Request for Proposal
Business Recovery Planning Software Evaluation
General Functions
General Inquiries About Your Company and Business History
Can the vendor provide at least ten (10) references with contact names and phone numbers?
How many installations / organizations have this software?
What is the length of time you have been in business?
Are there any users groups for your product?
How many employees do you employ?
How many programmers support the product?
What are the future directions of your product?
Does the vendor staff include Certified Business Recovery Planning consultants?
Is Business Recovery Planning software the Vendor/s principal line of business?
Is the first year of maintenance services included with software?
What is the cost?
What is the maintenance cost?
Is there a trail (evaluation) period before you have to purchase the product?
What are the return policies on the product?
Does the vendor provide toll-free technical support within the USA?
Is toll-free technical support available 24 hours a day, 7 days a week to all users?
Is free training included with software?
Is free "hands-on" training available during evaluation stages?
Does the vendor provide training for unlimited personnel at no charge?
Are product updates and enhancements free under active maintenance?
Is the product PC based and menu driven?
Provides a systematic method for developing an effective plan?
Uses a popular word processing package for customization of text files? (e.g. Word, WordPerfect)
Provides database management capabilities for information best presented in a list format, (i.e. equipment inventories, personnel lists, vendor lists, etc.)
Can be used for developing an organization wide disaster recovery plan or a plan for only the data processing function?
Is designed to facilitate maintenance?
Provides a comprehensive operations manual?
Includes backup and restoration procedures?
Can be used on a LAN system.
Facilitates recovery from multiple levels of disaster?
Contains emergency management module?
Is there a single-user version of the product that can operate on either a stand alone PC or on a file server?
In the multi-user LAN version, can multiple people access the same data table/file simultaneously?
Does the LAN version operate in a number of LAN environments? (i.e. Novell, NT, UNIX)
Disaster Recovery Plan Development
Inquiries About the Product Functions for Recovery Plan Development and Use
Provides a time and events schedule (i.e. Project Management System) that describes the various activities necessary to complete the planning process, allowing input of responsible party, start date, targeted completio
n date, and applicable section of the Plan?
Provides a data collection questionnaire to assist in identifying critical functions and activities at the department level?
Provides methods to determine critical functions and prioritize operations?
Describes various backup and recovery strategies for:
- Main computer systems
- Voice communications
- Data communications
- Departmental systems
- Other critical equipment
Includes contractual considerations for backup/alternate site arrangements?
Can be used with any backup and recover strategy?
Provides sample team designations based on the type of organization and scope of the Plan?
Contains data gathering forms that tie to the detailed exhibits within the Plan?
Describes typical assumptions used during disaster recovery plan development?
Includes descriptions of the various insurance coverage that should be considered by your organization including:
- Extra expense coverage
- Business interruption costs
- Valuable paper and records coverage
- Errors and omissions coverage
- Fidelity coverage
- Medical transportation coverage
- Electronic funds transfer systems coverage
Includes insurance analysis techniques to reduce premiums?
Provides records retention guidelines for corporate, financial, information systems and other records?
Describes salvage procedures for various types of records, including magnetic media, paper, microfilm, etc?
Is the hypertext help with the system? (i.e. can the user "jump" from one help topic to another.)
Is there context sensitive help with the system? (i.e., when the user hits the Help key, does the system bring up help that is pertinent to the section or feature that was being used?)
Is there a "search" shortcut option under the Help menu bar so you can go directly to the help you need?
Is there an on-line "How To" Guide on building a recovery plan? If yes, can this recovery planning guide be printed by each user?
Does the system offer flexibility in plan design? (i.e., even if system is based on a specific methodology does it allow for variation and flexibility instead of rigid adherence to the plan’s methodology?)
Provides a comprehensive disaster prevention checklist designed to address key security and control issues to assist in preventing disasters?
- Physical prevention
- Procedural prevention
Includes procedures and forms for performing a risk assessment (business impact analysis), considering the various natural, human and technical threats and their impact on various department within the organization?
Can unit plans be rolled-up into a master plan in an orderly structure? (i.e., there’s a fire in the building and you need to relocate affected areas… can you get summation of equipment, chairs, desks, PCs, phones, etc., for the affected areas only?)<
/LI>
Can unit plans be individually printed during a test or disruption? (i.e., there’s a telecommuncations event that disrupts
your customer service department in various states..can only your customer service DRP be printing, regardless of
locations?)
Will all subordinate plans be included in a single plan execution? (i.e., the building is inaccessible; you execute the
""building plan" and get all "subordinate" plans, instead of being forced to execute each plan individually.)
Sample Business Recovery Plan
Inquiries About Sample Recovery Plan Functionality
Provides for multiple levels of disasters?
Contains disaster assessment forms and procedures to assist the management team in assessing the extent of the disaster
and determining alternative actions?
Includes emergency/evacuation procedure for medical emergencies, fire, tornadoes, thunderstorms, gas leaks, power
failures, water leakage, etc?
Contains detailed procedure for the accounting and operation areas?
Contains high priority tasks, temporary operating procedures, facilities requirements, equipment and supplies, manual records and forms and reconstruction procedures for each team?
Contains disaster tracking forms once a disaster strikes?
Provides detailed procedure for contingency processing at an alternate site (i.e., location hot-site, mobile facility, etc.)?
Includes detailed procedures for establishing voice and data communications with the alternated processing site?
Describes detailed procedures for facility reconstruction and restoration?
Includes the following areas:
- Department procedures
- Team responsibilities and procedures
- Distribution procedure
- High priority tasks
- Manual processing techniques
- Emergency accounting procedures
- Functional area procedures
- Notification procedures
- Disaster policies
- Temporary operating procedures
- Risk assessment procedures
- Procedures for establishing a command and control center
Addresses the following equipment considerations:
- Main computer system
- Microcomputer
- Data Communications
- Voice communications
- Other critical equipment
Addresses the following facility considerations:
- Main building
- Remote facilities
- Off-site facility
- Backup facilty
Provides sample testing schedules and procedures, including types of tests, test participants, team test responsibilities
and test forms?
Includes exhibits or reports to supplement the main body of the Plan?
Allows for user defined capabilities? (i.e., user defined sections of the plan or user defined exhibits.)
Includes maintenance procedures for keeping the Plan current?
Uses a clear, concise writing style?
Uses a standard format?
Has a place for recording the names of company personnel who will play a role in recovery situation, as well as a list of the phone numbers for all personnel who must be notified in the event of a disaster?
Has a location for recording information about all vendors who will provide products or services during a disaster and the names and telephone numbers of vendor contacts?
Has sections detailing the locations and types of vital records stored off-site and the procedures for accessing them during recovery?
Has inventory systems hardware and other equipment should be maintained in the plan, both for insurance purposes and for use as a checklist in plan testing?
Provide a description of network operations and communications lines, and equipment and service recovery requirements?
Provide for application systems descriptions and should list the hardware necessary for operations and for meeting user
hardware requirements?
Provide sections for information regarding organization’s lawyers, insurance policies, and lines of credit?
Database Management System
Inquiries About the Product’s Database Functions
Uses "point and shoot" for data input?
Provides multi-key access to database information and reports?
Provides "memo" fields for certain database records allowing over 200 lines of test to be added per field?
Includes user defined field names and contents within each database record?
Provides on-line help screens?
Allows for multiple facilities, locations, with facilities and departments within locations?
Allows the user to find specific database records or browse the contents of all records?
Allows the user to change the sort sequence of records within the database files?
Provides a report writer that allows the user to select from a variety of reports and report sequence?
Allows reports to be printed or viewed on the screen?
Allows reports to be recorded in ASCII format for input into other work processing software?
Can the product be populated with data resident on another system? (i.e., you want to enter employees from the HR system, and your vendors from Purchasing system; is there an import capability so you don’t have to perform data entry?)
Will imported data be reflected in the product’s audit-history sub-system?
Does the system prevent accidental import duplication?
Can the import function handle changes and deletions as well as additions?
Are "exception" reports provided to tell you about any data import errors?
Can field names be easily customized to fit your terminology? (i.e., say a field name is "Alternate Phone" and you want it to read "Beeper" or "Cellular"; can the field name be easily changed?)
Can the tool bar icon description be customized?
Can the order of the Plan output be customized for execution? (i.e., if you’ve determined you want you call list first,
your list of critical applications by priority second, tasks, and procedures third, etc., can you customize to Z order of output?)
If reports can be exported to a file, can the type of file be specified? I.e., WordPerfect, MS Word, Lotus 123, MS-Excel.)
If the type of file is specified, will the report be placed in the correct format? (i.e., will headers be placed in the header section of the work proceding document.)
Can reports be sent directly through your e-mail system? (i.e., if you have the report on your screen, can you click a button and have it sent directly through your mail system?)
Can previously created charts and diagrams be linked into your plan using OLE 2.0?
Does the system have the ability to move information from one plan to another? (i.e., when employees change departments; can you easily move them into different plans?)
Does the system have the ability to "selectively" replace one employee’s team assignments and management positions with another? (i.e., if employee A is laid off or promoted, can employee B be easily assigned employee A’s responsibilities?)
When performing a global delete, are all relationships associated with that record also removed? (i.e., if a department is
eliminated and you want to delete that plan, can you do a global delete of everything associated with that plan?)
Provides for the following functions when reports are viewed on the screen:
- Scrolling line by line
- Scrolling screen by screen
- Panning left and right
- Windowing to view separate parts of a report side-by-side
Allows the combining of separate database records into a consolidated file?
Provides project management capabilities?
Does the system interface to any Windows (3.1 or 95) or DOS-based word processor?
Can you use your own text documents instead of those included with the system?
Does the system come with standard reports?
Can you edit standard reports? (i.e., change the contents, style, and typeface.)
Are custom reporting capabilities available?
Can summations of equipment, supplies, employees, etc., be performed?
Can recovery plan data be sorted in any order?(i.e., alphabetically, numerically, ascending/descending, by zip code, etc.?)
Can you determine the search criteria for each report?
Can only portions of the plan be printed? (i.e. , allows for the generation and printing of individual plan reports.)
Can reports be printed to the screen for on-line viewing before printing?
Can reports be printed or exported to a file?
Contains the following files/information:
- Facilities file
- Location file
- Department file
- Alternate location file
- Off-site storage location file
- Position description file
- Personnel file
- Personnel skills ratings file
- Team members file
- Data communications inventory file
- Main computer hardware inventory file
- Main computer software file
- Microcomputer hardware file
- Microcomputer software file
- Documentation inventory file
- Forms inventory file
- Insurance policies inventory file
- Office equipment inventory file
- Office supply inventory file
- Records inventory file
- Telecommunications inventory file
- Emergency procedure file
- Recovery procedure file
- Project management file
Testing
Questions About the Product’s Reocvery Testing Functions
Contains testing schedules?
Includes testing methods and procedures for:
- Structured walk-through testing
- Checklist testing
- Simulation testing
- Integrated testing
- Parallel testing
- Tactical testing
Contains techniques for evaluation results?
Product Security System
Inquiries About the Product’s Security Functions
Contains USER ID, password, and login capability?
Encrypts passwords?
Includes the capability to require users to change their passwords after a specified period of time?
Allows the capability to establish security level for each user?
Contains multiple levels of security?
Provides the capabilty to establish security levels for each menu item?
Provides a minimum length of six characters in the password field?
Does the system have recovery plan level security? (i.e., Finance cannot edit MIS’s plan.)
Does the system offer access security into different areas/functions of the tool? (i.e., can you lock out some users from editing or printing plans f, from performing any customization to product, from accessing administrative tools, etc.)
Can security profiles for various users be easily duplicated? (i.e., user on the LAN have the same level of security, the
only difference is the plan each can edit - one security profile can be created once and duplicated as necessary.)
Can a user be denied access to major data editing capabilities? (i.e., Move, Replace, Global Delete?)
Can an individual user change his/her password with out requiring access to security?
Does the system have an audit history subsystem?
Does audit history provide a before and after image of transactions performed? (i.e., does it show if this transaction was
an add, a change or a deletion. If it was a change, does it show how the record looked before and after the transaction?)
Does audit-history identify/track the user performing the transaction/
Does audit-history stand a data and time on every transaction?
Can the audit reports be printed?
Can you restore data from the audit-history subsystem?
Logs and reports user access and usage:
- Summary reports
- Detailed reports