Wednesday, 19 December 2012

DRaaS, a real solution or just another acronym?

DRaaS borns as a concept related to Cloud services which, in a first approach seems to be very similar to the traditional backup datacenters service solutions, but however it has an important differential feature: abstraction from infrastructure.

In traditional backup datacenters, the infrastructure should be equal or very similar, so all services could be run in a proper way independently from the site in which are running. When we talk about DRaaS, and manly due to virtualization, the services are offered in an infrastructure-agnostic way, and this allows services to be recovered only coping data between datacenters. Moreover, with the dynamic capacity management feature given by virtualization, service level can be granted in most cases.

From a conceptual perspective, DRaaS has two different options:
  • DR of software (SaaS), infrastructure (IaaS) or platform (PaaS) running in the Cloud. The Cloud service provider should offer the DR service and it will be completely transparent to users.
  • DR as a solution for IT services running in a corporate datacenter, with cold or hot stand-by.
Is in the second options when DRaaS concept is taken to the extreme, allowing the design of different solutions depending on our infrastructure. For example, since most IT infrastructures are virtualized, a DRaaS can consist on a virtualization server that can host virtual machines conforming the whole service. Carrying out a data replication service could be recovered in an alternative site in seconds.
Advantages of DRaaS are obvious:
  • Economic. In the BCM industry, wer ROI are not very cleary and is difficult to justify, economic matters are very important. In the case of DRaaS we have not to make all payment upfront, it can be done with a pay-per-use model, with a mensual fee. This is a great advantage nowadays because hardware cost of ownership has not to be done.
  • Simplicity in test. Most efforts in business continuity and IT service continty is dedicated to drill and tests. With a reduction of complexity of this test we will reduce the economic cost and we can dedicate this budget to other important issues.
  • Flexibility. Service can be adapted depending on business requirements established to each application. In some industries, which are very dynamics, this issue is very important in order not to have more costs than ingress for a service.
Step by step, housing providers are increasingly using DRaaS as a new product of  their portfolios,  identifying the diferent options of  this kind of  service defined above. In Spain there are not too much providers using this terminology, but we can found some examples, as the DRaaS by Ermestel.
In the same way than Cloud services, not all infrastructure can be migrated to DRaaS. It will be dependent on determining factors like specific hardware, information confidentiality, integration with other corporative services or service level required (a lot of times required service levels cannot be offered by providers because of technology conditioning). The most interesting options could be a combination of Cloud solutions with traditional backup solutions in order to take advantage of IT service continuity in a proper and economically way. This is called hybrid Cloud.

Thursday, 1 November 2012

In a desaster like the one in New York, Can we be prepared?

Colaboration by Moises Lopez Business Continuity Consultant at Grupo SIA
From my point of view, except multinational companies with a global and diversificated market which don’t depend on one or two locations, in disaster like this one very few companies can resist.
When identifying resources required to business continuity, every organization can estimate the amount of resources they will need to assure their resilience for each activity. Having a deeply look into some of the main resources supporting business, can find:
  • People: welfare has to be a priority and, in this case, forecast and advertising is an advantage to assure their safety. Except emergency services, nobody should be in their jobs, moreover, in this case there has been some victims.
With city paralyzed and employees only available in their houses, Will only technology support all the business? Are workforce prepared to develop their activities when their city is under emergency?
  • Technology: with power outages and floods, it’s very difficult to maintain a adequate service level, even if our IT infrastructures are based in Cloud. Even more, Can we assure that our employees’ communication provider will still deliver services in this scenario?
  • Providers: We can have the most restrictive service level agreement that, in this scenario will be wet paper. Moreover, we can have back up providers, but Can they will deliver the service in a proper way?  Can they deliver services even in scenarios in which we can’t?
  • Locations: When city is not available, Will our facilities be available?
We can have a business continuity plan, with a communications plan properly defined, the response and emergency procedures also established,  even we could have decided to establish our backup datacenter in other city, but our budget and technology could be enough to put it in New Jersey, for example,… If despite all this measures we cannot restore our business, then we can only hope the help of the government or pay of insurance premium.
As a conclusión, if the scope of unavailability is as big as our city and around, it will be time to start from the beginning.. or  Would be realistic to consider as an scenario in our plan about “unavailability of the whole city”, if the city is our main operation center?  How many companies in Spain would be able to assure it resilience in such a big disaster situation? 

Monday, 22 October 2012

Healthcare service continuity

Blackout taken place in Fundación Jimenez Diaz hospital , last 16th of October in Madrid is a good example to realize that there is not necessary great disasters or disruption  to activate Business Continuity Plans.
Although we have not too much information about this incident, it can be clearely indenfied two tradicional continuity measures:
  • Power generators activation, to support critical systems
  • Redirection of new admissions to other hospitals, in this case the Hospital Clínico.
When we are talking about a hospital, such as I discuss in my previous post components supporting business, this service is so critical that  availability of all components supporting the service has to be granted, that is, facilities, suppliers, medical staff or information technology. Impact caused by lack of service is simply unaffordable because the life of patients is in play.

However, the incident occurred in Jimenez Diaz Hospital must make us think about if our health system is really prepared for emergency situation or disasters when hospitals are affected. 2004 terrorist attacks in Madrid realized that the emergency agency are prepared to deal with such a great disaster, but What would happen if the own hospitals were affected by the disaster?

In a hospital there are a lot of diverse healthcare services, with different criticalities: emergencies, maternity, hospitalization, operating rooms, doctor appointments, radiology,.... Strategies must be different depending on this criticality. For example, a pediatric appointment could be delayed or redirected to other hospital, but a serious patient that has to go through surgery or with dependation of ventilation can no be unattended and any delay can be fatal.

Having a look abroad, for example to United States, hospitals has a global framework since lasts 80s, called HICS (Hospital Incident Command System). This framework identifies different issues to be taken into account to assure healthcare service. HICS was born as a emergency specific framework (HEICS), but it nowadays is a system for use in both emergency and non-emergency situations. George W Bush govern created in 2003 a global framework to manage incidentes (NICS) and this caused a new revision or HICS which is the last version (version V).

About content, HICS identifies five management functions hat has to be defined in the hospital to manage incidentes:
  • Incident Command, set by different responsibles of safety, liaison and public information officers and the global responsible
  • Operations section concuct ths tactical operations.
  • Logistics Section: provides required resources to achived operational objectives.
  • Planning Section: Collects information about the incident, maintain resource status and infomration for reports and prepares documents, such as incident plan.
  • Finance and Administration Section: Monitors costs related to the incident and provides accounting, procurement, time recording, and cost analyses
The most important advantange of HICS is provides a common terminology and position titles to enhance standardization among agencies and responders

In Spain, with healthcare service tranferred to Autonomous Comunities and with the actual economic crisis it seems that this kind of initiatives are not a priority, altough from my point of view is an interesting tasks for CNPIC. At the end of the day hospitals should be considered critical infrastructure.

Saturday, 29 September 2012

Conference "CONTINUIDAD DE NEGOCIO 2012"


Contribution by Daniel Blanco Business Continuity Consultancy Solutions Coordinator at Grupo SIA.

Last 26th of september was pleased to attend the conference "CONTINUIDAD DE NEGOCIO 2012" (Bussiness Continuity 2012) in Madrid, organized by Fundación DINTEL in colaboration with continuam and INTECO
In the conference there were invited different lectures as BBVA, Banesto, AccionaMinister of Defensa, Adif, Aena, Bankinter or EMT. The schedule can be seen in the followin link at Fundación DINTEL:
http://www.dintel.org/index.php?option=com_content&view=article&id=216&Itemid=312

Lectures were divided into two blocks, with different presentation models. In the morning, presentations about cases of success and experiences in Security and Business Continuity Management in their organizations were done by speakers speakers; in the evening took place a colloquium in which speakers answer questions done by a moderator. 
Better than describe in deep each lecture, I'd like to highlight some relevant messages and topics commented  repeatedly during the day:
  1. Although there are still points of view in which business continuity is treated as a part of information security, this time there were presented as a independent discipline that complements information security and that, in conjunction with risk management, deliver resilience to organizations
  2. Awareness and Management Commitment are important points not achieved in Spain nowadays and is necessary and essential. Business continuity plans or crisis management training and drills were presented as one of the most important ways to deal with the objective.
  3. There is not enough with having a business continuity plan or a crisis management plan in which an organization critical business process recovery were defined, other actors like police, emergencies support, government and critical providers have to be taken into account in order to get the minimum level of operation after a disruption. Without internal and external support no organizations can recover their business.
  4. The Spanish Critial Infraestructures Protecction Law were presented as an inflexion point that can bring the development of a industrie collaborative framework and allow to have sectorial strategic plans in Spain. Moreover, this can be a energizer of the three point described bellow.
As a conclusion, from my point of view, different lectures of the conference were in the right way: defining business continuity issues, resilience, economic sustainability and not only IT or Information Security. Nevertheless, we have still a long way to achieve what was defined in the second point: management has to commit and promote business continuity activities. As as sign I can point out that most of people attending the conference were chief of IT or were part of the structures of IT in companies.

Tuesday, 25 September 2012

Sabotage

Yesterday, talking with the chief of Business Continuity consultancy in one of the main companies of the industry in Spain, we have doubts about if the case of sabotage in the power infrastructure in Rayo Vallecano's stadium should be consider as a scenario in Business Continuity plans.

La falta de luz obligó a aplazar el choque que debían disputar Rayo Vallecano y Real Madrid.On the one hand, it could be clear that a scenario of lack of power, no matter the origin, must be included in BC plans. Measures to assure power are very common: generators, two power providers, etc.

On the other hand, the sabotage in football match between Rayo Vallecano - Real Madrid has two special considerations:
  • The stadium must be available at a specific time and during a relatively short period (2 hours)  There is not possibility to play the match in other stadium - it would be impossible to move 15.000 - and it's not possible to play at other time, since the main business to be continued is the is the television retransmission.
  • Internal electrical infraestructure were damaged, so there is no way to use an alternative infrastructure. It has to be repaired.
Since Business Continuity has to focus on moments after an events occurs, and the plans covers the actions to be taken on this moments, its seems to be difficult that the staff of Rayo Vallecano could done something different if they would have a Business Continuity plan. Traditional measures would be not effective in this scenario because it was damaged the internal infrastructure. So this scenario is only useful to analyze risks and define the mitigation measures.

In general terms, when business depends on somebody doing something in a certain location, business continuity plans doesn't help too much: It's not possible to change actors, location or time, so we can only make a good risk analysis and try to mitigate it as far as we can.

Friday, 7 September 2012

BYOD and Business Continuity

BYOD can be considered as a trend in the IT and is called to be developed during the following years, since this has a lot to do with mobility and telework. There has been users themselves, manly top management, who has introduced smartphones and tables into the offices when they realized that they were using their shabby professional mobiles more regularly than their brand new iphone and they began to invert this trend, forcing their CIOs to allow access to their email, agenda and other applications. This means that, instead of being the product of a marketing strategy or the conclusion of trends report by a high level consultancy company (surely they are going to include in it from now), is the result of an increasingly widespread practice.

From a technical point of view, BYOD is going to be a revolution in the workstation world that will require procedures update, new tools for manage the devices and new security policies. Security and legal issues will be probably most affected by this trend, with a lot of voices form security experts rising against it because of the violation of traditional security dogmas of access control al data loss prevention. That’s why there are a lot of comments in forums and a rising market about device protection tools to avoid happened situation like the one affected to the Spanish Homeland Security Department Minister, who loses his ipad. Most of this tool were available before and has been named with the fashion acronym (BYOD compliance…)
From Business Continuity perspective, BYOD doesn’t bring a great change, since will be very similar to remote access policies in which users usually take care of the expenses of Internet connection or even the computer they use to access to company’s intranet. In the same way they do to remote access, BC manager, usually with Human Resource department, should assure the following:
  • Employee give consent to use their own resources to a professional use.
  • Employee owns the required resources to carry out activities they have to do in a crisis or contingency situation. The better way to do this is involving the user when inventory of their own resources periodically.
  • Employee resources comply with company security and feature politics and procedures.
Apart from that, as every BC resource, BC manager should assure the information in the inventory will be updated continuously. In order to do that, the best option is to automate the process with tools like Workforce Assessment by SunGards AS, in which inventory and update process are done with a web form and is stored in a relational database. This allows using this information later, when defining BC strategies and procedures. And of course these resources have to be included in the exercising program.

Thursday, 2 August 2012

Thoughts about blackouts in India

It seems that last blackouts in India have activated a lot of Business Continuity plans and have made the different between companies with and without a BC program. Lack of power supply is a clear continuity scenario to which most companies are prepared, mainly through power generators able to support the sites demand of electricity, or at least, of the most important.

Other issue to take into account is how to assure that workforces are going to reach their workplaces, since public transport are not available. Moreover, if telework is the alternative, How can they work from their homes if there is a lack of telecommunications?

ICTs are one of the resources that will be affected most because of their dependency on power supply. Blackout in India scenario shows resiliency examples of companies which principal business is IT services, as we can read on this article about Winpro, Genpact and WNS, but is not a trivial matter.

However my thoughts go in other way: Can this scenario be really included in the BC scopes?
In a first approach it seems clear that this scenario has to be included, but thinking on it deeply, our customers will probably be affected by the same problem, so it has no sense to be able to deliver our service if our customers are not going to receive it.
In a globalized world, in which we can have customer located near us or in the most remote place of the earth perhaps this thoughts has no sense, but we have to take into account that most business are done locally, with companies and organizations very close one to the others. Resource investments on this scenarios are not justified too much.
As an example, we can think on a clothing store: It’s difficult to have our store plenty of customers in a situation of a blackout like the one taken place in India. Every street and every shopping center are in dark

As a conclusion, and as an advise as well, when defining the scope of our Business Continuity plans we must evaluate the scenario thinking on the situation of our customers because perhaps I recover my services and there is nobody use it.