident Commander will be (Name, Title and Contact information of Incident
Commander). In case he or she cannot assume command, the following are
authorized to assume Incident Command
If the first alternate is unable to take command, the command moves to the next
person on the list. Unable to take command is defined as given below. It is
advisable to carefully consider who is capable of leading during emergency especially non managerial employees. They should have leadership qualities
and have the respect of their colleagues.
Page 29
Situational Analysis
1. Mission Statement
This BCDR plans mission is to disseminate information on activation to all
stakeholders giving information about the nature of the disaster, the response
and actions each stakeholder has to perform during the crisis.
2. BCDR Plan Implementation
A BCDR plan is only as good as its implementation. To this end to ensure that
the BCDR plan meets the objective of business continuity and quick recovery,
input of various plan stakeholders is important in the planning stage itself.
a. Status of Infectious/Communicable Disease
A vital part of plan activation and implementation is knowledge of the
current status of the Infectious/Communicable disease outside and within
the business. To this end, source of information the business will use in
such cases should be identified and listed. Source that will be used are:
numbers)
c. Community
Every business exists in a community and goodwill and respect is an
important part of business operations. When confronted with these
diseases in the community, a business should gather all possible
information to ensure proper action can be taken. Local health services
will provide information. In case the outbreak is within a business, it is
important to inform local agencies. Information flow through these
agencies to the public is important in maintaining public relations
d. Customer Relationships
If a business has activated its BCDR plan, customer and it is important for
the business to understand why customer behavior has changed. The
BCDR of plan should have steps in place to handle the change in behavior
and revenue flows. This is important to ensure financial viability of the
business during this crisis.
e. Vendor Relationships
Vendor relationships mean change during the crisis. If the vendor service
being provided is on-site it may be even affected to a greater extent than
normal. If the vendor is providing services that do not require a physical
presence, then the relationship might not be affected to a great extent.
However there should be a clear understanding between the business and
the vendor what can be expected by each party. As soon as the BCDR
plan is activated, vendors especially the critical ones, should be contacted
and a clear understanding of expectations should be established. The
following a list of vendor, contact information and services provided
Page 31
f. Business Operations
Operations will be affected mainly due to staff strength. Businesses
should pre-determine what critical business functions are and how to
handle them. Staff functions may have to be reassigned to fill gaps.
g. Staffing
The BCDR plan should have a staffing plan. To do this, reasonable
assumptions must be made. List functions, staff strength and
assumptions in this section.
Communications
a. Stakeholders
During disasters, communications are critical in ensuring smooth handling
of the disaster. Communications to various stakeholders will be different
and the manner and mode of communications vary. It is important to
ensure, the entire business speaks with one voice and therefore it is
prudent to assign an empowered committee to channel communications
through. The stakeholders are:
Page 32
Employees
Customers
Vendors
Government Agencies
Community
b. Messaging
The content of message to each group of stakeholders can be
predetermined because it is a initial message informing that the BCDR
plan has been activated. After the initial message goes out, the next batch
of messages can be crafted to meet needs.
i. Employees
Sample message (edit to suit business needs)
The company has activated the BCDR plan for
Infectious/communicable diseases with effect from (date and time).
This message is to inform you of the activation of the plan. The
company places a very high value on keeping employees informed
as time progresses. A follow-up message will be sent shortly
informing you of the actions the company will be taking and the role
Page 33
Page 34
Phones hot line (internal and external give numbers here), text,
voice mail, recorded messages, call tree, call centers.
d. Urgent Communiqu
Determine what modes will be used to communicate urgent messages to
Page 35
Page 36
Page 37
Page 39
Page 40
Page 41
Page 43
Page 44
Sample message (edit per your business situation): The BCDR plan for a
breach of data security has been activated. The plan was activated due to
(give reason). We will keep you informed by (name mode of information
text, email, video, website announcement, etc) every hour on the hour
unless circumstances prevent us. You are instructed to (give instructions
here do not use company laptop till it is checked by an expert etc). Call
the following number that has been established for more information and
instructions.
k. BCDR Team
(Insert message per business requirement)
Sample message (edit per your business situation): The BCDR plan for a
breach of data security has been activated. Report for your assignments
per the BCDR plan. In case you need to refer to the plan, it can be
obtained securely at (name source cloud, website etc). You should call
the falling number (give number) immediately and check in. All leave and
vacations have been cancelled.
l. Customers
(Insert message per your business requirement)
Sample message (edit per your business situation): Dear (name) this is
to inform you we have activated our BCDR plan for a breach of data
security. We are working urgently to secure our data and systems to
minimize further issues. Please be assured we take this situation very
seriously and will keep you updated periodically by (text, email, video,
public announcements, press conferences etc). We have set up a hotline
(number) to answer any questions you may have. We request your
patience and we work to resolve this situation.
m. Vendors
(Insert message per your business requirement)
Sample message (edit per your business situation): Dear (name) this is
to inform you we have activated our BCDR plan for a breach of data
security. We are working urgently to secure our data and systems to
minimize further issues. Please be assured we take this situation very
Page 45
seriously and will keep you updated periodically by (text, email, video,
public announcements, press conferences etc). We have set up a hotline
(number) to answer any questions you may have. We request your
patience and we work to resolve this situation. One of our specialists will
contact you shortly.
n. Other
(Insert message her per your requirements)
Authority and Command
The following will be Authority and command structure during a data security breach
1) BCDR Response Organization and Command Structure
The following is the organization and command structure for the response to a
breach of data security. All or parts may be activated or mdified during this
emergency.
2. Response Management
Once the BCDR plan for a data security breach has been activated, the incident
commander will be (Name, Title, Contact Information of Commander). In case he
or she cannot assume command, the following are authorized to assume
command in descending order
a. Alternate 1 (name, title and contact number)
b. Alternate 2 (name, title and contact number)
c. Alternate 3 (name, title and contact number)
d. Other add name per requirement
If the first alternate is unable to take command, the command moves to the next
person on the list. Unable to take command is defined below. It is advisable to
carefully consider who is capable of leading during emergency especially non
managerial employees. They should have leadership qualities and have the
Page 46
Situational Analysis
1. Mission Statement
This BCDR pans mission is to systematically handle a data security breach while
disseminating information to all stakeholders.
2. BCDR Plan Implementation
Any BCDR plan is only as good as its implementation. In order to achieve this,
the plan must meet the objectives of business continuity and recovery. Input of
various parts of a business is important to ensure that the plan is well rounded
and acceptable to all employees. Plans developed with employee input generally
are the best. A top down plan, where upper management develops the plan and
foists it on employees usually fails during execution.
a. Status of Data Protection
Knowledge of the current trends in data protection is vital to ensuring that
data will be secure and not vulnerable to hacking. To do this, it is prudent
to have multiple sources of information that describe and detail various
advances in data protection. Sources that will be used are
i. Information Source 1
ii.Information Source 2
iii.Other
b. Customers
If a business has activated a BCDR plan due to a security breach, it is
natural for customers to be concerned if their personal data has been
Page 47
Page 48
activation are
1 Non Critical Operation 1 - Name, department
2 Non Critical Operation 2 - Name, department
3 Other add per business requirement
e. Staffing Plan
The BCDR should have a staffing plan when activated. Staff duties may
have to be rearranged during this period. List functions, staff strength and
assumptions in this section.
Communications
a. Stakeholders
During disasters, communications are critical in ensuring smooth handling
of the disaster. Communications to various stakeholders will be different
and the manner and mode of communications vary. It is important to
ensure, the entire business speaks with one voice and therefore it is
prudent to assign an empowered committee to channel communications
through. The stakeholders are:
i. Employees
ii.Customers
iii.Vendors
iv.Other specify per local requirement
b. Empowered Communications Committee
The following employees are assigned to the committee through whom all
communication will be routed.
i. Director of Communications (Chair of committee)
ii.Member 1 (name & title)
iii.Member 2 (name & title)
iv.Member 2 (name & title)
Page 49
Page 50
Page 51
Personnel
During crisis, employees may be required to carry out duties in new areas and support
other departments. In this section add all personnel policies that will be in effect.
Remember, even during emergencies, all policies should adhere to prevailing federal,
state and local laws. A committee that oversees issues regarding personnel should be
constituted. Take HR/legal advice to ensure compliance.
a. Personnel Committee
i. Director Personnel
ii.Member 1 policy matters
iii.Member 2 training and reassignment
iv.Member 3 tracking
v.Member 4 temporary work assignment
vi.Member 5 inter departmental coordination and liaison
vii.Other add per business requirement
BCDR Plan Deactivation
An orderly deactivation of the plan is just as important as activation. The policies that
will be followed when transitioning back to normal should be detailed in this section.
a. Plan Deactivation Announcement
Management should announce the end of the crisis. This is very
important as it will give employees, customers, vendors and other
stakeholders confidence that the company is back on track and the worst
is over.
b. Transition to Normal Operations
The following should be considered and policies developed
i. Work assignments for staff (specially if some staff are yet to report
to work)
ii.Transition from temporary assignments to regular assignments
iii.SOP modifications if any
Page 52
Page 53
Page 54