
Explore the fundamentals of business continuity and disaster recovery, define key terms, and outline the planning phases and purpose behind BCP and disaster recovery.
Understand why disaster recovery matters—from cyber incidents to natural disasters—and learn who requests recovery, how to plan, and how to comply with laws and regulations.
Identify and classify intellectual property and critical information assets to prevent leaks, then engage department leaders to map critical functions and implement business continuity planning.
Explore natural disasters like volcanoes, hurricanes, floods, fires, wildfires, and storms, and note that insurance plans vary, with you paying only for what you're protected.
Examine man-made disasters from terrorism and arson to IT failures such as hacking and ransomware, and learn how power outages, backups, ups and generators, and infrastructure disruptions threaten operations.
Business continuity planning (BCP) ensures an organization stays functional during disasters by prioritizing critical processes such as accounting, sales, and CRM, and conducting a business impact analysis.
Apply disaster recovery planning to major physical disruptions, including natural disasters, arson-caused fires, or events that disable facilities. Restore IT services and servers, and support business processes.
Discover the difference between bcp and drp by focusing on sustaining critical business processes during disruptions versus preparing equipment, procedures, and call trees for disaster recovery.
Explore business resumption, continuity of operations, information technology contingency, and crisis communications plans, including external relations, media notification, and cyber incident response with evidence preservation.
Outline the high-level phases of building a business continuity plan, from project initiation and business impact analysis to strategy development, implementation, testing, and ongoing maintenance.
Define the project scope, perform a business impact assessment, write the plan, obtain management approval, and begin implementation; then test and maintain the plan with annual updates.
Define the project scope in BCP step 1 by mapping the organization's operations and essential services, forming a cross-functional team, and planning resources and regulatory considerations for a multi-site program.
Perform a business impact assessment by surveying priorities, quantifying process importance and budget share, identifying natural and manmade risks, evaluating disruption and cost, and prioritizing resources for a final report.
Explore step 3 of the BCP: the actual continuity plan after identifying risks and critical processes, and demonstrate to management a strategy to survive disruptions.
Secure senior management approval and funding, then procure hardware and software, train staff, and implement with deployed resources, testing readiness, and ongoing adaptation.
Review the introduction to business continuity and key definitions. Identify the stages for business continuity planning, the purpose of both programs, and the overview of BCB and the planning phases.
Define project scope and planning by examining the organization's operations from a crisis perspective, assemble an internal crisis planning team, and assess resources, environment, and legal landscape across four stages.
Secure management support, define scope and objectives, form a cross-department team with a business continuity coordinator, plan milestones, and conduct business impact analysis with a budget for initiation phase.
Management involvement strengthens business continuity, requiring a legally sound business case, recovery plans, and cost-benefit analysis to justify an alternative site and executive accountability.
Executive management stays in the loop, approves final disaster recovery plans, and oversees budget to ensure plans are tested and funding is used efficiently.
Coordinate functional management to identify and prioritize critical systems and keep key stakeholders informed as recovery progress unfolds.
Stage one identifies and protects organizational services—IT, telecommunications, and email—while maintaining critical support, password changes via helpdesk, and perimeter defense with firewalls and intrusion detection, plus executive involvement during emergencies.
Select a cross-functional BCP team from core services and support departments, including IT specialists, security, and legal reps, to create, implement, and test recovery plans.
Senior management provides moral and financial support to the BCB team's plan, understands the process, and ensures initiation, monitoring, supervision, execution, and testing to help the organization survive.
Identify required resources for disaster recovery rollout, including tools, training, and hardware, and secure management backing. Plan to borrow resources from other organizations to support operations and network teams.
Define resource requirements with provisions and processes to mitigate risks in disaster recovery. Protect people, data centers, and infrastructure through hardening, backups, alternative sites, and secure networks.
Explore how federal, state, and local laws shape disaster recovery, including COOP requirements, HIPAA, PCI, SLAs, and the role of legal counsel in contracts and emergencies.
Explore legal and regulatory requirements for disaster recovery, including ISO/IEC standards, NIST guidelines for federal IT systems, and PCI DSS 3.2, with emphasis on recovery and continuity planning.
Executive management initiates, approves, and funds disaster recovery project, while the VCP committee handles planning, implementation, and testing; functional business units participate in implementation and testing, collaborating on the plan.
Identify critical IT dependencies and backup needs, monitor data feeds to financial institutions during restoration, safeguard offsite media, and maintain security and up-to-date inventory, even in emergencies.
Outline the scope, covering stage one operations and support, stage two BCB team with senior management approval, stage three resource assessment, and legal and regulatory landscape with an attorney.
Explore the quantitative and qualitative types of business impact analysis, identify priorities, assess risk likelihood and impact, prioritize resources, and generate a final report.
Identify critical resources and threats, assess likelihood and impact, and translate potential losses into a dollar figure for management to guide disaster recovery decisions.
Explore the two types of business impact analysis: quantitative decision making that assigns monetary value to resource impact, and qualitative assessments prioritizing outcomes into high, medium, or low.
Identify priorities in a business impact analysis by listing and ranking critical processes. Senior business unit managers collect input via surveys, interviews, workshops, or videoconferences, depending on organizational complexity.
Identify priorities by conducting a criticality survey that senior management fills out to highlight the most important systems or processes in their business units.
Identify priorities through a quantitative BIA by listing assets with dollar values, determining the maximum tolerable downtime (MTD), and setting recovery time objectives for each business function.
Identify natural risks that disrupt facilities and data centers, from power outages and weather events to earthquakes and floods, and assess their impact using 100-year floodplain concepts.
Identify manmade risks such as civil unrest, theft, fires, power outages, and transportation disruptions, plus malware threats like ransomware targeting critical IT systems.
Assess the likelihood and impact of disasters using weather bureau data to estimate the annualized rate of occurrence, then multiply damages by likelihood to prioritize Miami hurricanes versus Colorado snow.
Assess likelihood and impact using quantitative metrics such as exposure factor, single loss expectancy, and annualized loss expectancy to estimate yearly asset losses.
Assess qualitative likelihood and impact of security incidents on future business and trust. Explore cases of privacy breaches, downtime, and negative publicity shaping disaster recovery decisions.
Prioritize base business continuity resources by evaluating risks quantitatively and sorting them by impact to create a single, merged priority list from the BCB team and management reps.
Document and present recovery recommendations from the prioritized bia, compiling all material, identified critical support areas, and qualitative and quantitative impact statements to secure funding from management.
Explain to management the loss types—direct, indirect, and delayed—and how reputational damage, lost sales, and competitive advantage affect business continuity; include legal violations and income costs in BIA reporting.
Identify the maximum tolerable downtime (MTD) for various activity priorities, from critical two hours to non-essential thirty days, with normal seven days, important 72 hours, and urgent 24 hours.
Analyze interdependencies across operations from manufacturing to IT, identify essential functions and bottlenecks, present quantitative and qualitative threat data with rationale and alternative recovery methods.
In the disaster recovery engineer course, this demo shows how to locate NIST SP 800-34 business continuity planning samples, and outlines the contingency planning process, templates, and testing for recovery.
Summarizes the five phases of business impact analysis—identify priorities, identify risks, assess likelihood and impacts, prioritize resources, and report to management—alongside quantitative and qualitative analysis types.
Examine the policy cycle draft as a project management subtask, covering state strategy, development provisions, and processes, and conclude with insights on BCB and the object.
Document policy components and laws and standards and best practices for business continuity, perform gap analysis against business impact analysis, gain feedback and buy-in, and secure management approval before publishing.
Apply core project management principles to disaster recovery by securing funding and talent, then perform a SWOT analysis to identify strengths, weaknesses, opportunities, and threats.
Develop and implement a business continuity plan through continuity planning using Microsoft Project, Primavera, or a spreadsheet, guided by the business impact analysis to minimize impact and risk.
Develop a strategy to bridge the gap between business impact assessment and continuity planning, prioritizing concerns from the prioritization exercise and evaluating MTV estimates to identify acceptable risks and mitigations.
Identify provisions and processes within continuity planning, outlining how the BCB uses procedures to mitigate risk by safeguarding people, buildings, and infrastructure, and by deploying alternative sites and redundant systems.
Define areas of responsibility, assign tasks to the right people, and confirm authority for decisions and extraordinary expenses, while stressing training drills, communication, and documentation; prioritize critical systems over nice-to-haves.
Define BCP and DRP objectives, implement and test the plan, and document it for quick access. Conduct annual drills to train assigned personnel and improve the business continuity program.
Explore the FFIEC business continuity planning framework for financial institutions, including business impact analysis, risk assessment, plan development, testing, and governance for enterprise-wide resilience.
Review module 4 material for disaster recovery engineers, covering the VCP and related topics, and prepare for the next chapter.
Explore the approval and implementation of a BCP plan, then cover training and education, documentation, maintenance, and testing.
Develop a valid, reasonable, feasible BCP plan with resources and a realistic timeline. Secure senior management approval and cross-unit buy-in for funding and implementation.
Coordinate resources, train staff, and procure goods and services to implement the approved BCP, while writing contracts and maintaining a flexible maintenance program to adapt to change.
Invest in training and education for all personnel to align the team with the plan, prevent backlogs, and avoid costly remediation from untrained accounting.
Document the BCP process to capture lessons, track failures and frictions, and provide an emergency reference plus a historical record for future personnel.
Define BCP goals and priorities early in the documentation, reflect critical systems and business impact analysis, and communicate management's commitment to enterprise continuity to employees.
This lecture states that business continuity is everyone's responsibility from the start, linking risk assessment and business impact analysis to urgent procurement of a spare facility, database, and cost updates.
Examine how disaster recovery plans capture risks, acceptance decisions, and mitigation steps, with signed documents, responsible roles, notification procedures, vital records, backups, and emergency response guidelines.
Wrap up the VCP documentation with annual update cycles, reflect organizational and technology changes, run formal, trained disaster exercises, and keep teams engaged with clear checklists and pre-read materials.
Assess module five by detailing plan approval and funding, workforce training on roles, and documenting the career trail of evidence while maintaining and testing the disaster recovery plan.
Test and validate the disaster recovery plan after implementation, and schedule annual testing based on system criticality. Document test processes and types, and continuously update the plan.
Develop and execute an annual DRP test plan, detailing test scenarios, contact roles, backup and restore procedures, and alignment with PCI, ISO 27000, and other frameworks.
Explain why testing costs time and money, and how it informs management of recovery capabilities. Onboard leaders, verify backup site readiness, and train employees with clear procedures and emergency contacts.
Document the entire test process by scheduling, notifying participants, and outlining test steps, roles, scenarios, and required resources to ensure an efficient, well-prepared disaster recovery drill.
Explore test types from checklist to full interruption, including structure, walk-through simulation, and test pilot tests. Costs rise with depth, so choose tests based on needs and budget.
Distribute the plan to management for review to verify critical processes and procedures, enabling a preliminary sanity check before a real test and identifying potential loss of key personnel.
Structural walkthrough, or tabletop exercise, brings managers, admins, operators, and business owners together to role-play a disaster scenario and validate the recovery plan.
Conduct an assimilation simulation with real operational personnel working through simulated disasters to test immediate response, featuring actors and potential interruptions of non-critical activities.
Assess parallel testing by running the test backup site alongside main production, ensuring hardware, software, and databases function, can take load, and operators can execute cold process procedures smoothly.
Conduct a full interruption test by disconnecting the main site to validate the disaster recovery plan, acknowledging its high cost and environmental needs.
Maintain the data recovery plan by updating contacts, technology changes, management changes, and personnel shifts; review processes and external connections annually using the organization's BGP template.
Prioritize protecting life during emergencies by executing trained emergency responses and drills, appointing a communications lead, notifying authorities and security, and coordinating internal and external messaging.
Update and maintain BCP and DRP to reflect changes in infrastructure, hardware, software, and personnel, and embed maintenance into decision making while conducting regular audits and drills for emergency readiness.
Learn how the ready.gov business continuity planning suite helps organizations create, test, and maintain a scalable disaster recovery and business continuity plan with templates and training.
Review the importance of testing the DRP, document test processes, and explore different test types, while maintaining and updating the BCB and DRP plans to stay current.
Examine operational hardware options for different site types to enable backups, and explore cloud as an alternative data recovery location.
Execute the recovery and restoration functions with trained teams to keep IT and business operations running. Securely restore data from backups and reestablish operations at the original or secondary site.
Assess hardware reliability by examining MTBF as a predictor of failure, compare warranties for drive quality, and plan for MTTR, hot-swapping drives, and parity-driven data recovery in RAID setups.
Develop a comprehensive disaster recovery plan with a written document reviewed by top management, rehearsed and tested annually to minimize economic loss and reduce security exposures.
Develop a comprehensive disaster recovery plan to ensure orderly recovery, protect assets and personnel, and minimize liability and insurance costs through designated alternates and clear delegates.
Justify disaster recovery planning by budgeting for personnel, outsourcing, network recovery, and offsite storage. Learn from the 1982 Chicago flood and 9/11 to justify distant backup sites.
Explore disaster recovery through insurance coverage for vital records and documents and crime insurance for money and securities, noting databases, servers, and software used in data processing are not covered.
Explain property insurance options, including name peril and open peril policies, flood risk, and exclusions for disasters affecting businesses.
Compare replacement cost and actual cost valuation policies, outlining depreciation and current replacement costs that determine payouts for damaged or destroyed property.
Identify critical business units and functional priorities using the business impact analysis. Create a priority checklist with risk, cost, and mean time to recovery to set recovery objectives and milestones.
Learn crisis management and emergency communications strategies, including rapid internal and external updates, a crisis management team, ready-made public statements, and alternative channels during outages.
Implement disaster recovery plan by restoring work groups to their usual locations or to separate recovery facilities until the main operations facility is back online, ensuring continuity.
Explore the importance of backups within a disaster recovery plan. Outline current backup strategies, emphasize regular testing, and compare full, incremental, and differential backups, including offsite storage considerations.
Explain full backups as complete data copies that reset the archive bit; use incremental backups to copy only touched files, and differential backups to cover changes since the full backup.
Assess characteristics and wear of backup tapes and drives, check specs, and clean drives to prevent oxidation and dust. Formats include digital data storage, DAT, DHT, DLT, and open altie.
Schedule backups during low traffic to prevent site slowdowns, ensure scalable storage for growth, implement real-time backup options such as raid, clustering, or server mirroring, and test recovery.
Protect software assets with escrow by an independent third party, who holds the source code and activates if the developer fails to respond or the company ceases to exist.
Establish external communications channels, designate a CEO as spokesperson, and keep up-to-date utility and logistics contacts to ensure food, shelter, and equipment access during a disaster.
Explore alternate processing sites for disaster recovery, from cold to hot, rolling, service bureau, and multiple sites, prioritizing lowest cost and locating about 20 miles from the main site.
Maintain a cold site as an empty warehouse ready for equipment during an emergency, with no on-site hardware or IT resources, and bring in servers and tape drives.
Compare warm site options to hot sites, noting power, cooling, and computers are available but data copies lag and patching isn’t current, roughly twelve hours to full operation.
Explore hot sites as fully configured, 24/7 operational disaster recovery replicas of the main site, including file and print servers and workstations, with high costs and capacity considerations.
Mobile sites act as self-contained moving data centers, with servers, power, networking, and environmental control systems in trailers or other mobile units.
Explore service bureaus that rent computing power by the hour or day, providing tested backups, response time, availability, and recovery steps through a third-party insurance policy outsourcing option.
Organizations use multiple processing centers such as remote offices as redundant backup sites to reduce disaster impact when sites are far apart, though managing dispersed staff adds cost and complexity.
Explore redundancy through a company-owned redundant site, a mirror of the original, offering increased redundancy and employee convenience, at higher duplication costs for alternative office locations.
Mutual aid and assistance agreements enable organizations with similar hardware and software to share costs, management, information, equipment, and parts of facilities for outages or disruptions, under legally binding contracts.
Explore mutual aid and assistance agreements to gain cost-effective shared disaster recovery capacity, potentially limited, by piggybacking on others’ hardware and personnel, with clear contracts.
Implement transaction redundancy with database recovery and C2 logging to capture before and after images, enabling fault tolerance and rapid restoration; use off-site backups and remote journaling for integrity.
Explore remote mirroring as a high-cost, high-speed transaction redundancy solution that replicates data to multiple locations in seconds, enabling a fully redundant database with clustered servers.
Wrap up the recovery plan with an executive summary, department-specific plans, IT technical guides for backups and replicated databases, and team checklists, all bound in a red binder.
Develop and validate disaster recovery plans with executive summaries, emergency response, clear communications, contact details, backups and offsite storage, restoration procedures, and training for disaster recovery and business continuity teams.
Leverage cloud storage as part of disaster recovery by keeping enterprise data in cloud environments or private cloud shares, and follow IT security guidance to protect confidential data.
Review core disaster recovery strategies across operations, hardware, software, and multiple site types, including cloud storage, in this module seven recap.
VCP guides the creation of plans that ensure critical business functions withstand emergencies, with DRP disaster recovery planning helping you prepare, practice, and resume operations after a loss.
Apply business impact analysis to classify critical systems and assign dollar figures. Design and implement a business continuity plan, obtain management approval, and test it annually, integrating IT recovery strategies.
Explore references for disaster recovery and business continuity, including ISO standards for business continuity management, the federal contingency planning guide SP 800-34 rev. 1, and PCI DSS requirement 12.
The core aspect of any company crucial its success is information technology. All systems in a modern enterprise depend on the IT infrastructure. The need to have a detailed DR strategy is therefore KEY.
Being a Disaster Recovery Engineer (DRE) validates that you are prepared to work with businesses to create and implement disaster recovery and business continuity plans.
Those who are certified will be working, as a professional, with a business to prepare processes, policies and procedures to follow in the event of a disruption. You are important to keep a business’ critical operations running, which today heavily relies on its IT infrastructure. SIGN UP NOW!