You have been assigned to a large cross-functional team


Case Study : Integrating Disaster Recovery / IT Service Continuity with Information Technology Governance Frameworks

Case Scenario:

You have been assigned to a large, cross-functional team which is investigating adopting a new governance framework for your company's Information Technology governance program.

Your first assignment as a member of this team is to research and write a 2 to 3 page white paper which discussesone of the Chief Information Security Officer (CISO) functional areas.

The purpose of this white paper is to "fill in the gaps" for team members from other areas of the company who are not familiar with the functions and responsibilities of the Office of the Chief Information Security Officer.

Your assigned CISO functional area is:Disaster Recovery/ IT Service Continuity (IT Service Continuity is a subset of Business Continuity). Your white paper must address the planning, implementation, and execution aspects of this CISO functional area.

Your audience will be familiar with the general requirements forbusiness continuity planning (BCP), business impact analysis (BIA), and continuity/recovery strategies for business operations (e.g. restore in place, alternate worksite, etc.).

Your readers will NOT have in-depth knowledge of the requirements / implementation strategies which are specific to restoring IT services which support the critical functions of the business (as identified in a BIA).

Research:

1. Read / Review the Week 3 readings:

2. Find three or more additional sources which provide information about best practices for IT Service Continuity / Disaster Recovery planning, implementation, and execution.

For the purposes of this assignment, implementation means the advance work necessary to implement recovery plans by acquiring or contracting for products, services, infrastructures, and facilities. Execution means activating the DR/BCP plans and overseeing the recovery operations.

Write:

Using standard terminology (see case study #1), write a two to three page summary of your research. At a minimum, your summary must include the following:

1. An introduction or overview of disaster recovery / IT Service Continuity which provides definitions and addresses the reasons why cybersecurity should be specifically addressedin the company's DR/BCP strategies and plans. This introduction should be suitable for an executive audience.

2. A separatesectionwhich addresses the CISO & CISO staff roles and responsibilities during the planning phase of DR/BCP and IT Service Continuity. This section should include identification and discussion of best practices for addressing cybersecurity objectives in the planning process.

3. A separate section which addresses the CISO & CISO staff roles and responsibilities during the implementation phase of DR/BCP and IT Service Continuity. This section should include identification and discussion of best practices for ensuring that cybersecurity objectives are met during the implementationphase. The implementation phase includes such activities as acquisition and contracting.

4. A separate section which addresses the CISO & CISO staff roles and responsibilities during the execution phase of DR/BCP and IT Service Continuity.

This section should include identification and discussion of best practices for ensuring cybersecurity objectives are met during the executionphase. The execution phase includes such activities as activating the DR/BCP or IT Service Continuity plan(s) and overseeing recovery operations.

5. A closing section that provides a summary of the issues and recommendations regarding inclusion of Cybersecurity considerations in the company's DR/BCP strategies and plans.

Request for Solution File

Ask an Expert for Answer!!
Management Information Sys: You have been assigned to a large cross-functional team
Reference No:- TGS02691125

Expected delivery within 24 Hours