The Structured External Assignment for this class will be the compilation of a completed Business Continuity Plan from the materials produced through the block. The Business Continuity Plan will be organized as follows and is worth 20% of your final grade:
- Management overview
- Business Continuity Plan deployment instructions
- Maintenance log
- Contact list
- Index
- An index page
- One section for each scenario covered in the Business Continuity Plan
- Supporting documentation
- BCP Policies
- Completed Business Impact Analysis
- Preventive Control recommendations
- Test Plan
- Change control process
The final Business Continuity Plan will be in a format presentable to management. Instructions contained in the document should be clear, simple, and usable by people responsible for implementing the plan. The rubric for this assignment can be viewed when clicking on the assignment link. #action=share SEC 6010 Planning for Information Security Project will be a running project. The information in this document will be used as a template to develop your business continuity/disaster recovery plan. Input the upcoming weeks’ projects into the attached continuity plan template to fulfill the requirements of the project. On week seven, a final draft of your business continuity/disaster recovery plan and PowerPoint of the plan will be submitted and graded per the rubrics assigned to that project.
Although there is no specific equation that must be followed to create continuity plans, there are best practices that have proven themselves over time. The National Institute of Standards and Technology (NIST) organization is responsible for developing these best practices and documenting them so that they are easily available to all. NIST outlines the following steps in its Special Publication 800-34, Continuity Planning Guide for Information Technology Systems:
- Develop the continuity planning policy statement: A formal department or agency policy provides the authority and guidance necessary to develop an effective continuity plan.
- Conduct the business impact analysis (BIA): The BIA helps to identify and prioritize critical IT systems and components. A template for developing the BIA is also provided to assist the user.
- Identify preventive controls: Measures taken to reduce the effects of system disruptions can increase system availability and reduce continuity life cycle costs.
- Develop recovery strategies: Thorough recovery strategies ensure that the system may be recovered quickly and effectively following a disruption.
- Develop an IT continuity plan: The continuity plan should contain detailed guidance and procedures for restoring a damaged system.
- Plan testing, training, and exercises: Testing the plan identifies planning gaps, whereas training prepares recovery personnel for plan activation; both activities improve plan effectiveness and overall agency preparedness.
- Plan maintenance: The plan should be a living document that is updated regularly to remain current with system enhancements.
Unsatisfactory Satisfactory Good Excellent Analysis Points Range:0 (0%) – 14 (14%)Does not present an analysis of the issues identified or demonstrate an understanding of the topic(s) and issue(s).Points Range:15 (15%) – 16 (16%)Presents a superficial analysis of some of the issues identified and demonstrates a somewhat acceptable understanding of the topic(s) and issue(s).Points Range:17 (17%) – 18 (18%)Presents a thorough analysis of most issues identified and demonstrates an accomplished understanding of the topic(s) and issue(s).Points Range:19 (19%) – 20 (20%)Presents an insightful and thorough analysis of all issues identified and demonstrates a sophisticated understanding of the topic(s) and issue(s).Evaluation Points Range:0 (0%) – 14 (14%)Makes no connection between the issues identified and the strategic concepts studied in the reading. Does not Support diagnosis and opinions with reasons and evidence; argument is one-sided and not objective.Points Range:15 (15%) – 16 (16%)Makes appropriate but somewhat vague connections between the issues and concepts studied in the reading; Demonstrates limited command of the strategic concepts and analytical tools studied. Supports diagnosis and opinions with limited reasons and evidence; presents a somewhat one-sided argument.Points Range:17 (17%) – 18 (18%)Makes appropriate connections between the issues identified and the strategic concepts studied in the reading; Demonstrates good command of the strategic concepts and analytical tools studied. Supports diagnosis and opinions with reasons and evidence; presents a fairly balanced view; interpretation is both reasonable and objective.Points Range:19 (19%) – 20 (20%)Makes appropriate and powerful connections between the issues identified and the strategic concepts studied in the reading; Demonstrates complete command of the strategic concepts and analytical tools studied. Supports diagnosis and opinions with strong arguments and evidence; presents a balanced and critical view; interpretation is both reasonable and objective.Recommendations Points Range:0 (0%) – 14 (14%)Does not present realistic or appropriate recommendations and offers no support from the information presented and concepts from the reading.Points Range:15 (15%) – 16 (16%)Presents realistic or appropriate recommendations supported by the information presented and concepts from the reading.Points Range:17 (17%) – 18 (18%)Presents specific, realistic, and appropriate recommendations supported by the information presented and concepts from the reading.Points Range:19 (19%) – 20 (20%)Presents detailed, realistic, and appropriate recommendations clearly supported by the information presented and concepts from the reading.Research Points Range:0 (0%) – 14 (14%)Does not supplement case study with research and documentation.Points Range:15 (15%) – 16 (16%)Supplements case study with limited research into the present situation of the company; provides limited documentation of sources consulted.Points Range:17 (17%) – 18 (18%)Supplements case study with relevant research into the present situation of the company; documents all sources of information.Points Range:19 (19%) – 20 (20%)Supplements case study with relevant and extensive research into the present situation of the company; clearly and thoroughly documents all sources of information.Writing Mechanics Points Range:0 (0%) – 14 (14%)Writing is extremely unfocused, rambling, or contains major errors; lacks detail and relevant data and information; extremely disorganized. Does not use APA guidelines.Points Range:15 (15%) – 16 (16%)Writing lacks clarity or conciseness and contains numerous errors; gives insufficient detail and relevant data and information; lacks organization. Reflects incomplete knowledge of APA guidelines.Points Range:17 (17%) – 18 (18%)Writing is accomplished in terms of clarity and conciseness and contains only a few errors; includes sufficient details and relevant data and information; well-organized. Uses APA guidelines with minor violations to cite sources.Points Range:19 (19%) – 20 (20%)Writing demonstrates a sophisticated clarity, conciseness, and correctness; includes thorough details and relevant data and information; extremely well-organized. Uses APA guidelines accurately and consistently to cite sources.


0 comments