Frequently Asked Question
Purpose
The purpose of this Information Technology Disaster Recovery Policy is to define the framework and procedures that Chroma Colors Corporation will follow to ensure the recovery and continued operation of IT systems, applications, and critical data in the event of a disaster.
Scope
This policy applies to all IT resources, systems, and data across all Chroma Colors Corporation location in the United States, as well as to all employees, contractors, and third-party service providers who access these resources.
Objectives
- Minimize Downtime: Reduce downtime and ensure the prompt recovery of IT services following a disaster.
- Data Protection: Safeguard critical data and ensure its integrity and availability.
- Regulatory Compliance: Comply with relevant industry regulations and legal requirements regarding data security and business continuity.
- Risk Management: Identify, assess, and mitigate risks associated with IT system failures and disasters.
Responsibilities
Security & Operations Center (SOC)
- Scott Schweitzer – Sr. Infrastructure Engineer
- Michael Poltorak – Infrastructure Engineer
IT Executive Steering Committee (ITESC):
- Steve Kosovich – VP Information Technology
- Joe Herres - Chief Executive Officer
- LJ Baillargeon – Chief Financial Officer
- Peter Gallagher – VP Sales
- Gary Buckland – VP Operations
- Jim Walsh – VP Product Technology
- Cass Birchbauer – VP Human Resources
Risk Assessment
At a minimum an annual risk assessment is conducted to identify potential threats to IT systems, including natural disasters, cyberattacks, hardware failures, and human errors. Risks are prioritized based on the likelihood and potential impact.
Business Impact Analysis (BIA)
The following systems have been identified and categorized according to their business impact
Application | Status | Priority | RTO | RPO | Owner |
FILESERVER | Pass | 1 | 8 | 0.25 | Mike Poltorak |
BCDATA | Pass | 1 | 8 | 0.25 | Felipe Barranco |
GREAT PLAINS | Pass | 1 | 8 | 0.25 | Felipe Barranco |
TMM | Pass | 1 | 8 | 0.25 | Felipe Barranco |
VICINITY | Pass | 1 | 8 | 0.25 | Felipe Barranco |
MSSQL | Pass | 1 | 8 | 0.25 | Matt Patchin |
ACTIVE DIRECTORY | Pass | 1 | 8 | 24 | Scott Schweitzer |
DHCP | Pass | 1 | 8 | 24 | Scott Schweitzer |
DNS | Pass | 1 | 8 | 24 | Scott Schweitzer |
DUO | Pass | 1 | 8 | 24 | Scott Schweitzer |
WATCHGUARD | Pass | 1 | 8 | .25 | Scott Schweitzer |
OSTICKET | Pass | 1 | 8 | 0.25 | Steve Kosovich |
UVWINLAB | Pass | 2 | 24 | 0.25 | Eric Soder |
LISAM | Pass | 2 | 24 | 0.25 | Felipe Barranco |
BARTENDER | Pass | 2 | 24 | 24 | Mike Poltorak |
LABELVIEW | Pass | 2 | 24 | 24 | Mike Poltorak |
MS REMOTE APPS | Pass | 2 | 24 | 24 | Mike Poltorak |
NICE PRINT | Pass | 2 | 24 | 24 | Mike Poltorak |
PRINT SERVER | Pass | 2 | 24 | 24 | Mike Poltorak |
VPN | Pass | 2 | 24 | 24 | Scott Schweitzer |
ANCORA | Pass | 2 | 24 | 24 | Steve Kosovich |
CORE INTEGRATOR | Pass | 2 | 24 | 24 | Steve Kosovich |
EMPOWER | Pass | 2 | 24 | 24 | Steve Kosovich |
NEXTCLOUD | Pass | 2 | 24 | 24 | Steve Kosovich |
SHAREPOINT | Pass | 2 | 24 | 24 | Steve Kosovich |
DATACOLOR | Pass | 2 | 24 | 24 | Van Laskarides |
CORVU | Pass | 3 | 48 | 24 | Felipe Barranco |
SAGE | Pass | 3 | 48 | N/A | Felipe Barranco |
THOROUGHBRED | Pass | 3 | 48 | N/A | Felipe Barranco |
GitHub | Pass | 3 | 48 | 24 | Matt Patchin |
MCHTIME | Pass | 3 | 48 | 24 | Mike Poltorak |
SFTP | Pass | 3 | 48 | 24 | Mike Poltorak |
MS GATEWAY | Pass | 3 | 48 | 24 | Steve Kosovich |
WATCHGUARD DIMENSION | Pass | 3 | 48 | 24 | Scott Schweitzer |
Disaster Recovery Strategies
Data Backups:
- Regular Backups:
Implement a systematic schedule for daily, weekly, and monthly backups. Ensure that: - Incremental Backups: Only the data that has changed since the last backup is saved, reducing backup time and storage space.
- Full Backups:
Comprehensive backups are performed weekly or monthly to capture all data. - Multiple Backup Locations:
- On-Site Backup:
Use local servers to store backups for quick access in mild disruptions. - On-Site Replication: Use local servers to store server replicas for immediate access in mild disruptions.
- Off-Site Backup:
Store backups in a secure off-site data center to protect against local disasters (e.g., fire, flooding)
Alternative Work Locations:
Employees trained for remote work will have access to Remote desktops and secure connections to maintain operations.
Disaster Recovery Plan
Alerts and Notifications
- Monitoring: Continuous monitoring of IT infrastructure for potential disasters (e.g., natural disasters, cyber threats).
- Incident Notification:
Upon identification of a potential disaster, the SOC will assess the situation and authenticate the impacting event.
Activation of Disaster Recovery Procedures
Initial Assessment
- Conduct an immediate assessment to understand the extent of the damage to IT systems and data.
- Log the time and details of the incident and any immediate actions taken.
Notification of Stakeholders
- Inform Team Members:
Notify SOC members via email and phone. - Notify Management:
The SOC Lead will inform ITESC senior management (CEO and other executives) of the situation and action plan.
Identification
- Detect the Incident: Utilize security monitoring tools to identify suspicious activities or security breaches promptly.
- Assess the Scope: Determine the nature and scope of the incident. Identify affected systems, data, and the potential impact on business operations.
Containment
- Immediate Containment: Implement short-term containment measures to prevent the spread of the incident. This may include:
- Disconnecting affected systems from the network.
- Blocking malicious IP addresses or domains.
- Changing passwords and access credentials for affected accounts.
- Long-Term Containment: Maintain business operations while implementing longer-term strategies to resolve the incident, such as applying patches or reconfiguring firewalls.
Eradication
- Identify Root Cause: Investigate to understand how the incident occurred and what vulnerabilities were exploited.
- Remove Threats: Eliminate any identified threats, malware, or unauthorized access points from the systems.
- System Hardening: Implement security measures to prevent future occurrences, such as patching vulnerabilities, updating software, and enhancing network security configurations.
Recovery
- Restore Affected Systems: Begin the process of restoring systems and services to normal operation. This may involve:
- Restoring data from backups (ensure backups were not compromised).
- Reinstalling clean versions of software and applications.
- Verifying the integrity of recovered systems and data before bringing them back online.
- Monitoring: Continue to monitor systems closely for any signs of recurring issues or unauthorized activities.
Communication
- Internal Communication: Keep stakeholders informed regarding the incident, response actions, and any required changes to processes or responsibilities.
- External Communication: If applicable, prepare communication for customers, clients, partners, and regulatory authorities regarding the incident, including information about potential data breaches or impacts on services.
Documentation
- Record Everything: Document the entire incident, including detection, containment, eradication, and recovery steps taken. Include timelines, personnel involved, and specific actions.
- Prepare an Incident Report: Create a detailed incident report summarizing the findings, actions taken, impact assessment, and recommendations for improvements.
Post Incident Review
- Conduct a post-incident review with the incident response team and stakeholders to analyze the response process. Identify Areas for Improvement, discuss what went well, what did not, and how processes can be improved for future incidents.
- Update Policies and Procedures: Revise the incident response plan, security policies, and training materials based on lessons learned and identified gaps.