<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disaster Recovery Policy in Governance, Risk, Compliance</title>
    <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Disaster-Recovery-Policy/m-p/49404#M594</link>
    <description>&lt;P&gt;You can certainly go this route, as I'm sure people have created specific DR policies on this forum but this is typically covered in a Contingency Planning Policy, which encompasses BC and DR plans. Along with many other types of plans, e.g.,&amp;nbsp;Cybersecurity Incident Response Plans, Crisis Communications Plans, etc.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf" target="_blank" rel="noopener"&gt;https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-34r1.pdf" target="_blank"&gt;NIST 800-34, Rev 1 Contingency Planning Guide for Federal Information Systems&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tagging&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1602421967"&gt;@CISOScott&lt;/a&gt;&amp;nbsp;because he has extensive experience in Government work. Some things to include if I were to create a specific DR policy in no particular order:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Purpose&lt;/LI&gt;&lt;LI&gt;Scope&lt;/LI&gt;&lt;LI&gt;Roles and responsibilities&lt;/LI&gt;&lt;LI&gt;Specific disasters that will be included in the DRP&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Defining recovery time objectives (Or at least say it's going to be included in the DR plan)&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;BIA requirements&lt;/LI&gt;&lt;LI&gt;Communication plan or point to one that's already created&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;There's more but others can chime in with their thoughts.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 28 Jan 2022 21:04:59 GMT</pubDate>
    <dc:creator>tmekelburg1</dc:creator>
    <dc:date>2022-01-28T21:04:59Z</dc:date>
    <item>
      <title>Disaster Recovery Policy</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Disaster-Recovery-Policy/m-p/49403#M593</link>
      <description>&lt;P&gt;Hi Everyone!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm looking at creating my first policy and putting some of my CISSP to use in the form of a disaster recovery policy for the local authority I work for. &lt;A href="mailto:I@m" target="_blank"&gt;I'm&lt;/A&gt;&amp;nbsp;wondering if there are any good resources to use and examples of these? I'm trying to make sure that this stays a policy and doesn't become a plan as this needs to be the broad direction that the organisation takes not any step by step.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciate any pointers or resources that will help.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Rob&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jan 2022 18:33:15 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Disaster-Recovery-Policy/m-p/49403#M593</guid>
      <dc:creator>Rob243</dc:creator>
      <dc:date>2022-01-28T18:33:15Z</dc:date>
    </item>
    <item>
      <title>Re: Disaster Recovery Policy</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Disaster-Recovery-Policy/m-p/49404#M594</link>
      <description>&lt;P&gt;You can certainly go this route, as I'm sure people have created specific DR policies on this forum but this is typically covered in a Contingency Planning Policy, which encompasses BC and DR plans. Along with many other types of plans, e.g.,&amp;nbsp;Cybersecurity Incident Response Plans, Crisis Communications Plans, etc.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf" target="_blank" rel="noopener"&gt;https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-34r1.pdf" target="_blank"&gt;NIST 800-34, Rev 1 Contingency Planning Guide for Federal Information Systems&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tagging&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1602421967"&gt;@CISOScott&lt;/a&gt;&amp;nbsp;because he has extensive experience in Government work. Some things to include if I were to create a specific DR policy in no particular order:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Purpose&lt;/LI&gt;&lt;LI&gt;Scope&lt;/LI&gt;&lt;LI&gt;Roles and responsibilities&lt;/LI&gt;&lt;LI&gt;Specific disasters that will be included in the DRP&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Defining recovery time objectives (Or at least say it's going to be included in the DR plan)&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;BIA requirements&lt;/LI&gt;&lt;LI&gt;Communication plan or point to one that's already created&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;There's more but others can chime in with their thoughts.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jan 2022 21:04:59 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Disaster-Recovery-Policy/m-p/49404#M594</guid>
      <dc:creator>tmekelburg1</dc:creator>
      <dc:date>2022-01-28T21:04:59Z</dc:date>
    </item>
    <item>
      <title>Re: Disaster Recovery Policy</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Disaster-Recovery-Policy/m-p/49428#M595</link>
      <description>That sounds like a good place to start really appreciate it! There is already a BC policy in place but it only covers the business side of a situation and what IT is required and due to a data center cloud migration its no longer fit for purpose. I'm trying to create a policy that sits with IT so it can be updated and underpin a specific IT DR plan so when a system or DR event happens the policy states the direction the business is taking and the IT DR plan can be kept upto date with moving technologies and systems so the IT department has a play book for most eventualities.&lt;BR /&gt;&lt;BR /&gt;Hope that makes sense</description>
      <pubDate>Sun, 30 Jan 2022 13:28:02 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Disaster-Recovery-Policy/m-p/49428#M595</guid>
      <dc:creator>Rob243</dc:creator>
      <dc:date>2022-01-30T13:28:02Z</dc:date>
    </item>
  </channel>
</rss>

