Tech

Guides
 

Put an Internet disaster plan in place

By Jonathan Yarden, Special to ZDNet Asia
Wednesday, September 20, 2006 02:34 PM

Find out why Jonathan Yarden advises companies to prepare for Internet disasters in the same manner they do for natural disasters and physical ones.

In the weeks since Hurricanes Katrina and Rita, there has been much talk about disaster preparation as well as discussions on how society can avoid such a tragedy the next time. And that's not surprising: Such large-scale situations, including Hurricane Katrina, September 11, and even the Blackout of 2003 in the northeastern United States, always highlight the importance of strong disaster recovery plans.

In the aftermath, organizations tend to focus more time and money on preparing for natural disasters (such as hurricanes and earthquakes) and physical disasters (such as fires and floods). However, what companies often fail to realize is that disasters also pose a significant threat to electronic assets--particularly in our ability to communicate and in the value of information itself.

An Internet disaster--whether accidental or intentional--could damage or destroy the ability of a company to communicate with the outside world and seriously impact business. For example, a company that's the target of a denial of service (DoS) attack or that has lost its Internet connectivity due to a cut fiber-optic cable is often helpless.

Knowing what to do in these cases can be confusing, but companies should seriously consider the cost of lost productivity due to Internet problems. It can be extremely difficult to plan for or recover from an electronic disaster due to the complexity of the Internet.

Planning for a physical threat to a building (such as a fire) and to the employees who work in that building requires sprinklers, fire alarms, and fire escapes. Similarly, strict access controls and expensive fire-suppression equipment typically protect a corporate data center because serious problems could cause a significant loss of business. (This planning occurs not only for the safety of the occupants, but also because of fire codes and insurance requirements.) In addition, most companies plan for power problems by using battery-backed power supplies or installing backup generators.

Some companies plan for internal computer system disasters on key assets by using clustering and highly available server systems and by using a disaster recovery vendor. They put the time and money into all of this disaster planning because these assets are essential tools of business. Yet, in my experience, even though many companies consider the Internet an essential tool to conduct business, few plan for Internet problems--until, of course, the systems stop working.

When there's a problem (such as a mass-mailing worm) that disables a company's e-mail server, this shuts off e-mail. A crashed virus-scanning system or firewall also paralyzes e-mail. A DoS attack on a gateway router can shut off a company from the Internet completely. By the same token, a fiber cut in Chicago can shut off a company in Cleveland.

That's why I advise companies to prepare for Internet disasters in the same manner they do for physical disasters. Being prepared for Internet disasters requires planning and redundancy on key Internet systems, similarly to how some companies implement highly available systems for internal business needs. This means that companies that depend on the Internet as a communication tool should consider these essential components: multiple Internet gateways, redundant firewall systems, e-mail servers, and virus-scanning systems.

Companies should plan for virtual disasters in the same manner as physical disasters by developing and implementing disaster planning procedures for Internet equipment. If your company is Internet-dependent, make sure you're prepared in the unfortunate event that a disaster occurs.

Jonathan Yarden is the senior UNIX system administrator, network security manager, and senior software architect for a regional ISP.



WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.

Guest user

Guest user

Level: 
Joined: —
Already a member? Log in »



 

Loading...

Getting credit for having a BCP

Blog thumbnail

In July U.S. credit rating agency Standard & Poor's (S&P) started evaluating the enterprise risk management (ERM) capabilities of non-financial companies that it covers. This is S&P's announcement, and here..... by Nathaniel Forbes

Read more »

Whitepapers / Case Studies

Downloads

Disaster Recovery News


Tech Jobs Now!

Tags

  1. access
  2. customize
  3. determine
  4. disable
  5. easily
  6. easy
  7. excel
  8. handle
  9. install
  10. keep
  11. know
  12. letters
  13. out
  14. own
  15. pc
  16. printing
  17. project
  18. run
  19. scripting
  20. security
  21. server
  22. should
  23. sql
  24. time
  25. use
  26. user
  27. web
  28. what
  29. windows
  30. word