10.08.2015 Views

Risico’s van een gevirtualiseerde IT-omgeving

Risico's van een gevirtualiseerde IT-omgeving - Vurore

Risico's van een gevirtualiseerde IT-omgeving - Vurore

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Risico’s</strong> <strong>van</strong> <strong>een</strong> <strong>gevirtualiseerde</strong> <strong>IT</strong>-<strong>omgeving</strong> Possen & Ulrich----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ProcessnumberProcessControlobjectivenumberControl objectiveControl objective descriptionSLAsAccompany all exception reports with recommendations for corrective action.DS04DS04DS04Ensure continuousserviceEnsure continuousserviceEnsure continuousserviceDS4.1 <strong>IT</strong> Continuity Framework Develop a framework for <strong>IT</strong> continuity to support enterprisewide businesscontinuity management using a consistent process. The objective of theframework should be to assist in determining the required resilience of theinfrastructure and to drive the development of disaster recovery and <strong>IT</strong>contingency plans. The framework should address the organisational structurefor continuity management, covering the roles, tasks and responsibilities ofinternal and external service providers, their management and theircustomers, and the planning processes that create the rules and structures todocument, test and execute the disaster recovery and <strong>IT</strong> contingency plans.The plan should also address items such as the identification of criticalresources, noting key dependencies, the monitoring and reporting of theavailability of critical resources, alternative processing, and the principles ofbackup and recovery.DS4.2 <strong>IT</strong> Continuity Plans Develop <strong>IT</strong> continuity plans based on the framework and designed to reducethe impact of a major disruption on key business functions and processes. Theplans should be based on risk understanding of potential business impacts andaddress requirements for resilience, alternative processing and recoverycapability of all critical <strong>IT</strong> services. They should also cover usage guidelines,roles and responsibilities, procedures, communication processes, and thetesting approach.DS4.3 Critical <strong>IT</strong> Resources Focus attention on items specified as most critical in the <strong>IT</strong> continuity plan tobuild in resilience and establish priorities in recovery situations. Avoid thedistraction of recovering less-critical items and ensure response and recoveryin line with prioritised business needs, while ensuring that costs are kept at anacceptable level and complying with regulatory and contractual requirements.Consider resilience, response and recovery requirements for different tiers,e.g., one to four hours, four to 24 hours, more than 24 hours and criticalbusiness operational periods.----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------Pagina 116

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!