Sep, 2001 : Satel Advises on "Preparing for the Unthinkable"
📅 - Satel Inc. (satel.com), a leader in information securitywith a legacy of helping companies worldwide prepare for worst-casescenarios, Thursday offered an expert look at the process of keepingbusinesses running during times of crisis.
The fundamental ingredient, according to a statement released by thecompany, is the policy, technology, and practices that surround datasecurity. Satel encourages companies of all sizes to assessvulnerabilities, plan contingencies, and execute appropriate securitymeasures to ensure that disasters like Tuesday's terrorist attacks or morecommonplace threats such as computer viruses and hackers don't cripplebusiness activities.
"After the initial horror of this tragedy and the grieving over the loss ofthousands of lives finally passes, the reality of providing continuingemployment for survivors and serving the customers of the dozens ofdestroyed companies will gradually creep to the forefront," said RogerBlohm, director, managed services at Satel. "For the well-being of everyoneinvolved, it's critical that companies get back to business as usual asquickly as possible. How quickly that happens is directly tied to theplanning those companies did weeks, months, and even years before. Thelessons being learned in New York and Washington D.C. can apply equally toevery business in Utah, whether it's a small shop or a multinationalcorporation."
An accurate assessment of a company's day-to-day business activities is thenecessary first step in an adequate contingency plan. Satel encouragesorganizations of all sizes to accurately examine their reliance on computerresources and the security of those resources. Companies must determinewhich resources (data and applications) are most critical to vital businessactivities. Based on this hierarchy of resources, companies should assignacceptable standby timeframes to each. For example, a payroll system wouldnot necessarily need to be back online until the next pay period. On theother hand, for financial institutions, transaction records and applicationsdemand immediate restoration.
Once this hierarchy and its related standby intervals are determined,companies can logically select and implement appropriate security solutions.Solutions range from a variety of data and application backup and recoverystrategies to quick-turnaround sources for computer hardware. Depending onhow mission-critical a particular set of data and applications is, optionsinclude:
Hot standby - creating an exact duplicate of data and applicationsthat is updated in real-time and automatically takes over if the primarysystem fails.Cold standby - creating an exact duplicate of data and applicationsthat is updated periodically and can be activated within a relatively shorttime frame (typically a matter of hours)Site diversification - keeping backup resources or running standbysystems at sites geographically separated from primary activities.Outsourcing - turning data and application hosting, management,security, backup, and recovery over to a managed service provider thatprovides a level of security, expertise, and redundancy typically missing inmost organizations.Backup - ranging from weekly data backup stored in the company safeto real-time, entire-system backups stored at off-site data storagefacilities.
The solutions a company uses will be determined by the relative impact thata loss of data or applications will have on business. For example, ane-commerce company would require a fully redundant hot standby of its Website and applications, while a restaurant would require only a nightly databackup stored off-site.
Finally, companies must determine how they will react in the event ofunforeseen and unfortunate circumstances. While the response to situationssuch as the recent terrorist attacks, fire, or a natural disaster are fairlyclear-cut - rebuild systems and get data and applications running as soon aspossible - many other very real threats require more complex response plans.
For situations such as computer viruses, hacker attacks, or computermischief initiated by disgruntled employees, appropriate response oftendemands continuing operations while reversing damages, investigating causes,communicating with customers, and even launching investigations and legalrecourse. Obviously, incident response can involve much more than simplyrestoring data.
"Not every business needs in-depth planning and detailed incident responseplans," said Blohm. "But for those that can't continue to function withoutmission-critical data and applications, any security and contingencyinvestment made on the front end will be paid back many times if a tragedydoes happen."
The fundamental ingredient, according to a statement released by thecompany, is the policy, technology, and practices that surround datasecurity. Satel encourages companies of all sizes to assessvulnerabilities, plan contingencies, and execute appropriate securitymeasures to ensure that disasters like Tuesday's terrorist attacks or morecommonplace threats such as computer viruses and hackers don't cripplebusiness activities.
"After the initial horror of this tragedy and the grieving over the loss ofthousands of lives finally passes, the reality of providing continuingemployment for survivors and serving the customers of the dozens ofdestroyed companies will gradually creep to the forefront," said RogerBlohm, director, managed services at Satel. "For the well-being of everyoneinvolved, it's critical that companies get back to business as usual asquickly as possible. How quickly that happens is directly tied to theplanning those companies did weeks, months, and even years before. Thelessons being learned in New York and Washington D.C. can apply equally toevery business in Utah, whether it's a small shop or a multinationalcorporation."
An accurate assessment of a company's day-to-day business activities is thenecessary first step in an adequate contingency plan. Satel encouragesorganizations of all sizes to accurately examine their reliance on computerresources and the security of those resources. Companies must determinewhich resources (data and applications) are most critical to vital businessactivities. Based on this hierarchy of resources, companies should assignacceptable standby timeframes to each. For example, a payroll system wouldnot necessarily need to be back online until the next pay period. On theother hand, for financial institutions, transaction records and applicationsdemand immediate restoration.
Once this hierarchy and its related standby intervals are determined,companies can logically select and implement appropriate security solutions.Solutions range from a variety of data and application backup and recoverystrategies to quick-turnaround sources for computer hardware. Depending onhow mission-critical a particular set of data and applications is, optionsinclude:
Hot standby - creating an exact duplicate of data and applicationsthat is updated in real-time and automatically takes over if the primarysystem fails.Cold standby - creating an exact duplicate of data and applicationsthat is updated periodically and can be activated within a relatively shorttime frame (typically a matter of hours)Site diversification - keeping backup resources or running standbysystems at sites geographically separated from primary activities.Outsourcing - turning data and application hosting, management,security, backup, and recovery over to a managed service provider thatprovides a level of security, expertise, and redundancy typically missing inmost organizations.Backup - ranging from weekly data backup stored in the company safeto real-time, entire-system backups stored at off-site data storagefacilities.
The solutions a company uses will be determined by the relative impact thata loss of data or applications will have on business. For example, ane-commerce company would require a fully redundant hot standby of its Website and applications, while a restaurant would require only a nightly databackup stored off-site.
Finally, companies must determine how they will react in the event ofunforeseen and unfortunate circumstances. While the response to situationssuch as the recent terrorist attacks, fire, or a natural disaster are fairlyclear-cut - rebuild systems and get data and applications running as soon aspossible - many other very real threats require more complex response plans.
For situations such as computer viruses, hacker attacks, or computermischief initiated by disgruntled employees, appropriate response oftendemands continuing operations while reversing damages, investigating causes,communicating with customers, and even launching investigations and legalrecourse. Obviously, incident response can involve much more than simplyrestoring data.
"Not every business needs in-depth planning and detailed incident responseplans," said Blohm. "But for those that can't continue to function withoutmission-critical data and applications, any security and contingencyinvestment made on the front end will be paid back many times if a tragedydoes happen."
Reads: 1183 | Category: General | Source: TheWHIR : Web Host Industry Reviews
URL source: http://www.thewhir.com/marketwatch/satel914.cfm
Want to add a website news or press release ? Just do it, it's free! Use add web hosting news!