EDUCATION · CONTINUITY · RECOVERY

💾 Continuity, backup and emergency recovery (DR)

Six topics on how an organisation experiences interference - from backup to full business continuity - by international practice (ISO 22301, ISO/IEC 27031, NIST SP 800-34). Figures and deadlines are illustrative, for training.

Basic concepts and scope

Backup - IT recovery - business continuity

Nepārtrauktības disciplīnu ligzdošana Trīs koncentriskas jomas: rezerves kopija ir daļa no avārijas atkopšanas, kas ir daļa no darbības nepārtrauktības; katrai savs jautājums un mērogs. Trīs disciplīnas, viena mērķa - izdzīvot traucējumu Katrs slānis ietver iekšējo, bet risina plašāku jautājumu Darbības nepārtrauktība (BCP) · visa organizācija Cilvēki · procesi · telpas · piegādātāji · komunikācija · IT Avārijas atkopšana (DR) · IT sistēmas Serveri · tīkls · lietojumi · datu centri · mākonis Rezerves kopija · dati Datu kopijas, no kurām atjaunot Kopija nav atkopšana, kamēr tā nav pārbaudīta ar atjaunošanu 3-2-1 · nemaināma · ārpus vietas · šifrēta BCP: vai bizness strādā? DR: vai sistēmas atgriežas? Kopija: vai dati ir? ISO 22301 (BCP) · ISO/IEC 27031 + NIST SP 800-34 (IT DR) · ISO 27002 8.13

Backup answers to "whether data is" - DR - "or systems return," BCP - "or business continues to work." Copies without recovery plan and plan without verified copies both fall into a real disorder.

Application

Common Language of Management and IT: When it comes to data, when about systems and when about the whole business. Do not confuse layers - each one has its own responsibility and budget.

Reference

ISO 22301:2019 (BCMS) · ISO/IEC 27031:2011 (IRBC) · NIST SP 800-34 Rev.1 · ISO/IEC 27002:2022 (8.13, 8.14, 5.29, 5.30).

Safety Note

The most common mistake - 'we have backups, so we are protected'. A copy without a regular renewal test is an assumption, not a guarantee.

Recovery objectives and business impact analysis

RPO ← incident → RTO, and where they are determined by BIA

RPO un RTO ap incidenta brīdi Laika ass ar incidentu centrā; pa kreisi RPO līdz pēdējai kopijai (datu zudums), pa labi RTO līdz atjaunotai darbībai; zem tās MTPD un biznesa ietekmes analīzes soļi. Atkopšanas mērķi ap incidenta brīdi RPO skatās atpakaļ (cik datu zūd), RTO skatās uz priekšu (cik ilgi stāv) Incidents t = 0 Pēdējā kopija RPO = maksimālais datu zudums Darbība atjaunota RTO = maksimālais dīkstāves laiks MTPD rezerve (WRT) aiz MTPD - kaitējums kļūst neatgriezenisks retākas kopijas = lielāks RPO Biznesa ietekmes analīze (BIA) piešķir katram procesam tā RTO un RPO 1 · Kartē procesus kritiskās aktivitātes un to atkarības 2 · Vērtē ietekmi laikā (finanses, reput., juridiski, drošība) 3 · Nosaka MTPD pieļaujamais traucējuma logs 4 · Atvasina RTO/RPO mērķi < MTPD; vada stratēģiju ISO 22301 8.2 (BIA) · NIST SP 800-34 Rev. 1 (3.2 BIA) · RTO/RPO/MTPD/WRT

RTO and RFMO are not IT choices, but business decisions from BIA. Lower RTO/RPO costs more - therefore, targets are determined by the decline of the process, not by everyone alike.

Application

RFMOs determine how often copies should be made; RTO determines how fast recovery should be. Both together choose DR strategy and its cost.

Reference

ISO 22301:2019 (8.2.2 business impact analysis) · NIST SP 800-34 Rev. 1 · ISO/IEC 27031 (in the context of RTO/RPO IT).

Safety Note

"Nule" RTO and RFMO are theoretically attractive, but rarely economical. Set fair goals and test them - promised, but unachieved RTO is more dangerous than honest.

Copies strategy and sustainability

regulation 3-2-1-1-0, copy types and non-variability

3-2-1-1-0 rezerves kopiju noteikums un kopiju tipi Augšā 3-2-1-1-0 noteikuma pieci elementi; zem tiem trīs kopiju tipi (pilna, inkrementālā, diferenciālā) un nemaināmas kopijas skaidrojums. 3-2-1-1-0 noteikums un kopiju tipi Klasiskais 3-2-1 paplašināts pret izspiedējvīrusu un kļūdainu kopiju 3 kopijas oriģināls + 2 dublējumi 2 datu nesēju veidi disks · lente · mākonis 1 ārpus vietas cits objekts / reģions 1 nemaināma / bezsaistē air gap · WORM 0 kļūdu atjaunojot pārbaudīts restore Kopiju tipi - kompromiss starp kopēšanas ātrumu un atjaunošanas ātrumu Pilna (full) · Visi dati katru reizi · Lēnākā kopēšana, lielākā vieta · Ātrākā, vienkāršākā atjaunošana Bāze visām pārējām kopijām Inkrementālā · Izmaiņas kopš pēdējās kopijas · Ātrākā kopēšana, mazākā vieta · Atjauno visu ķēdi secīgi Viens pārtrūkums ķēdē = risks Diferenciālā · Izmaiņas kopš pēdējās pilnās · Vidēja vieta, aug līdz nākamai pilnai · Atjauno: pilna + viena diference Kompromiss starp abām Nemaināma kopija (immutable / WORM) un air gap Kopija, ko noteiktu laiku nevar mainīt vai dzēst - pat ar administratora tiesībām. Izspiedējvīruss šifrē tikai sasniedzamos datus - nemaināmā vai bezsaistes kopija paliek. GFS un PITR papildina. ISO/IEC 27002:2022 8.13 (informācijas rezerves kopēšana) · NIST SP 800-34 · CISA #StopRansomware

3-2-1 is a minimum; an additional fixed and offline copy (1) and verified renewal (0) is a modern response to the spying virus that targets directly on backup copies.

Application

Practical checklist copy for architecture: how many copies, to whom, where, how isolated and or checked. The choice of types balances the copying window against the speed of renewal.

Reference

ISO/IEC 27002:2022 8.13 · NIST SP 800-34 Rev. 1 · CISA #StopRansomware (constant, offline copies) · US-CERT 3-2-1 principle.

Safety Note

If backup copies are reachable from the same network with the same rights, the ejector viruses shall also destroy them. At least one copy shall be isolated and non-replaceable.

Emergency recovery strategies

Spectrum - less RTO/RPO, higher costs

Avārijas atkopšanas stratēģiju spektrs Četras stratēģijas no lētās rezerves kopēšanas un atjaunošanas līdz dārgai aktīvs-aktīvs konfigurācijai; augšup aug izmaksas, pa labi krīt RTO un RPO. DR stratēģiju spektrs Izvēlas pēc BIA - katram procesam tik daudz, cik prasa tā RTO/RPO Mazāks RTO / RPO (ātrāka atkopšana) → Izmaksas → Backup & Restore kopēt un atjaunot RTO stundas-dienas Pilot Light kritiskais kodols gatavs, pārējo mērogo pēc vajadzības Warm Standby samazināta kopija darbojas gaidgatavībā Active-Active pilna dublēšana, RTO/RPO tuvu nullei Lētās stratēģijas Atjauno no kopijām, kad vajag - zemas izmaksas, bet ilgs RTO un lielāks datu zudums (RPO). Der ne-kritiskiem procesiem ar plašu MTPD. NIST SP 800-34 Rev. 1 (rezerves vietas: cold/warm/hot) · ISO/IEC 27031 · nozares DR spektrs

There is no one-size-fits-all strategy - it is active for a critical payment process, it is enough for the archive to copy-and-renew. Often within one organization there are several.

Application

Helps to choose recovery architecture after budget and criticalness - from cheap copy-and-renew approaches to full duplication, each process according to BIA.

Reference

NIST SP 800-34 Rev.1 (cold / warm / hot site • ISO/IEC 27031 · Cloud DR models (Pilot Light, Warm Standby, Active-Active).

Safety Note

The hot reserve and active-active replicate the attack or damage immediately. Synchronous replication is not a back-up copy - a separate, time-shifted copy is also required.

Life Cycle of Continuity Management

ISO 22301 BCMS - and how it is checked

Darbības nepārtrauktības pārvaldības dzīves cikls Pieci soļi ciklā ar atgriezenisko cilpu no analīzes līdz uzturēšanai; zem tiem pārbaužu veidi no galda vingrinājuma līdz pilnai pārslēgšanai. BCMS dzīves cikls (ISO 22301, PDCA) Nepārtraukts - pārbaudes un mācības baro atpakaļ plānā 1 · Analīze BIA + riska novērtējums RTO/RPO/MTPD 2 · Stratēģija izvēlas risinājumus DR, rezerve, resursi pret MBCO 3 · Plāns BCP · DRP · lomas procedūras, kontakti eskalācija 4 · Pārbaude vingrinājumi un testi pierāda RTO/RPO 5 · Uzturēšana pārskata, atjauno pēc izmaiņām audits ⇢ mācības → labāks plāns Pārbaužu veidi - no lētas diskusijas līdz reālai pārslēgšanai Galda vingrinājums diskusija pēc scenārija zems risks, ātrs Caurstaigāšana soļu pārbaude praksē bez ražošanas ietekmes Paralēlais tests rezerve strādā līdzās ražošana neskarta Pilna pārslēgšana reāls failover augstākā pārliecība ISO 22301:2019 (8.5 vingrinājumu programma) · ISO 22313 · NIST SP 800-84 (testu vadlīnijas) Neparbaudīts plāns nav plāns - tā ir hipotēze

The cycle is continuous: each change in infrastructure, personal or processes can aging the plan. Regular inspections are the only way to know that RTO/RPO is realistic.

Application

Structure the continuity work over a manageable cycle that can be audited and certified (ISO 22301). The test ladder allows you to start cheap (table exercise) and grow to a real failover.

Reference

ISO 22301:2019 (BBCMS requirements) · ISO 22313:2020 (Guidelines) · NIST SP 800-34 · NIST SP 800-84 (testing and exercises).

Safety Note

A plan in a document stored only on an encrypted network may not be available during an incident. Critical procedures and contacts shall also be kept offline.

Standards, frameworks and compliance

ISO 22301 to NIS2 and DORA

Nepārtrauktības un atkopšanas standartu ainava Sešas standartu un ietvaru grupas divās rindās - starptautiskie ISO, NIST, ISO 27002 kontroles, ES atbilstība, nozares un plānu tipi. Standartu ainava Pārvaldības sistēma + tehniskā gatavība + kontroles + atbilstība ISO (nepārtrauktība) ISO 22301:2019 BCMS prasības (sertificējams) ISO 22313:2020 ieviešanas vadlīnijas ISO/IEC 27031 IKT gatavība (IRBC) NIST SP 800-34 Rev. 1 rezerves plānošana, BIA SP 800-84 testu un vingrinājumu programma CSF 2.0 Recover funkcija ISO 27002 kontroles 8.13 · rezerves kopēšana 8.14 · apstrādes dublēšana 5.29 · drošība traucējuma laikā 5.30 · IKT nepārtrauktība saista drošību ar nepārtrauktību ES / LV atbilstība NIS2 21. p. (2)(c) nepārtrauktība, rezerves, krīze saistošie normatīvie akti MK noteikumi Nr. 397 (LV) GDPR 32. p. pieejamības atjaunošana Nozaru DORA (ES) finanšu IKT noturība SOC 2 (pieejamība) pakalpojumu kritērijs BCI Good Practice nozares metodika Plānu tipi (NIST) BCP biznesa nepārtrauktība DRP IT avārijas atkopšana ISCP sistēmas ārkārtas plāns COOP darbības turpināšana Crisis Comms - krīzes komunikācija ISO 22301/22313/27031 · NIST SP 800-34/800-84 · ISO 27002 8.13/8.14/5.29/5.30 · NIS2 · DORA · saistošie normatīvie akti

Standards compatible, not competitive: ISO 22301 gives management systems, NIST SP 800-34 technical methodologies, ISO 27002 specific control, NIS2 and DORA legal obligations.

Application

Map to search for requirements and methodology: for management of ISO 22301, for technical implementation of NIST SP 800-34, for controls of ISO 27002, for compliance with NIS2 and DORA.

Reference

ISO 22301:2019 · ISO 22313:2020 · ISO/IEC 27031:2011 · NIST SP 800-34/800-84 · ISO/IEC 27002:2022 · NIS2 · DORA · binding national and international regulations.

Safety Note

Article 21 (2) (c) of the NIS2 makes continuity and reserve management a legal obligation for essential and important entities, not only good practice.

Abbreviations

All abbreviations used in the guide (original and meaning).

BCP
Business Continuity Plan - business continuity plan.
BCMS
Business Continuity Management System - Continuity Management System (ISO 22301).
DR / DRP
Disaster Recovery (Plan) - emergency recovery and its plan (IT systems).
BIA
Business Impact Analysis - Business Impact Analysis.
RTO
Recovery Time Objective - the permissible restoration time.
RPO
Recovery Point Objective - permissible amount of data loss during time.
MTPD / MAO
Maximum Tolerable Period of Disruption / Maximum Acceptable Outage - maximum permissible interference window.
WRT
Work Recovery Time - time to restore data and work after starting systems.
MBCO
Minimum Business Continuity Objective - minimum acceptable service level during the event.
3-2-1
3 copies, 2 media types, 1 out of the space (extended: +1 invariable, +0 error).
GFS
Grandfather-Father-Son - copy rotation (month/week/day).
PITR
Point-In-Time Recovery - renewal at any point through transaction logs.
WORM
Write Once Read Many - one-time writing, multiple-reading (invariable copy).
air gap
physically or logically isolated copy without network connection.
cold/warm/hot site
cold, warm and hot spare space - increasing readiness and costs (NIST).
Pilot Light
DR strategy - critical core ready, the rest measured as needed.
Warm Standby
DR strategy - reduced but working system copy ready.
Active-Active
DR Strategy - full duplication where both parties serve the work (RTO/RPO close to zero).
COOP
Continuity of Operations Plan (NIST).
ISCP
Information System Contingency Plan - Information System Emergency Plan (NIST).
IRBC
ICT readiness for business continuity (ISO/IEC 27031).
PDCA
Plan-Do-Check-Act - continuous improvement cycle.
CSF
Cybersecurity Framework - NIST cybersecurity framework (Recover function).
NIS2
Network and Information Security Directive 2.
DORA
Digital Operational Resilience Act - EU Financial Sector Resilience Regulation.
GDPR
General Data Protection Regulation - General Data Protection Regulation (32th p. - availability).
saistošie normatīvie akti
Cabinet Regulations No. 397 (Implementation of CIS2 in Latvia).
ISO 22301
international business continuity management standard.
NIST SP
NIST Special Publication.