Contingency Audits and Business Continuity
Increasing need for Telecoms DR planning
With the recent increase in terrorism, business has once again been reminded of the need for effective disaster recovery. The advent of the new millennium and the associated predictions had seen improved focus on contingency planning as companies sought advice and technology aimed at reducing the likelihood of any interruption to business continuity.
As it eventuated the predictions concerning the Y2K bug were largely exaggerated, but it’s arguable that some of the effects of Y2K were mitigated by effective DR and contingency having been put in place. The threats to business continuity remain given the heightened security alerts and the increasing environmental concerns.
Telecoms Contingency Auditing
Once a business communications contingency plan has been instituted it needs to remain effective and as such regular auditing is necessary, both to ensure that each aspect of the DR plan is pertinent to the current state of the business concerned and it’s telecoms infrastructure, also that each aspect of the comms infrastructure is operating at maximum efficiency and if costs can be reduced.
The contingency audit will result in an effectiveness assessment covering both the unique aspects of a telecoms DR plan, plus an overview for the entire business continuity strategy. Diligent auditing will produce cost savings and improve efficiency, more than compensating for the time and expense involved.
The Audit Process
The early stages of the audit should review the DR plan development i.e. the circumstances surrounding the planning and implementation of the telecoms recovery plan, including ascertaining whether there were any shortcomings or bias in the development process itself.
With a recovery plan that has been developed considering each critical area individually there may be significant failings in overall impact, with each area focused on immediate disaster consequences and with insufficient attention paid to the overall business objective and it’s effective continuation.
Reviewing the background of each stage of the recovery plan development, including the personnel involved, a comprehensive audit will produce recommendations on allowing and adjusting for any bias which reduces the effectiveness of the DR plan.
The recovery plan should also review any changes in perceived threats against business continuity or any shift in risk levels since the initiation of the DR plan or since the previous audit.
Continued optimization of the DR plan via regular auditing ensures continuity is protected with business and service level agreements being maintained.
Telecoms Providers
It is worthwhile to establish if chosen networks and providers continue to offer the most cost effective services. With many telecoms providers competing for business and offering differently structured plans entailing reductions when combining services, an audit can be useful in establishing the most cost effective options for continuation of a telecoms recovery plan.
| Contingency Audit Summary |
| |
Audit DR plan development pertaining to business communications infrastructure
Clarification of terminology
Assess any bias in the development of the recovery plan
Evaluate the personnel involved in the DR development process
Review of the critical comms services accommodated in the contingency plan
Review of risk assessment and business impact analysis of comms downtime
Contingency audit covering overall structure of the telecom recovery plan:
Establish current threats to continuity
Threat pre-emption to mitigate likelihood of comms outage
Assess management role during comms outage and evolving recovery
Evaluate preparedness including backup systems and staff readiness
Continuity of business communications during recovery period
Media and press information
Resumption of business with communications restored
Audit telecom recovery plan maintenance
Determination of cost effectiveness of associated telecoms services and providers
Auditing communications outage strategies:
Review of telecom backup and recovery systems
Management structure during outage
Assessment of staff involvement and positioning during outage
Communications backup systems both internal and external
Public relations and media liaison
Assessment of DR systems and off-site backup or outsourced hosted telecom services
Audit deployment of backup DR systems providing interim critical communications
Evaluate timing and level of restoration of communications with customers during outage
Review contingencies and effects of failure in backup systems
Assess return to full business communications:
Procedures for return to normal internal and external communications
Processing of enquiries and transactions not actioned during the outage
Systems for testing communications after recovery
Audit report recommendations for improvements to DR structure and costs
Review of documentation for comms DR systems and maintenance |
|