The Skeleton
Policy scaffold

Business Continuity and Disaster Recovery Policy

Sets how long the organisation can be without each service, how much data it can afford to lose, and who decides to invoke.

What it has to decide

  1. Recovery time and recovery point objectives, per service

    Per service, agreed with the business owner and not with IT. Objectives set by the technology function are aspirations; objectives agreed with the owner are commitments.

  2. Who may invoke, and on what threshold

    Invocation is expensive and reversing it is worse, so people hesitate. Name the role, give the threshold, and say that invoking in good faith and being wrong carries no penalty.

  3. Dependency mapping, including third parties

    A four hour objective on a service that depends on a supplier with a next-business-day commitment is not a four hour objective.

  4. Backup rules, including immutability and isolation

    State that at least one copy is offline or immutable. Ransomware targets the backup estate first, and an online backup is part of the blast radius rather than the recovery from it.

  5. Testing, with the type and cadence named

    Distinguish a restore test from a failover test from a full exercise. Most organisations test restores and describe it as continuity testing.

  6. Communications during an outage

    Who tells customers, on what channel, and what is said when there is nothing to report. The channel must not depend on the systems that are down.

How it is usually got wrong

  • Objectives were set once by IT, never agreed with the business, and are physically unachievable with the architecture in place.
  • Backups run successfully for years and a full restore has never been performed, so nobody knows how long one takes.
  • The continuity plan is stored on the file share that the plan exists to recover.
  • The plan assumes staff availability during a scenario that would plainly affect staff.
  • A supplier dependency has a weaker commitment than the service that depends on it, and nobody has reconciled the two.

Worked extract

What a decision looks like once it has been madeEvery service in the service catalogue carries a recovery time objective and a recovery point objective agreed in writing with its business owner and reviewed annually. Tier 1 services carry a recovery time objective of four hours and a recovery point objective of fifteen minutes. At least one backup copy of Tier 1 data is held in an immutable store that cannot be deleted or altered by any production credential, including any administrative credential. A full restoration test of each Tier 1 service is performed at least annually and the elapsed time is recorded and compared against the objective; where the tested time exceeds the objective, the objective or the architecture is changed, and the gap is not carried forward. The continuity plan is maintained in a form retrievable without access to corporate systems. Any member of the executive may invoke, and invoking in good faith on incomplete information is explicitly supported.