Names have been changed to protect both the innocent and the guilty. I am looking at the business continuity plan for Company A. I am not working for Company A or any organization that would have Company A as a critical vendor â although Company Aâs services most definitely fall into the âcritical vendorâ category. So why do I have the plan on my computer? Someone at Company A breached corporate security.
Iâm Honest, But . . .
- The information on my notebook basically is Company Aâs disaster response plan. In truth, itâs a pretty good plan.
- If I was working for an organization that had Company A as a critical vendor, I would be delighted to see the plan.
- If I was working in the agency that regulates Company Aâs business, I would be delighted to see the plan.
- By the same token, if I was a disgruntled Company A employee, ex-employee, competitor, or just someone who wants to make a âstatementâ at Company Aâs expense, the plan could be just the tool I need.
- DRJâs pages have been the venue for plan security on several occasions, but none of those occasions addressed the âpublic plan,â a plan which meets client and regulator requirements but maintains the level of secrecy needed to protect the Company As of the world from prying eyes.
- We need to find a way to create this âpublic planâ as painlessly and economically as possible.
What Does a Planner Need to See
Obviously, a planner would like to see the entire plan, from proposal to final deliverable.
What better way to improve the plannerâs effort than by looking at othersâ work?
The question, however, is what does the planner need to see to develop a reasonable level of confidence that the organization for which the plan was developed meets all the requirements.
For absolutely critical vendors, a client or regulator might be justified in demanding to see who provides the vendorâs critical services and backup. It may be sufficient that the primary vendor simply state, âMultiple vendors provide the critical materials.â As to a back-up operation, I would want to know what organization stands ready to assure that the vendor will meet its service level agreements (SLAs) with my organization.
Critical Information
As a planner, I want to see what the vendor plan includes.
Is it limited to business functions? It is IT-specific? Or is it an enterprise plan? I need to be certain all the functions the vendor uses to provide the products I depend upon are protected.
I want to know who is sponsoring the plan. Was the plan created because a regulatory agency said the vendor had to have a plan? If so, what does the regulation require?
Some agencies only require a âfeasibleâ plan. Demands to exercise and maintain the plan are absent.
Plans not exercised or maintained are not plans.
I want to know some critical dates. When was the plan created? When was it last updated?
If the plan was created more than a couple of years ago and the first update is still to be completed, the plan is not a plan.
If the plan was created more than a couple of years ago and there are annual updates, Iâm a little happier ⦠unless I know that the vendor has introduced changes in product, process, people, policies, etc.
All these things and others should trigger updates to the vendor plan.
I want to see when the plan was last exercised, and in general, what constituted the exercise.
Was it a desktop walk-through or did they âpull the switch?â Something in between?
While I donât need specifics â some things may be confidential â I want to know âgenericallyâ how the exercise went, where there problems discovered, and are they being addressed?
In addition to the âgenericâ exercise report, I want to know something about the exercise methodology. Is it staged, and if so, what stage is it in now? What happens if there is a âPâ change â product, process, people, policies, etc.
Equally critical, I want to know â again in generic terms â how the vendor intends to meet its SLAs with my organization. If it depends on vendors, I need to know how long it expects to continue this dependency. This will partially determine how much I want to know about the back up vendors.
It also may cause me to recommend contracting directly with alternate vendors and, if appropriate, increasing the on-hand supply of vendor products.
I want to see a generic overview of the vendorâs recovery plans. What are the priorities? Have all scenarios been considered? It makes no sense to replace damaged servers if there is no place to put them ⦠or anyone to use the data âserved upâ by the machines.
I also would like to see a sample of the response pages.
Given my documentation background, I have this âthingâ about clarity and comprehension. I want to see the KISS principle (Keep It Simple Stupid) in practice.
Interesting, But Not Necessary
From a plannerâs point of view, having the âwhole enchiladaâ is wonderful but hardly necessary.
The only reason I would want to see a contact list is to see when it was last updated. I would like to see an expurgated contact list, one listing response titles and perhaps ânormal businessâ titles.
Having a list of responder titles gives me the opportunity to see if most functions are listed. I also want to know that each position has both âprimaryâ and âalternateâ staffing.
Having a list of ârealâ names has one benefit: it would allow me to guess with a certain amount of accuracy if responders will be over-extended.
Telephone numbers, addresses, and other contact information should be hidden. As with the vendor plan that kicked off this exercise, if the information falls into the wrong hands, anything can happen, from nuisance calls to physical attacks on personnel and their families.
While I want to see a response template, I donât need to see actual response instructions. (Actually I do; it would let me â or an appropriate subject matter expert â see if a process or procedure is complete).
The business impact analysis is something in which a planner is interested for its educational value, but as a tool to rate a plan, of little use. Most of what I want to know will be covered in the plan overview, which I do want to read.
The risk avoidance and mitigation program â what is recommended, what will be implemented, and when â again is something that would be nice for educational purposes but something which could â and should it fall into the wrong hands â be detrimental to the vendor.
Non-disclosure agreements are worthless. They may have some legal weight, but by the time the matter is settled in court, enough damage may have been done to an organization that a massive revision of processes, procedures, policies, etc. is needed to restore confidentiality.
Two Documents, One Plan
It is possible to meet both private and public plan requirements with one document (set).
The tools needed are a good word processor that has a âhidden textâ feature, an editor with a good eye, and a PDF generator. Free tools are fine, but pay the editor handsomely.
The trick is to create the complete plan â the controlled internal document â with the âsanitizedâ version in mind.
Once the plan is complete and approved, the editor goes over the document to âhideâ any sensitive information. The information still remains in the word processor file and is available to anyone who takes the time to âunhideâ it.
The PDF generate takes a âpictureâ of the visible word processor file. The hidden content is ignored.
The sanitized plan is available to share as a data file or printed out as hard copy.
With a little thought, organizations cannot only advertise that they have plans in place, they can confidently provide evidence to support the claim without sacrificing security.
