Ongoing Operations conducts hundreds of Disaster Recovery Tests for Credit Unions every year. Our tests are designed to be much more realistic than testing from 10 or 15 years ago. Credit Union Disaster Recovery Testing can be very complex and should be taken in intervals. If you have never conducted Disaster Recovery Tests before we recommend following a five step program to gradually increase the scope and complexity of the test.
The process follows five key Areas:
- Process – Start with making sure you do a tabletop exercise first. This ensures your staff have a basic understanding of the recovery process. We find that Credit Unions have between 75 and 150 different business processes.
- Systems – Have your IT Department recover servers, data, and telecom independently of the rest of the organization. Make sure they can meet established RPO and RTO objectives.
- Combine Process and Systems – Conduct a Disaster Recovery Test that combines the human and technology elements into one Test. This will be much harder and is a significant step forward in your testing process.
- Improve on Step 3 by adding realism to the scenario and complexity by simulating what would really happen in a disaster
- Move to Live – Conduct a full failover and failback using your recovery solutions. Very few clients ever get to this as it does include some risk and can be disruptive. However it is the best way to validate and establish expectations for a real event.
Outside of the 5 step process above – each test that Ongoing Operations conducts is designed to accomplish ten key criteria. Ongoing Operations will present our Standard Scope of Work for a Credit Union Disaster Recovery test and then will work with the Credit Union to tailor it for your specific requirements. The Ongoing Operations testing methodology is designed to accomplish the following:
Ten Key Goals
- Validate your Business Impact Analysis
- Improve your Crisis Management Plan
- Validate you can meet your RPO’s (Recovery Point Objectives)
- Validate you can meet your RTO’s (Recovery Time Objectives)
- Establish standard Recovery Procedures (in case you are gone in a disaster)
- Determine if your Telecommunication plan can handle your disaster scenario
- Determine if you can connect to critical third party providers (Connector)
- Uncover problems or flaws in your Disaster Recovery Program
- Train your IT Department and Organization on your Disaster Recovery Solution
- Establish confidence and value with the solutions you have purchased
Click here for an outline of the FFIEC guidelines on Disaster Recovery Testing:
In general we find it takes a few hours of effort to properly scope and design the test. The actual disaster recovery test can take up to two full days depending on the depth. Many of our clients test multiple times in a year.
Are you looking for ways to engage your staff in your business continuity program? Are you looking for ways to improve your disaster recovery solution? If you have these or other questions please fill out this quick form: