Information Assurance: Managing Organizational IT Security Risks

Understand the importance of contingency planning
Discuss the need for backups
Identify the need for an emergency action plan
Provide a contingency planning list
The dichotomy between users and certification and accreditation (C&A) authorities was once explained as follows: C&A authorities want to protect the information's confidentiality; ensure data integrity; and, if possible, see that the information is available when users want it. Users want the information available when and where they want it, without corruption, and, if possible, in a secure manner. The IA manager is left in the middle trying to appease both extremes.
The organization's dependence on IT as an integral part of the business process means that when systems or networks are unavailable, business processes fail. As a result, availability is one of the primary concerns of users, to include management. Managers are briefed daily on system downtime. Scheduled downtime is coordinated well in advance with all affected departments. Improved software tools now allow IT departments to predict system outages and network faults before they occur, in order to take preventive action before experiencing operational downtime.
Availability is the focus of contingency planning the multifaceted approaches to ensure that critical system and network assets remain functionally reliable. Contingency planning accounts for an emergency response, backup operations, and post-disaster recovery as a set of comprehensive, consistent, documented, and tested procedures. When services are interrupted, adequate backups ensure that security functions and user data are continuously maintained. When data is...