What Are The Primary Factors That Influence Ffc's Business Continuity Planning

Great Essays
Findings --IT Management

The IT Management controls appear to be properly implemented and effectively working for FFC. The assessed level of risk is low. FFC has a strong IT strategic plan that is in line with the corporate strategic plan which has a diverse set of strong members on the committees and allows for fundamentally sound decisions that are best for the organization by taking all aspects of the business into consideration. The organizational structure is conducive to a strong and clear reporting channels which include the CIO reporting to the CFO and EVP. One step lower on the corporate ladder the VPs of applications, operations, information security and database administration reports to CIO.

Findings -- System Development
…show more content…
The primary factor that influenced this grade is the fact that FFC has no documented business continuity or disaster recovery plan in place to provide a framework to ensure that the organization will continue to operate with minimum disruption if a natural disaster or any other event that threatens operations occurs. Management believes such a plan is cost prohibitive for an organization of its size, and relies on the fact that they have never experienced any major business disruption. FFC’s unofficial plan is to have the data center manager retrieve the most recent backup tapes to recover its systems in case of disaster. This plan does not take into account the possibility of their primary facilities and resources becoming unavailable for use. Although FFC back-ups its data on a daily basis, the audit team believes that the backup data should be transported to the off-site facility on a more frequent basis. An additional weakness is that FFC has not tested their backup tapes during the past year, and has no plan to test these tapes in the future. Without this testing, FFC is unable to effectively monitor whether or not they are capable of effectively restoring lost data and resuming operations through the recovery …show more content…
In addition to managing ongoing IT operations and system development, the IT function must ensure that computing resources are operational and secured. To ensure that computing resources are secured, management should establish a process to account for all IT components. Processes should be in place to identify, track, and resolve problems in a timely manner. We recommend that FFC should implement a business continuity management program immediately that defines an effective policy and response plan, and assigns responsibilities to an established response team. FFC should regularly rehearse the plan, perform timely and appropriate maintenance, and review the testing and updating to confirm that the plan is operating effectively. Additionally, FFC should embed the business continuity management program into the organization’s culture, providing the necessary education, training, and awareness to all employees so that they are ready to respond effectively during a catastrophic event. Although mirror sites or electronic vaulting may not be cost effective alternatives, FFC should make arrangements with hardware vendors, service centers, or others for standby use of compatible computer equipment through the use of a hot or cold site. A cold site is a less costly option that will provide FFC with an alternative computer facility

Related Documents

  • Superior Essays

    Nt1310 Unit 8.2

    • 772 Words
    • 4 Pages

    Many of these concerns may be remedied by simply revisiting the company policies and procedures. Data loss is a serious problem. Typically large companies have an automatic data backup in place. Proper automatic backups can be set up daily, weekly, or monthly. For this size company, I would recommend daily backups.…

    • 772 Words
    • 4 Pages
    Superior Essays
  • Improved Essays

    Employees are responsible for maintaining the information that may reside on various storage platforms utilized at the university, to include emails, databases, text files, pdf files, computer usage logs, and other…

    • 1033 Words
    • 5 Pages
    Improved Essays
  • Improved Essays

    Ba501 Week 1 Assignment

    • 740 Words
    • 3 Pages

    These studies might show labor hours needed, hardware and software costs, utility costs and prevention of data lost. Another aspect of computer security is disaster recovery, this might include damage caused by a natural or manmade occurrence. Computer equipment that is damaged might include sensitive information stored on hard drives and these would either need to be recovered or disposed of. The key decision makers in a security project would include: Chief Executive Officer: The most senior corporate officer reports to the board of directors.…

    • 740 Words
    • 3 Pages
    Improved Essays
  • Improved Essays

    The data are straightforward to backup as all the data is stored on the file server and this is significant because the work that is done might have been a lot. Therefore, it is a decisive factor. Although, purchasing the network cabling and file servers can be expensive and managing a large network is complicated, requires training and a network manager usually needs to be employed. However, for Progress Vinyl Music Stores there company would find it useful in view of that it is faster and it makes it easier. The employees would need to be trained regularly, but this is beneficial for the future considering the employees are likely to stay if the company offers support.…

    • 542 Words
    • 3 Pages
    Improved Essays
  • Great Essays

    Risk: Disaster takes place that affects the access to PCBB or Silverlake Mitigation Strategies: A. Board approved Business Continuity Plan is in place B. Appropriate processes and controls exist to manage and protect…

    • 1287 Words
    • 6 Pages
    Great Essays
  • Improved Essays

    INFO 290: Final Exam

    • 1200 Words
    • 5 Pages

    INFO 290 – Final Exam Name (Print) Cristian David Ramirez-Loaiza Signature______________ Date:____________ Answer any FOUR questions 1. Explain in detail with examples as to why a business needs a disaster recovery plan and Business Continuity plan?…

    • 1200 Words
    • 5 Pages
    Improved Essays
  • Decent Essays

    Ist 305 Assignment 6-3

    • 538 Words
    • 3 Pages

    ID: 2597622 IST 305 – Assignment 6 6-1: The Toronto Globe and Mail had an information systems issue with how their business databases and files were stored. Throughout the firm, multiple databases were isolated and duplicated among departments. This had caused issues, such as their subscribers receiving unnecessary marketing material, and not being able to keep the databases secure. In order for them to solve this issue was to implement and store all company data into a data warehouse using SAP NetWeaver, as well as educate their own employees on the new system to prevent further inconsistent databases. By implementing the data warehouse and training their employees, it produced the results that management envisioned.…

    • 538 Words
    • 3 Pages
    Decent Essays
  • Improved Essays

    P1 – The impacts that different types of threats have on an organisation Technical Failure A technical failure can be caused for many different situations. Most devices will fail at some point because of some kind of error. There are certain measures that can be put into place to avoid these errors from occurring more often. Such as the training of staff of the device they are using so these issues will become less common and then they will also be to most likely solve the problem also.…

    • 1227 Words
    • 5 Pages
    Improved Essays
  • Decent Essays

    Macy’s Inc. relies extensively on technology and on its information systems to process transactions, compile results and operate its business. As an advantage, Macy’s Systems and Technology, Inc. engages in creating, collecting, and directing pieces of data to form management tools. The company implements integrated retail, e-commerce, and data warehouse systems. As a disadvantage, the information systems can be subject to interruption from power outages, damage from viruses, cyber-attack or other security breaches. In these cases, companies like Macy’s may experience the loss of critical data and delays in its processes.…

    • 111 Words
    • 1 Pages
    Decent Essays
  • Great Essays

    Breonna Case Study

    • 611 Words
    • 3 Pages

    It supports decision-making and operational management, and it provides accountability. It is also a business asset and resource (Bradley A 2011) Findings and Analysis What's the solution ?…

    • 611 Words
    • 3 Pages
    Great Essays
  • Improved Essays

    The Dodd-Frank Act was a piece of legislature passed by the Obama administration in 2010. This act is formally known as the Dodd-Frank Act Wall Street Reform and Consumer Protection Act. This piece of legislature was a response to the financial crisis of 2008. The Dodd-Frank Act at the time of passing consisted of 2,307 pages, 16 titles and 540 sections of law. This piece of legislation was named after Senator Christopher J. Dodd and Representative Barney Frank who had endorsed this act.…

    • 1726 Words
    • 7 Pages
    Improved Essays
  • Improved Essays

    The purpose of the Continuity of Operations Plan is to keep the government running and the sustainment to keep functioning in an operational manner. The continuity of operations (COO) and the continuity of government (COG) work together for the common goal of the public, private sector stakeholders and the government to mitigate the effects of hazards activity. Without a functioning government who will be the responsible party to step up and give direction when faced with great destruction or even death after a hazard event has taken place. Survival of leadership and or those who will take their place ensures that the right proper authority will exercise powers in any capacity of a hazardous event (COOP Fact Sheet). Having these plans in…

    • 339 Words
    • 2 Pages
    Improved Essays
  • Improved Essays

    Recovery Planning

    • 443 Words
    • 2 Pages

    With the today’s reliance on EHR’s, healthcare organizations have little tolerance for downtime and reverting to a paper based operation is no longer practical. Healthcare organizations must plan on how to recover business operations as well as the foundational IT systems and the data required to treat patients (e.g. electronic personal health information (ePHI)). Continuity, Contingency and Disaster Recovery planning are often used interchangeably when discussing recovery planning. They are critical components of emergency management and organizational resilience, but each type of planning has a very specific focus. Continuity planning exists to recover your healthcare organizations critical business functions and processes a disaster or adverse…

    • 443 Words
    • 2 Pages
    Improved Essays
  • Improved Essays

    Zones: The Entity-Level controls associated with ABC Ferries include a Disaster Recovery Plan, and an Internal Audit of all IT records. Because the Disaster Recovery Plan focuses on higher-level issues, ensuring that all information is backed up off-site and a complete plan is in place in case of a disaster, it is considered an Entity-Level control. In addition, the Internal Audit is performed to help detect fraud and is an overall policy that is in place, making it an Entity-Level control as well. The IT General Controls in the system are an Employee Login ID and Fingerprint Scanner, Removal of Duplicate Entries, and a Summary of Employee Logs.…

    • 751 Words
    • 4 Pages
    Improved Essays
  • Improved Essays

    Team 3: Vadde Aditya, Bishal Bk, Fang Fang, Suraj Karki, Varshini Paladugu, Raghuveerreddy Suram Week 7 Group Assignment • Discuss what can happen if the framework you choose as a foundation does not fit your organization’s business objectives. If the framework the organization choose as a foundation does not fit the business objectives, it may face several problems as following. 1.…

    • 723 Words
    • 3 Pages
    Improved Essays