Hi Everyone!
I'm looking at creating my first policy and putting some of my CISSP to use in the form of a disaster recovery policy for the local authority I work for. I'm wondering if there are any good resources to use and examples of these? I'm trying to make sure that this stays a policy and doesn't become a plan as this needs to be the broad direction that the organisation takes not any step by step.
Appreciate any pointers or resources that will help.
Rob
You can certainly go this route, as I'm sure people have created specific DR policies on this forum but this is typically covered in a Contingency Planning Policy, which encompasses BC and DR plans. Along with many other types of plans, e.g., Cybersecurity Incident Response Plans, Crisis Communications Plans, etc.
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf
NIST 800-34, Rev 1 Contingency Planning Guide for Federal Information Systems
Tagging @CISOScott because he has extensive experience in Government work. Some things to include if I were to create a specific DR policy in no particular order:
There's more but others can chime in with their thoughts.