Disaster Recovery

Being prepared means planning for the worst and expecting the best. While CU*Answers has invested steadily over the past decade developing and implementing High Availability strategies to prepare us to continue operations through likely disruptive scenarios, we would fall short on our commitment if we did not plan for those unexpected, large-scale disasters, outside of the scope and reach of high-availability controls.

In the event of a disruption where failing-over to redundant hosts at the secondary datacenter is not an option, recovery teams will follow the necessary recovery procedures to restore the production system from backup media at a surviving site. To ensure our recovery teams are fully trained and capable and that procedures are validated and confirmed, bare-metal recovery exercises are performed on systems in a sandbox test environment.

For applications and systems that are not categorized as “core-processing” and are not included in the High Availability strategy, IT Contingency and Recovery Plans are maintained and tested regularly. Where feasible, redundant components are installed on systems and hardware to mitigate the risk of component failure and expedited warranty service maintained (most with 4 hour support or less).

Results from each disaster recovery test are published in a report and available for download. In-network credit unions are encouraged to review each report and to include them in their board packet documentation.

The Recovery Planning Process

Having a test-validated recovery plan that clearly articulates which systems must be recovered and in what order is crucial if an organization is to resume normal operations within an acceptable timeframe. A test-validated Disaster Recovery Plan should answer the following questions:

  • What happens when disaster strikes?
  • Will what we have planned support our business?
  • How do we resume ‘normal’ business procedures?

The information obtained from current Business Impact Analysis (BIA) and Risk Assessment (RA) reports will identify the amount of downtime tolerable before the organization is significantly impacted, and provide a prioritized list of systems that are required to restore critical business functions.  A recovery plan should include all of the steps required to bring systems back on-line and re-establish functionality for system end-users. These systems to restore include main and branch office facilities, hardware, software, data, and communications networks.

Components required for a successful recovery include:Components required for a successful recovery

  • Test-validated documentation for restoring systems
  • Skilled personnel
  • Access to vital records (data), and
  • Alternate recovery resources

 

 

 

For the Credit Union

Whether an on-line or in-house credit union, having a test-validated recovery plan for all resources required to perform critical business functions is the baseline. To be effective, your recovery plan must provide a roadmap for restoring minimum service levels within a time-frame that is acceptable to the organization (within the parameters of RTO/RPO as identified in the BIA).

Business Impact Analysis (BIA)“is the Process of identifying the potential impact of uncontrolled, non-specific events on an organization’s business processes.”

Recovery Time Objectives (RTO) –  “represent the maximum allowable downtime that can occur without severely impacting the recovery of operations or the time in which systems, applications, or business functions must be recovered after an outage (e.g., the point in time that a process can no longer be inoperable).

Recovery Point Objectives (RPO)“represent the amount of data that can be lost without severely impacting the recovery of operations or the point in time in which systems and data must be recovered (e.g., the date and time of a business disruption).”

 For more information, see the “Resilient Credit Union.

Next Steps

CU*Answers offers professional and managed services to help you meet and exceed your recovery objectives. Contact a CU*Answers Continuity Consultant today to discover in-network solutions that best meet your business objectives.

 

AdvantageCIO

 Professional Services available include:

  • Business Continuity Planning and Resilience Testing
  • Information Security Risk Assessment
  • Comprehensive Information Security Program (CISP)
  • Staff Security Training
  • IT Examination and Audit Preparation
  • IT Strategy Consulting
CU*Answers Network Services

Managed Services available include:

  • Network Management and Monitoring
  • Continuous Data Protection (CDP) including off-site data storage
  • Virtual Branch / Virtual Office
Updated
August 11, 2015

[The Pulse] 2021 Business Continuity Plan Now Available

[The Pulse] 2021 Business Continuity Plan Now Available

CU*Answers Business Continuity Plan: 2021 Release Now Available   As your core data processor, we continue to invest in high availability and recovery strategies to ensure that the products and services you count on us for are there when you need them. Implementing those strategies and responding when uncertainty happens requires a well-designed and thoroughly… Read more »

Feb 1, 2021

CU*Answers assists credit union in flexing their incident response skills

On January 8, 2021, CU*Answers facilitated a virtual tabletop exercise for credit unions in Taylor, MI as part of the training and testing program for the Incident Response Plan. Participants began with an overview of Incident Response and the similarities to Business Continuity Planning. From there the exercise shifted to a walk-through of the Incident […]

Jan 22, 2021

CU*Answers offers “Components of the CU Information Security Program” education course

On January 13, 2021, CU*Answers presented a complimentary web-based educational course for credit unions to assist them in building, implementing, and testing a risk-based information security program. Titled, “Components of an Information Security Program”, participants were guided through the stages of developing a program from risk and technology assessment, asset inventory and classification, controls selection […]

Jan 22, 2021

Let CU*Answers Help Design Your Business Continuity Plan!

Let CU*Answers Help Design Your Business Continuity Plan!

The CU*Answers Business Continuity Team continues to invest in high availability and recovery strategies to ensure that the products and services you count on us for are available when you need them. Implementing strategies and responding when uncertainty happens requires a well-designed and thoroughly tested plan, helping you to continue serving your members, even when… Read more »

Dec 1, 2020

Is Your Credit Union Looking to Review Cybersecurity Compliance?

Is Your Credit Union Looking to Review Cybersecurity Compliance?

October is national cybersecurity awareness month!  While a robust cybersecurity plan is integral to the year-round business functions of financial institutions across the country, this month presents additional opportunities to re-evaluate your current program and consider changes you can implement to strengthen your security posture. AdvantageCIO offers a Cybersecurity Compliance Bundle designed specifically to address… Read more »

Oct 23, 2020

Is Your Staff Ready for Unexpected Incidents or Disruptive Events? We Can Help.

Is Your Staff Ready for Unexpected Incidents or Disruptive Events?  We Can Help.

Two key components of your Information Security Program is a test-validated Incident Response Plan and a trained response team. Your credit union’s Information Security program should be engrained in the corporate culture and an accepted part of job responsibilities throughout the organization.  Achieving this goal requires an ongoing awareness and training program that educates and prepares… Read more »

Oct 21, 2020

[The Pulse] CU*BASE HA and It’s Me 247 Rollover Results Now Available

[The Pulse] CU*BASE HA and It’s Me 247 Rollover Results Now Available

CU*BASE HA and “It’s Me 247” Rollover Results Now Available HA Rollover: September 13-20 It’s Me 247 Rollover: September 9 & 15 Now available for your review are summaries of the recent HA (high-availability) rollover events performed in September for both CU*BASE core processing and online banking environments. In these reports, you will find details… Read more »

Oct 21, 2020

FREE: Order a DVD Guide on Cybersecurity for Your Credit Union

FREE: Order a DVD Guide on Cybersecurity for Your Credit Union

If your board of directors would like a guide on the basics and terminology of cybersecurity, CU*Answers has produced a DVD that your credit can order, FREE of charge!  Remember that the FFIEC and examining bodies are expecting “the need for engagement by the board of directors and senior management, including understanding the institution’s cybersecurity… Read more »

Oct 13, 2020

3 Down, Just One More to Go! Final Stage of Rollover on Sunday

3 Down, Just One More to Go! Final Stage of Rollover on Sunday

Don’t forget: this month, we will be performing multiple rollovers including CU*BASE/GOLD and Online Banking.  In the past, these rollovers have been performed independently.  However, this month we will be performing the rollovers together.  While we are live with CU*BASE/GOLD production from our High Availability (HA) data center in Yankton, SD, we will also be… Read more »

Sep 17, 2020