ACC306 Readings

Introduction to Availability Objectives

  • The importance of ensuring that systems and information are always available when needed.
  • The primary objective is to minimize risks of system downtime.
  • Complete elimination of downtime risk is impossible; hence, quick recovery controls after disruptions are vital.

Key Controls Related to Availability Objectives

Table 13: Summary of Key Controls for Availability

  • Reference the full information in the embedded table within the eText.

Minimizing Risk of System Downtime

  • Organizations can undertake various actions to minimize downtime risks.
COBIT 2019 Management Practices
  • DSS 01.05: Emphasizes preventive maintenance (e.g., cleaning disk drives, proper storage of media) to reduce risks of hardware and software failures.
  • Redundant systems enhance fault tolerance:
    • Example: Redundant Arrays of Independent Drives (RAID) allow simultaneous data writing to multiple drives.
    • If one drive fails, data remains accessible from others.
Data Center Design
  • DSS 01.04 & DSS 01.05: Importance of strategic location and design of data centers for critical servers/databases to minimize disaster risks.
    • Common design features include:
    • Raised floors: Protect against flooding.
    • Fire detection & suppression systems: Mitigate fire damage risks.
    • Air conditioning systems: Prevent damage due to heat/humidity.
    • Special Cables: Prevent accidental unplugging.
    • Surge Protection Devices: Defend against power fluctuations.
    • Uninterruptible Power Supply (UPS): Protect systems during outages, allowing time to back up and shut down safely. Regular inspection of UPS batteries is crucial.
Physical Access Controls
  • Reduce risks of theft or environmental damage.
Importance of Training
  • Well-trained operators make fewer mistakes, enhancing recovery from errors.
  • DSS 01: Importance of documentation of operational procedures for IT staff.

Risks Related to Malware

  • Computer malware (e.g., ransomware) can lead to inaccessibility of applications and data.
  • Importance of installing and updating antivirus and anti-spyware programs:
    • Programs should automatically scan emails and removable media (CDs, DVDs, USBs).
  • Patch Management Systems: Timely fixes for vulnerabilities exploited by malware.
  • Employee training essential to recognize/respond to phishing attacks.

Recovery and Resumption of Normal Operations

  • Despite preventive controls, system downtime is a risk. IT failures, disasters, malware, and human errors can cause inaccessibility.

Key Questions for Senior Management

  1. How much data are we willing to recreate or lose?
  2. How long can we operate without our information system?
Recovery Point Objective (RPO)
  • Represents the maximum acceptable amount of data loss or recreation.
  • RPO is inversely related to backup frequency:
    • Smaller RPO = More frequent backups.
Recovery Time Objective (RTO)
  • Maximum allowable time to restore an information system post-disaster.
  • Reflects how long an organization can function without its system.
Figure 13.1: RPO and RTO Relationship
  • Overview of relationship as data is lost post-backup.

Data Backup Procedures

  • Procedures to manage inaccessible information due to file/database corruption.
Types of Backups
  1. Full Backup: A complete copy of the entire database (usually done weekly).
  2. Incremental Backup: Captures only changed data since the last partial backup. Restoration involves loading a full backup first, followed by incremental files.
  3. Differential Backup: Captures all changes since the last full backup. Simpler restoration compared to incremental backups.
Deduplication Technology
  • Organizations are increasingly using deduplication rather than full backups.
  • Deduplication uses hashing to back up only modified portions of a file/database.
  • Process:
    • Files divided into uniform chunks, hashed, and compared with past backups.
    • Only changed chunks are backed up, speeding up the process.

Backup Storage

  • Multiple copies of backups are vital:
    • On-site: For minor issues (e.g., hard drive failure).
    • Off-site: For catastrophic events (e.g., fire, flood).
  • Transport methods include physical logistics (courier) and electronic transmission.
Security Controls for Backups
  • Encrypt sensitive backup data during storage & transit.
  • Monitor access to backup files.
  • Periodically practice restoration processes to ensure backup functionality.
Backup Retention Policies
  • Backups usually stored for shorter durations (e.g., several months).
  • Some-sensitive data stored longer (archive):
    • Archive = historical copy retained indefinitely for legal/compliance reasons.
    • Utilizes indexing features for quick retrieval unlike typical backup software.
What Media to Use for Backups/Archives
  • Disk: Faster access and retrieval times.
  • Tape: Cheaper, easy to transport, more durable, and safer from ransomware.
  • Many organizations use both: Backup to disk first, then transfer to tape.

Email Backup and Archiving

  • Recognized as vital organizational information.
  • Email policies should include archiving key communications to avoid costly legal repercussions.
  • Avoid policies of blanket email deletion; instead, classify emails’ importance.

Disaster Recovery and Business Continuity Planning

  • DRP focuses on IT restoration post-data center destruction.
  • BCP seeks to resume all business processes post-calamity.
DRP Options
  1. Cold Site: Empty building prewired, requires contract for equipment.
  2. Hot Site: Facility with equipment ready for essential activities.
  3. Real-Time Mirroring: Two live database copies at separate data centers for maximum resiliency.
Cost vs. RTO/RPO Consideration
  • Cold sites are least expensive; real-time mirroring is most expensive.
  • The choice should be driven by acceptable RPO & RTO metrics.
Case Study: Nasdaq Post-9/11
  • Effective DRP & BCP enabled Nasdaq to operate within a week after disruptions caused by the September 11 attacks:
    • Utilized effective communication and prior planning for crisis management.
    • Employed decentralized systems to ensure reduced operational risk.
    • Prioritized plans during disaster response.
Documentation and Testing of Plans
  • DRP & BCP documentation must include:
    • Recovery steps, vendor documentation, and modifications made.
    • Should be stored securely on-site and off-site.
  • Testing essential for revealing shortcomings.
  • Regular updates and annual testing of the plans needed.

Effects of Modern Technology

Virtualization
  • Enhances RTO; virtual machines recover faster than physical servers.
  • Backups of virtual machines required alongside snapshots.
  • Supports real-time mirroring functionality.
Remote Work Considerations
  • Shifts reliance from traditional backup sites (cold/hot) to multiple data centers for remote workers.
  • The DRP/BCP must address potential remote workforce connectivity issues during disasters.
Cloud Computing Impacts
  • Cloud providers utilize multiple redundant servers but have their own availability risks.
  • Organizations must have backup plans for when cloud services are down.
  • Evaluate financial health of cloud providers and ensure RTO/RPO considerations are established.

Conclusion

Assessment of Control Effectiveness at Northwest Industries

  • Report by Jason focused on the effectiveness of Northwest Industries’ system availability controls.
Controls Evaluation
  • Data Accuracy: Checks such as turnaround documents and online validation ensure accuracy.
  • Backup Weaknesses: Backups were not tested or encrypted; only stored on-site.
Recommendations
  • Immediate testing of backup restorations, encryption of backup files, and off-site storage.
  • Regular testing of DRP and BCP.
Compliance
  • Successful implementation of recommendations may assure alignment with APUS Trust Services framework for reliability.