MINUTES


MID-AMERICA CONTINGENCY PLANNING FORUM

JOINT GENERAL BUSINESS MEETING

With St. Louis ISACA Chapter

January 21, 1998 4:30 PM

Junior League of St. Louis

 

Present (according to sign in sheet):

Anna Bathon NationsBank

Tom Monroe Safe Deposit Company/CompuVault

Virgil Mueller Comdisco Recovery Services

Tamra O’Brien DataSafe Storage, Inc.

Timothy Proost A. G. Edwards & Sons, Inc.

Julie Scott Safe Deposit Company/CompuVault

Joan Speaker DataSafe Storage, Inc.

Clint Williams BJC Health System

 

The meeting was held at the Junior League of St. Louis and began at 4:30 p.m. This was a joint meeting with the St. Louis Chapter of Information Systems Audit and Control Association (ISACA).

 

Ray Bueneman began the meeting with a networking session from 4:30 until 5:00. Ray then introduced Doug Menendez (Express Scripts, Inc.), who gave a presentation on "Auditing the Disaster Recovery Plan." Highlights from Doug’s discussion include d:

 

"Auditing the Disaster Recovery Plan"

Why Audit:

v Provides insurance to Management that plans are complete and up-to-date.

v Motivates associates/personnel to maintain their recovery plans.

v Can identify and track improvements across operations.

v Helps to justify allocation of resources.

v Timing can occur during development of a recovery plan or once the plan has been completed.

v Can develop an alliance, build support, share issues, and maintain open lines of communication

 

Pre-Audit Steps:

v Obtain from business units:

Ø Business Functional or Risk Analysis documentation

Ø Existing contracts

Ø Previous test results

Ø Previous audit results

v Obtain from auditors:

Ø Audit scope

Ø Objectives of audit

Ø Reports issued

Ø Work plan / procedures

v Ensure auditors understand the functions to be audited

v Get Management’s expectations for audit or testing and recovery

 

 

Audit Approach/Testing:

v Four means of auditing:

Ø Inspection/Review

Ø Observation

Ø Participation

Ø Verification

Auditing Plan Components:

v Initiation and Administration:

Ø Ensure Senior Management support

Ø Organizational responsibility and user involvement

Ø Key strategies and assumptions

v Emergency Preparedness:

Ø Declaration and evacuation procedures

Ø Public relations

Ø Damage containment, clean up and salvaging program

v User Interim Procedures:

Ø Key strategies and assumptions

Ø Security and audit trails

Ø Manual procedures

Ø Arrangements for fall-back equipment

Ø Will the same environment exist in a recovery mode?

v Back-Up Process:

Ø Data files

Ø Application and System Software

Ø Hardware and Support Facilities

Ø Logistics Support and Personnel

Ø Verify contents at offsite storage location

Ø Review contracts

Ø Ensure the authorized signature list is updated

v Recovery Procedures:

Ø Data center activation

Ø File recovery procedures

Ø Start-up of critical systems

Ø Ensure configurations match logistics to/from facilities

Ø How detailed are the procedures?

v Documentation:

Ø Accountability for maintenance

Ø Distribution and version control

Ø Currency, form, style, and clarity

Ø Use of automated tools

v Testing and Training:

Ø Exercise objectives

Ø Roles and responsibilities

Ø Types of testing – simulation or live; announced or unannounced; frequency

Ø Plan maintenance

Ø Verify completeness and accuracy

Ø Increases the confidence in the ability to recover

v Summary:

Ø Create awareness of the recovery process

Ø Include Auditing as an observer of tests

Ø Auditors can see across a wide range of business units or departments

Ø Assists in gaining Management’s support

 

 

Following dinner, Ray Bueneman made a few announcements and introduced Anna Bathon as Secretary of the MCPF group. Anna thanked ISACA for the opportunity for the MCPF to participate in this joint meeting, stated when the MCPF meetings were held, and th at we would welcome any and all new members. Membership applications were available for anyone interested in joining our group. Following this brief period, Ray proceeded to introduce Steve Davis of DataSafe Corporation, who discussed "Future Technolog ies for Safe Storage and the Evolution of Offsite Storage."

 

"Future Technologies for Safe Storage and the Evolution of Offsite Storage"

 

Why:

v If something happens to the host facility

v Audit compliance

v Disaster recovery preparedness

 

Security of Offsite Data Storage:

v Legal compliance

v Audit compliance

v Satisfy management directive

v Disaster recovery preparedness

v Improved security

v Convenience

v Third-party discipline

v Economics

v Transportation security

v Magnetic secure containers

v 24-hour access to data

v A professional organization

 

Physical Security:

v Burglary protection

v Fire protection (Halon 1301, FM200)

v Secured storage area

 

Auditing and Bar Code Technology:

v Satisfies two main needs:

Ø Control – managed and under control

Ø Comfort – stored safely in case the company needs it

v Accomplishes needs by:

Ø Accuracy

Ø Location

Ø Flexibility

Ø Restoration/access

Ø Life cycle management

v Report features:

Ø Activity summary

Ø List of events

v Control and Audit features:

Ø Tracking

Ø Shipment verification

Ø Site audit

 

 

v Typical type of communication utilizing bar codes:

Ø Pick lists

Ø Retrieval requests

Ø Inventory files

Ø E-Mail

v Recordkeeping Advantages:

Ø Receipts

Ø Computerized inventory control

v Bar Code Media Tracking and Control:

Ø Electronic file transfer

Ø 100% accurate inventory control

Ø Audit function

Ø E-Mail

Ø Disaster recovery preparedness for disaster recovery processing

v Key option to bar code scanning – fast, accurate means to verify providing inventory control

 

Copies of the handouts provided by both Doug Menendez and Steve Davis are available upon request by calling Anna Bathon at 314/466-3509.

 

The next meeting of the MCPF group will be held on Thursday, February 19, 1998, 3:00 p.m., at the NationsBank Plaza downtown. The featured topic will be on Year 2000 concerns presented by Julie Bergh of MasterCard.

 

This meeting was adjourned at 7:45 p.m.

 

Recorded by: Anna M. Bathon

MCPF Secretary