1 © 2014 Cisco and Strategic BCP. All rights reserved Cisco Confidential

© 2014 Cisco and Strategic BCP. All rights reserved
Cisco Confidential
1
© 2014 Cisco and Strategic BCP. All rights reserved
Cisco Confidential
2
Risk-Based IT Disaster Recovery
From IT Assessment to Drills
Jean Anderson CBCP
Cisco IT Business Continuity and Disaster Recovery Service Manager
Frank Perlmutter CBCP, MBCI
Strategic BCP/ResilienceONE Chief Executive Officer
Christopher Duffy CISSP
Strategic BCP/ResilienceONE Chief Innovation Officer
© 2014 Cisco and Strategic BCP. All rights reserved
3
• Cisco: Resilient Company Overview
• Cisco: Resiliency Strategy
• Cisco IT Best Practices Process
• Best Practices Resiliency Process Details
• What Would You Do –
Recovery During a Disaster
© 2014 Cisco and Strategic BCP. All rights reserved
Cisco Confidential
4
© 2014 Cisco and Strategic BCP. All rights reserved
Cisco Confidential
5
Physical Safety
SSBR: ERT, SFOC
CEBC, HR, Cisco Staff
© 2014 Cisco and Strategic BCP. All rights reserved
Business Continuity
SSBR: ERT, SFOC
CEBC, HR, Cisco Staff
Asset Protection
SSBR: ERT, SFOC
WPR, Cisco Staff
IT Service Continuity Management
IT Resiliency Operations
IT Command Center
Operations, Support Teams
Application Teams,
IT Provisioning
Cisco Confidential
6
• 100+ Cisco locations in 165+ countries
• 460 Cisco offices
• 73,000+ employees
• 32 data centers/ server rooms
• 30,000 Virtual Machines
• 88% Server Virtualized in New Data Centers
• 73% Overall Virtualization
• Resiliency Data Centers
• 6000 Resiliency DC Components
• 1700+ Applications
• 300 Production Databases
© 2014 Cisco and Strategic BCP. All rights reserved
Cisco Confidential
7
• Cisco Business Continuity provides daily business continuity for
network, host, and database recoveries, using two redundant
Cisco Cloud Data Centers located in Texas.
Business Continuity
Disaster Recovery
• Cisco Disaster Recovery provides catastrophic disaster recovery
when both production data centers are unavailable and a Cisco
disaster is declared, using the remote Cisco Cloud Disaster
Recovery Data Center located in North Carolina.
© 2014 Cisco and Strategic BCP. All rights reserved
Cisco Confidential
8
© 2014 Cisco and Strategic BCP. All rights reserved
Cisco Confidential
9
Solving the Ubiquitous IT Challenge of Delivering Value to the Business
• Resilience ONE® can document and manage the IT
Applications Criticality assignments and compliance
reporting.
• Resilience ONE® can document required build and
recovery, manage Resiliency Compliance Validation and
reporting, and to manage IT response, in real-time,
during business interruptions large and small.
© 2014 Cisco and Strategic BCP. All rights reserved
10
Cisco Confidential
10
Solving the Ubiquitous IT Challenge of Delivering Value to the Business
Best Practices Resiliency IT Recovery can be integrated into Resilience ONE
IT Application
Inventory
Service
Dependency
Mapping
© 2014 Cisco and Strategic BCP. All rights reserved
BCPs,
BIAs
Builds,
Architecture,
Standard
Compliance
Validation
Process
SIA,
Criticality,
RTO Reqs
RPO Reqs
Metrics
Common SSOT
for presentations,
and information
used by multiple
teams.
Servers and
Support
Components
integrated
into
Application
Recovery
Plans
11
IT Command
Center manages
BC/DR Application
recoveries. For DR,
executes DC DR
plan with real time
status.
Third
Party
Vendor
Contacts
Cisco Confidential
11
© 2014 Cisco and Strategic BCP. All rights reserved
Cisco Confidential
12
IT Applications are included in the Resilience ONE,
organized by Services like Sales, Finance, Customer
Service
© 2014 Cisco and Strategic BCP. All rights reserved
Cisco Confidential
13
Solving the Ubiquitous IT Challenge of Delivering Value to the Business
Define Application Downtime Business Impact Factors:
• If the IT Application is down, what is the quantitative and
qualitative impacts to the company?
• Impact is based on priorities and risk tolerance and may include:
Loss of Revenue
Loss of Productivity
Brand Image
Additional Costs
Fines and Penalties
Loss of Market Share
1 hour
© 2014 Cisco and Strategic BCP. All rights reserved
4 hours
24 hours
48 hours
14
Best Effort
Cisco Confidential
14
Each Cisco IT Applications is assigned a Criticality using the Cisco
Enterprise Business Continuity (BIA) and and IT Service Continuity
Management (SIA) reports.
C-Level
Term
Impact Description
C1
Mission Imperative
Any outage that results in immediate cessation of a primary function,
equivalent to immediate and critical impact to revenue generation,
brand name and/or customer satisfaction; no downtime is acceptable
under any circumstances
C2
Mission Critical
Any outage results in immediate cessation of a primary function,
equivalent to major impact to revenue generation, brand name and/or
customer satisfaction
C3
Business Critical
Any outage results in cessation over time or an immediate reduction of
a primary function, equivalent to minor impact to revenue generation,
brand name and/or customer satisfaction
C4
Business Operational
A sustained outage results in cessation or reduction of a primary
function
C5
Business Administrative
A sustained outage has little to no impact on a primary function
© 2014 Cisco and Strategic BCP. All rights reserved
Cisco Confidential
15
Resilien
cy
Criticality
Level
Business Continuity
Disaster Recovery
(Unplanned downtime)
Recovery Time
Objective (RTO)
(hours)
Recovery
Point Objective
(RPO)
Recovery Time
Objective (RTO)
(hours)
Recovery
Point Objective (RPO)
C1
1
0 data loss
4
1 hour data loss
C2
1
0 data loss
4
1 hour data loss
C3
1
0 data loss
24
1 hour data loss
C4
24
1 hour data
loss
48
24 hours data loss
C5
Best Effort
1 week data
loss
Best Effort
1 week data loss
© 2014 Cisco and Strategic BCP. All rights reserved
Cisco Confidential
17
Critical Applications are supported in Business Continuity redundant
data centers for business interruptions plus a remote Disaster
Recovery Data Center for a catastrophic disaster.
Criticality
C1
C2
C3
Criticality
C4
Criticality
C5
© 2014 Cisco & Strategic BCP.
© 2014 Cisco and Strategic BCP. All rights reserved
Cisco Confidential
19
RCDN Data Center (DC1)
© 2014 Cisco and Strategic BCP. All rights reserved
ALLEN Data Center (DC2)
Cisco Confidential
20
Data Center Virtualization and
Cisco Virtual Routing and Forwarding
for Re-Use-Based Disaster Recovery
RTP
Campus
Centralized
Storage
NAS
BKP
Capability
Flexibility
Utilization
SAN
Non-Production ENV
Daily Operations
SIM DMZ Networking
& Config
DR
Production
(Dormant)
Shadow DR
VMs with
Non-Prod VM
Reduced Capacity
NON-PROD Sim-DMZ
Non-Production ENV
Daily Operations
DR-DMZ Networking
& Config
DR-DMZ
VM Farm
Non-Prod Networking
& Config
DR Production
(Dormant)
Placeholder DR Prod VMs
with Reduced Capacity
Non-Prod VMs
NON-Production ENV
Dedicated
Physical
(Exception)
Shared VM Farms
DR-Production ENV
Expand
Architecture to
Multiple DCs
Dedicated
Physical
(Exception)
DR Networking
& Config
Lowered
Cost
Virtualized Non-Prod Daily Ops ENV transformed into Disaster Recovery Production during a disaster.
© 2014 Cisco and Strategic BCP. All rights reserved
Cisco Confidential
21
© 2014 Cisco and Strategic BCP. All rights reserved
Cisco Confidential
22
• BC and DR Resiliency Compliance Validation proves that the
application is compliant with its Criticality requirement.
• Each application must meet the Recovery Time Objective and
the Recovery Point Objective.
© 2014 Cisco and Strategic BCP. All rights reserved
Cisco Confidential
23
Emulate
Interruption
Validate RTO
and RPO
Restore
Production
Submit Reports
• Confirm Readiness in both Data Centers
• Shut Down Apps and DBs in Production Data Center
• Activate Applications and DBs in Recovery DC (RTO)
• Validate Applications Work in Recovery DC (RPO)
•
•
•
•
Shut down Applications and DBs in Recovery DC.
Activate Applications and DBs in Production DC
Validate Applications Work in Production DC
Document and Submit Compliance Validation Reports
© 2014 Cisco and Strategic BCP. All rights reserved
Cisco Confidential
24
IT Business
Interruption
Recover
Production
Restore
Production DC
• IT Command Center manages IT Response for both IT BC and DR
• Data Center Disaster Recovery when Cisco IT Disaster Declared
• Activate Applications and DBs in Recovery DC within RTO
• Validate Applications Work in Recovery DC meeting RPO
•
•
•
•
Shut down Applications and DBs in Recovery DC.
Activate Applications and DBs in Production DC
Validate Applications Work in Production DC
Close Incident
© 2014 Cisco and Strategic BCP. All rights reserved
Cisco Confidential
25
© 2014 Cisco and Strategic BCP. All rights reserved
Cisco Confidential
26
Cisco IT Team all ERT Trained:
Helping Colleagues and Local Communities
and
Protecting
Cisco
Business!
© 2014 Cisco and Strategic BCP. All rights reserved
Cisco Confidential
27
• At Cisco, we Respond to Mir3 status check to update safety status.
• Use Emergency Contact card to connect with your household
members (handout).
• Follow your group's Emergency Procedures.
• Cisco IT Command Center and Cisco IT Staff launch DR plans to
Recover Cisco Disaster Recovery Production Data Center!
© 2014 Cisco and Strategic BCP. All rights reserved
Cisco Confidential
28
People
Best in Class
Technology
© 2014 Cisco and Strategic BCP. All rights reserved
IT Resiliency Operations
Availability - Business
Interruptions Recovery
Cisco Confidential
29
Thank you.