In wake of the incessant rains in south India and the resultant flooding organizations had to put their ‘business continuity plans’ (BCP) into action. No sooner did the rains lash the relatively dry area did the city know of a new natural disaster that was getting unleashed. Coping with this new type of natural disaster required a BCP (business continuity plans) for most organizations in Chennai.
What is BCP?
‘Business continuity’ may be an InfoSec professional’s domain of expertise but it was the need of the hour in Chennai. ‘Business continuity’ is planning to continue businesses at another location after disaster strikes till repair of the original location is under way. It also involves dealing with partners, shareholders, customers and other important stakeholders without whom an organization will not be complete.
We will talk about the business continuity plan as outlined in the NIST publication. The NIST publications define security measures that can be adopted by organizations, business institutions and educational institutions. These publications help an organization develop a good security posture. The NIST 800-34 publication is the ‘Contingency planning guide for Federal Information systems’.
What are the steps in a BCP?
These are some of the steps as specified in the NIST 800-34 publication:
1. Develop the contingency planning policy A ‘policy’ starts an effective continuity plan. This policy serves as the guide for the BCP and assigns roles to perform the tasks.
2. Conduct the business impact analysis (BIA) BIA helps an organization to first identify key functions in an organization and prioritize them. Vulnerabilities, threats and risks are also calculated during this process.
3. Identify preventive controls Preventive controls are implemented to mitigate the risks identified by the BIA.
4. Create contingency strategies Effective recovery strategies have to be developed such that all systems can be brought back up after a disaster.
5. Develop an information system contingency plan This plan should involve steps to get the systems back to their original state.
6. Ensure plan testing, training, and exercises All BCP should be tested to be sure that they meet the desired goals and any gaps should be identified and resolved. Training and exercises should be imparted to all the employees to make sure that they behave in the appropriate manner.
7. Ensure plan maintenance. Every plan is successful only if it is maintained properly and updated on a regular basis. This should be documented reflecting the changes in the organization and other enhancements. (Contingency Planning Guide for Federal Information Systems, 2010)
How did firms in Chennai invoke their BCP?
- IBM having one-fifth of its Indian employees in Chennai moved key personnel to Bangalore, India. This enabled them to maintain business continuity and maintain 24×7 relations.
- Cognizant moved some of its employees to work locations within Chennai which were not badly affected by the floods. They also moved their employees to other cities as well in addition to allowing employees to work from home where possible. Some employees also volunteered to stay in office and work on critical projects.
- Infosys moved many of its employees to Bangalore and Hyderabad in addition to providing work from home where possible.
- HCL flooded by rains moved several of its employees to Noida after having to shut down the Chennai office temporarily.
- TCS gave the option of work from home to maintain client interactions.
- Wipro gave its Chennai employees the option of working from home. (Chennai rains leave Tech Inc marooned; firms like IBM, Cognizant, Infosys enforce contingency plans, relocate key staff )
Electrical systems were monitored, food and fuel were stocked, boats were arranged to enable movement within Chennai.
‘Business continuity plans’ are a necessity in today’s world as unthinkable disasters such as earthquakes, flood, tsunamis continue to rock our world.
- Top 20 Questions To Prepare For Certified Kubernetes Administrator Exam - August 16, 2024
- 10 AWS Services to Master for the AWS Developer Associate Exam - August 14, 2024
- Exam Tips for AWS Machine Learning Specialty Certification - August 7, 2024
- Best 15+ AWS Developer Associate hands-on labs in 2024 - July 24, 2024
- Containers vs Virtual Machines: Differences You Should Know - June 24, 2024
- Databricks Launched World’s Most Capable Large Language Model (LLM) - April 26, 2024
- What are the storage options available in Microsoft Azure? - March 14, 2024
- User’s Guide to Getting Started with Google Kubernetes Engine - March 1, 2024
Neat blog! Is your theme custom made or did you download it from somewhere? A design like yours with a few simple adjustements would really make my blog stand out. Please let me know where you got your theme. Bless you
Hey there! I’ve been reading your blog for a long time now and finally got the courage to go ahead Just wanted to say keep up the excellent work!