DISASTER RECOVERY PLAN
FOR DATA RECOVERY FROM A
CYBERATTACK
BY: JAMES BOHL, NISHEETH AGRAWAL, SATISH LAKSHMANAN, AND STEVE REED
Team 1
Bullseye Corporation
B
Corp.
Bullseye
DRP- PURPOSE AND SCOPE
 Purpose of this DRP is to provide a detailed guide for
the DR team and other teams who may be involved
 Scope of this DRP is cyber attacks on customer and
employee data
 Some data is encrypted thus reducing the risk
 Customer general information – no encryption
 Customer login, credit card information – encrypted
 Employee general information – not encrypted
 Employee personal information - encrypted
B
Corp.
Bullseye
DR PLAN OBJECTIVES
 Identify the risks of the systems security attack
 Define teams
 Provide recovery procedures including recovery
checklists for cyber-attacks
 Provide company policies for disaster recovery
 Have the right tools for our teams to do the appropriate
tasks
B
Corp.
Bullseye
ASSUMPTIONS
 Various teams are already created – they are identified
and addressed in this document
 Corporate management structure is identified in other
documents
 Network plan and security detail as well as “how to
protect” is documented in other documents that are
available to DRP teams
B
Corp.
Bullseye
INCIDENT – DISASTER ESCALATION PROCESS
INICIDENT
RESPONSE
TEAM (IR TEAM)
Incident is escalated to
disaster after IR team
assessment
IR Team notifies DRT of the
declared disaster. DRT
evaluates disaster
independent of IR plan.
Is the disaster caused by an
EXTERNAL source?
INTERNAL
Assign task
to INTERNAL
Disaster
Team (IDT)
EXTERNAL
NO YES
DISASTER
RECOVERY
TEAM (DRT)
Report to
Human
Resources (HR)
department
Reports to Public
Relations (PR)
department
EDT Activates DRP:
Stop the attack: isolate, quarantine,
shutdown the breached access.
Assign task
to EXTERNAL
Disaster
Team (EDT)
B
Corp.
Bullseye
DISASTER RESPONSE PHASES
RESPONSE PHASE
Initial
Assessment
Manage
Communications
with Employees
& Stakeholders
Contain Damage:
Protect the database
and secure the
network
Continue
planning for
restoration
Identify
additional
needed
resources
Finalize
implementation of
primary functions
Initialize implementation
of primary functions, i.e.
recovery phase and
secondary functions, i.e.
hot site
Recover Critical
Business
Functions
Coordinate data
recovery efforts
Acquire Resources to
replace damaged /
destroyed equipment
Evaluate need
to implement
BC Plan
RECCOVERY PHASE RESUMPTION PHASE RESTORATION PHASE
Restore data at
the primary
site while hot
site handles
critical
operations
Restore data
from the tapes
both from the
backup center
and hot site
Restore
normal
operations at
the primary
site
Stand down DR
team, conduct
after action
review
Continue
recovery and
restoration at
primary site
DISASTER RESPONSE PHASES
B
Corp.
Bullseye
DISASTER RESPONSE
 Identify the disaster
 Contact proper response team leads
 Contain the disaster as much as possible
 Conduct damage assessment once contained
 Determine the resources and immediate funding needs
 Update the management team regarding damage
 Contact recovery and restoration teams
B
Corp.
Bullseye
DISASTER RESPONSE
 Begin evidence collection (Forensics team only)
 Eradicate the vulnerabilities and backdoors that may
have caused the disaster
 Begin system cleanup and data recovery
 Document the disaster and document any updates to
this document
B
Corp.
Bullseye
DISASTER RESPONSE
B
Corp.
Bullseye
DISASTER RECOVERY
 By this point:
 Infected portions of the system have been sanitized
 Vulnerabilities have been corrected
 The system removed from internet access (internal intranet is
made live if system is at all functional)
 The disaster recovery phase involves getting basic
operations up and running to a functional state. – focus is
DATA & SYSTEM RECOVERY.
 When the system has been breached and data
compromised, recovery and restoration of
company data along with systems operations
are critical.
B
Corp.
Bullseye
DISASTER RECOVERY
 Connect to the DRaaS department on secure
connection
 The DRaaS will:
 Attempt to recover as much current, undamaged data
from the system as possible
 Utilize proprietary software designed to repair as much
damaged data as possible
 Run proprietary diagnostics software on the system to
check for damage to the OS and hardware
B
Corp.
Bullseye
DISASTER RECOVERY
 DRT will Install additional storage drives if required
 DRaaS will:
 Restore system operations and applications to a
functional state
 Transfer recovered and repaired data along with
remaining data from offsite backup storage to unused
(and possibly newly installed) storage drives on the
system
B
Corp.
Bullseye
If The System Passes Diagnostics Inspection:
DISASTER RECOVERY
 DRaaS will:
 Setup the off site recovery system’s critical operations
and applications: hardware, OS, ERP software,
networking, etc. - at warm site
 Transfer recovered and repaired data along with
remaining data from offsite backup storage to recovery
system at warm site
B
Corp.
Bullseye
If The System DOES NOT Pass Diagnostics
Inspection:
DISASTER RESUMPTION
 Begin the process of resuming the operations
 Most critical capabilities during this phase
 Database rebuilding from backup
 Network security resumption and repair
 Resumption phase occurs in parallel with initial
response and recovery
 Prioritization of activities in this phase is key
B
Corp.
Bullseye
DISASTER RESUMPTION
 Critical steps:
 Establish data backup schedule per corporate procedures
 Implement hot site if needed
 Brief senior management on hot site activation
 Hot site ready for company data operations
 Begin repair of critical operations at primary site
 Keep workforce / management informed on progress of
the primary site
B
Corp.
Bullseye
Corrupt
Data
DISASTER RESTORATION
 Primary purpose
 Normalize business operations
 Return the organization to its pre-disaster state
 At end state, data operations and network security may have to change to
prevent future disasters
 Critical steps:
 Data backup from original site and hot site must be restored to the
main servers at primary site; hot site handles critical operations
 Transport backup tapes from the backup center, hot site, and original
data farm to the disaster/primary site and restore on new servers
 Restored data is backed up; data backup policy in effect
 Run queries to ensure all databases are restored
 Prepare restoration report
 Conduct after action review
B
Corp.
Bullseye
SUMMARY
 DRP guides Bulleye’s efforts recover from a cyber attack.
 Confidentiality, integrity, and availability are key aspects of our managed data to
ensure success.
 This standard builds confidence in our customers, stakeholders, and employees.
 Response Phase: stop the breach; contain the damage.
 Recovery Phase: focus on our most critical business functions and assets;
immediate recovery of databases and their proper security.
 Resumption Phase: determine move or no move to hot site; initiate
move if needed; regain primary and secondary business functions.
 Restoration Phase: merge data from hot site and original site into single database.
 IMPORTANT…keep employees informed throughout the disaster recovery
process.
B
Corp.
Bullseye

More Related Content

PPTX
Business continuity
PPTX
Business continuity & disaster recovery planning (BCP & DRP)
PDF
Business Continuity Planning
PPTX
Business Continuity Planning
PPT
What is business continuity planning-bcp
PDF
ISO 22301 Business Continuity Management
PPTX
Information Technology Disaster Planning
PPT
Business Continuity Planning Presentation Overview
Business continuity
Business continuity & disaster recovery planning (BCP & DRP)
Business Continuity Planning
Business Continuity Planning
What is business continuity planning-bcp
ISO 22301 Business Continuity Management
Information Technology Disaster Planning
Business Continuity Planning Presentation Overview

What's hot (20)

DOCX
Disaster Recovery Plan
DOC
Example business continuity plan
PDF
NQA - ISO 27001 Implementation Guide
PDF
Developing and Managing Business Continuity Plan (BCP)
PPT
Business Continuity And Disaster Recovery Notes
PDF
IT Control Objectives for SOX
PPTX
Business Continuity Planning
PPT
business-continuity-management-awareness-presentation-for-mampu2929
PDF
Assessing the impact of a disruption: Building an effective business impact a...
PPTX
Business continuity & Disaster recovery planing
PPTX
Business Continuity and Disaster Recovery Strategy
PDF
Implementing a Business Continuity Management System in Telecoms
PDF
Business Continuity Management PowerPoint Presentation Slides
PPT
Disaster Recovery Plan for IT
PPTX
How to write an IT DR plan
PPSX
BCMS Presentation1
PPT
Business Continuity Planning
PPTX
ISO 27701
PPTX
Business continuity planning and disaster recovery
PDF
Building a business impact analysis (bia) process a hands on blueprint
Disaster Recovery Plan
Example business continuity plan
NQA - ISO 27001 Implementation Guide
Developing and Managing Business Continuity Plan (BCP)
Business Continuity And Disaster Recovery Notes
IT Control Objectives for SOX
Business Continuity Planning
business-continuity-management-awareness-presentation-for-mampu2929
Assessing the impact of a disruption: Building an effective business impact a...
Business continuity & Disaster recovery planing
Business Continuity and Disaster Recovery Strategy
Implementing a Business Continuity Management System in Telecoms
Business Continuity Management PowerPoint Presentation Slides
Disaster Recovery Plan for IT
How to write an IT DR plan
BCMS Presentation1
Business Continuity Planning
ISO 27701
Business continuity planning and disaster recovery
Building a business impact analysis (bia) process a hands on blueprint
Ad

Viewers also liked (19)

PPT
Business Disaster Recovery Plan
PDF
Construction of a Disaster Recovery Plan with Business Only Broadband
PPT
Document the drp now
PPTX
Inodesain jayautama mandiri, ibm mte bandung
PDF
Budget 2016-proposals-on-direct-taxes - nclt
PPTX
Building High-scalable Enterprise Solutions,
PPTX
Living Lab Approach: Transformative and Integratve Climate Eductaion Initiati...
PDF
IoT Portal with PowerBI and SharePoint
PDF
Cloud transition - The Trivadis approach
PPTX
An Overview of Genomic Selection and Fertility
PDF
USECON RoX2016: Opening Remarks
PPSX
Mindfulness en el trabajo con Grupo P&A Consultores -Vigo
PDF
What makes a great product coach?
PDF
Thai Informatics Year In Review 2016 (November 25, 2016)
PPTX
Jboss Fuse Workshop 101 part 1
PDF
Do you have a DR plan in place: so, don't let a disaster defeat your business
PPTX
Disaster Recovery Plan / Enterprise Continuity Plan
PPTX
API Economy: 2016 Horizonwatch Trend Brief
PPT
Fuse overview
Business Disaster Recovery Plan
Construction of a Disaster Recovery Plan with Business Only Broadband
Document the drp now
Inodesain jayautama mandiri, ibm mte bandung
Budget 2016-proposals-on-direct-taxes - nclt
Building High-scalable Enterprise Solutions,
Living Lab Approach: Transformative and Integratve Climate Eductaion Initiati...
IoT Portal with PowerBI and SharePoint
Cloud transition - The Trivadis approach
An Overview of Genomic Selection and Fertility
USECON RoX2016: Opening Remarks
Mindfulness en el trabajo con Grupo P&A Consultores -Vigo
What makes a great product coach?
Thai Informatics Year In Review 2016 (November 25, 2016)
Jboss Fuse Workshop 101 part 1
Do you have a DR plan in place: so, don't let a disaster defeat your business
Disaster Recovery Plan / Enterprise Continuity Plan
API Economy: 2016 Horizonwatch Trend Brief
Fuse overview
Ad

Similar to disaster recovery-project_TEAM1 (20)

DOCX
IT4215-Info SecurityGroup-2-Disaster-Recovery-Plan-Final
DOCX
ISOL 533 - Information Security and Risk Management DIS.docx
PPTX
Bcp
DOCX
Joe Graziano – Challenge 2 Design Solution (Part 1)
PPT
Disaster Biz Resumpt
DOCX
COMPANY Disaster Recovery Plan (DRP) for [PRODU.docx
PPT
PPT
Business continuity planning
PDF
Pertemuan 15 disaster recovery plan
PPT
Fulcrum Group- Layer Your DR/BC
DOCX
Introductory PresentationGoals of .docx
PPT
IT Business Continuity Planning 2004
PPT
Misd chap 12 disaster recovery
PPTX
What is dr and bc 12-2017
PPTX
Risk crisis nad management
PPT
Drp Bcp Testing Alternatives
ODP
Network Admin D R P
PPT
Drp For Menora
PDF
DR Plan Implementation Experience: A Government Agency's Perspective by Inthr...
PDF
Disaster Recovery Development Strategy Business Measures Management Maintenance
IT4215-Info SecurityGroup-2-Disaster-Recovery-Plan-Final
ISOL 533 - Information Security and Risk Management DIS.docx
Bcp
Joe Graziano – Challenge 2 Design Solution (Part 1)
Disaster Biz Resumpt
COMPANY Disaster Recovery Plan (DRP) for [PRODU.docx
Business continuity planning
Pertemuan 15 disaster recovery plan
Fulcrum Group- Layer Your DR/BC
Introductory PresentationGoals of .docx
IT Business Continuity Planning 2004
Misd chap 12 disaster recovery
What is dr and bc 12-2017
Risk crisis nad management
Drp Bcp Testing Alternatives
Network Admin D R P
Drp For Menora
DR Plan Implementation Experience: A Government Agency's Perspective by Inthr...
Disaster Recovery Development Strategy Business Measures Management Maintenance

disaster recovery-project_TEAM1

  • 1. DISASTER RECOVERY PLAN FOR DATA RECOVERY FROM A CYBERATTACK BY: JAMES BOHL, NISHEETH AGRAWAL, SATISH LAKSHMANAN, AND STEVE REED Team 1 Bullseye Corporation B Corp. Bullseye
  • 2. DRP- PURPOSE AND SCOPE  Purpose of this DRP is to provide a detailed guide for the DR team and other teams who may be involved  Scope of this DRP is cyber attacks on customer and employee data  Some data is encrypted thus reducing the risk  Customer general information – no encryption  Customer login, credit card information – encrypted  Employee general information – not encrypted  Employee personal information - encrypted B Corp. Bullseye
  • 3. DR PLAN OBJECTIVES  Identify the risks of the systems security attack  Define teams  Provide recovery procedures including recovery checklists for cyber-attacks  Provide company policies for disaster recovery  Have the right tools for our teams to do the appropriate tasks B Corp. Bullseye
  • 4. ASSUMPTIONS  Various teams are already created – they are identified and addressed in this document  Corporate management structure is identified in other documents  Network plan and security detail as well as “how to protect” is documented in other documents that are available to DRP teams B Corp. Bullseye
  • 5. INCIDENT – DISASTER ESCALATION PROCESS INICIDENT RESPONSE TEAM (IR TEAM) Incident is escalated to disaster after IR team assessment IR Team notifies DRT of the declared disaster. DRT evaluates disaster independent of IR plan. Is the disaster caused by an EXTERNAL source? INTERNAL Assign task to INTERNAL Disaster Team (IDT) EXTERNAL NO YES DISASTER RECOVERY TEAM (DRT) Report to Human Resources (HR) department Reports to Public Relations (PR) department EDT Activates DRP: Stop the attack: isolate, quarantine, shutdown the breached access. Assign task to EXTERNAL Disaster Team (EDT) B Corp. Bullseye
  • 6. DISASTER RESPONSE PHASES RESPONSE PHASE Initial Assessment Manage Communications with Employees & Stakeholders Contain Damage: Protect the database and secure the network Continue planning for restoration Identify additional needed resources Finalize implementation of primary functions Initialize implementation of primary functions, i.e. recovery phase and secondary functions, i.e. hot site Recover Critical Business Functions Coordinate data recovery efforts Acquire Resources to replace damaged / destroyed equipment Evaluate need to implement BC Plan RECCOVERY PHASE RESUMPTION PHASE RESTORATION PHASE Restore data at the primary site while hot site handles critical operations Restore data from the tapes both from the backup center and hot site Restore normal operations at the primary site Stand down DR team, conduct after action review Continue recovery and restoration at primary site DISASTER RESPONSE PHASES B Corp. Bullseye
  • 7. DISASTER RESPONSE  Identify the disaster  Contact proper response team leads  Contain the disaster as much as possible  Conduct damage assessment once contained  Determine the resources and immediate funding needs  Update the management team regarding damage  Contact recovery and restoration teams B Corp. Bullseye
  • 8. DISASTER RESPONSE  Begin evidence collection (Forensics team only)  Eradicate the vulnerabilities and backdoors that may have caused the disaster  Begin system cleanup and data recovery  Document the disaster and document any updates to this document B Corp. Bullseye
  • 10. DISASTER RECOVERY  By this point:  Infected portions of the system have been sanitized  Vulnerabilities have been corrected  The system removed from internet access (internal intranet is made live if system is at all functional)  The disaster recovery phase involves getting basic operations up and running to a functional state. – focus is DATA & SYSTEM RECOVERY.  When the system has been breached and data compromised, recovery and restoration of company data along with systems operations are critical. B Corp. Bullseye
  • 11. DISASTER RECOVERY  Connect to the DRaaS department on secure connection  The DRaaS will:  Attempt to recover as much current, undamaged data from the system as possible  Utilize proprietary software designed to repair as much damaged data as possible  Run proprietary diagnostics software on the system to check for damage to the OS and hardware B Corp. Bullseye
  • 12. DISASTER RECOVERY  DRT will Install additional storage drives if required  DRaaS will:  Restore system operations and applications to a functional state  Transfer recovered and repaired data along with remaining data from offsite backup storage to unused (and possibly newly installed) storage drives on the system B Corp. Bullseye If The System Passes Diagnostics Inspection:
  • 13. DISASTER RECOVERY  DRaaS will:  Setup the off site recovery system’s critical operations and applications: hardware, OS, ERP software, networking, etc. - at warm site  Transfer recovered and repaired data along with remaining data from offsite backup storage to recovery system at warm site B Corp. Bullseye If The System DOES NOT Pass Diagnostics Inspection:
  • 14. DISASTER RESUMPTION  Begin the process of resuming the operations  Most critical capabilities during this phase  Database rebuilding from backup  Network security resumption and repair  Resumption phase occurs in parallel with initial response and recovery  Prioritization of activities in this phase is key B Corp. Bullseye
  • 15. DISASTER RESUMPTION  Critical steps:  Establish data backup schedule per corporate procedures  Implement hot site if needed  Brief senior management on hot site activation  Hot site ready for company data operations  Begin repair of critical operations at primary site  Keep workforce / management informed on progress of the primary site B Corp. Bullseye
  • 16. Corrupt Data DISASTER RESTORATION  Primary purpose  Normalize business operations  Return the organization to its pre-disaster state  At end state, data operations and network security may have to change to prevent future disasters  Critical steps:  Data backup from original site and hot site must be restored to the main servers at primary site; hot site handles critical operations  Transport backup tapes from the backup center, hot site, and original data farm to the disaster/primary site and restore on new servers  Restored data is backed up; data backup policy in effect  Run queries to ensure all databases are restored  Prepare restoration report  Conduct after action review B Corp. Bullseye
  • 17. SUMMARY  DRP guides Bulleye’s efforts recover from a cyber attack.  Confidentiality, integrity, and availability are key aspects of our managed data to ensure success.  This standard builds confidence in our customers, stakeholders, and employees.  Response Phase: stop the breach; contain the damage.  Recovery Phase: focus on our most critical business functions and assets; immediate recovery of databases and their proper security.  Resumption Phase: determine move or no move to hot site; initiate move if needed; regain primary and secondary business functions.  Restoration Phase: merge data from hot site and original site into single database.  IMPORTANT…keep employees informed throughout the disaster recovery process. B Corp. Bullseye