ITS Contingency Planning Policy
Policy Statement
To ensure that University business can continue in the event of a disaster, disaster recovery plans for all University information systems will be developed and tested on a regular basis.
Entities Affected By This Policy
All areas of Information Technology Services responsible for the administration and/or maintenance of a University information resource.
Contacts
EIU Information Security 217-581-1939
Principle
Contingency Plan
- All areas of ITS that are responsible for the administration and/or maintenance of information resources must develop a contingency plan for those resource
- ITS information resource contingency plans must contain:
- A list of individuals responsible for system recovery
- Contact information for these individuals
- A list of responsibilities for these individuals
- A list of hardware required for recovery
- A list of software required for recovery
- A list of system and/or data backups for recovery
- A list of any secondary or redundant systems for recovery
- A detailed explanation for the steps required for recovery
- The manager overseeing the area(s) responsible for the administration and/or maintenance of the information resource is responsible for reviewing contingency plans, approving all contingency plans and distributing copies of the plans to the ITS Disaster Recovery coordinator
- All contingency plans will be collected by the ITS Disaster Recovery Coordinator and stored in the departments ITS Disaster Recovery Plan
- The ITS Disaster Recovery Plan must include:
- A list of emergency service contact information
- A list of the various ITS Disaster Recovery Teams, including:
- Names
- Contact information
- Responsibilities
- The stated goal of the ITS Disaster Recovery Plan
- Procedures for initiating all or any part of the ITS Disaster Recovery Plan
- Procedures for documenting disaster recovery procedures
- Procedures outlining disaster recovery test response testing
- All information resource specific disaster recovery plans
- All disaster recovery plan test and the outcomes
- All actual disaster recovery responses and the outcomes
Contingency Training
- All areas of ITS must train individuals tasked with information resource recovery to ensure these individuals are aware of their roles and responsibilities outlined in information resource contingency plans
- All contingency training exercises must include simulated events to facilitate effective response and uncover unknown issues prior to a crisis situation
Contingency Plan Testing and Exercises
- ITS will conduct annual contingency plan tests and/or exercises of some set of information resources, as determined by the ITS Disaster Recovery Management Team, at least annually
- Contingency plan tests and/or exercises must be conducted after major information resource changes and/or changes to the recovery procedures
- All contingency plan tests and/or exercises must be constructed to simulate the failure of the primary information resource and/or a failure of the main operations area housing University information resources
- Contingency plan tests and/or exercises must follow established recovery procedures for all information resources involved in the test/exercise, including the use of secondary and/or redundant resources and/or locations
- The ITS Disaster Recovery Management Team will review the results of all contingency plan tests and/or exercises and will initiate any corrective actions necessary
Contingency Plan Update
- The ITS Disaster Recovery Management Team will review the department contingency plan at least annually and institute any changes that need to be made
- Immediately following each contingency plan test and/or exercise, the ITS Disaster Recovery Management Team, as well as the team responsible for the specific information resource(s) tested, will review the outcome of the test/exercise and determine which corrective actions to take, if necessary
Alternate Data Center
- The ITS Disaster Recovery Management Team will continue to assess the viability of establishing a secondary data center to house secondary and/or redundant systems for recovery use during crisis situations
Related Documents
ITS Disaster Recovery Plan
Supporting Policies, Procedures and Guidelines
TBD
Last Date Reviewed: 06/13/2024