1. Security, Privacy, and Other AIS Issues
You've been hired by a growing organization to perform systems consulting work. The CEO has concerns about systems security and the impact of privacy considerations on the organization's AIS. She is also interested in learning more about new and emerging AIS technologies that the organization should consider. You have been asked to provide a report on these areas. Your report will be used as a basis for planning and developing improvements to the AIS.

Prepare a paper to deliver your findings to the CEO. In your paper, include the following:

a. A disaster recovery/contingency plan that includes the following:
b. Identification and analysis of procedures to detect vulnerabilities and security threats (i.e., controls)
c. Identification and analysis of risks and risk mitigation measures, including plans for
i. Systems and data recovery
ii. Off-site data storage
iii. Business continuity
c. An analysis of the impacts of privacy considerations on AIS (i.e., HIPAA)

Use at least two academically peer-reviewed sources and/or your text author to support your work or your text authors. Be sure to properly cite any references used in your summary. Format the summary according to APA style.

You've been hired by a growing organization to perform systems consulting work. The CEO has concerns about systems security and the impact of privacy considerations on the organization's AIS. She is also interested in learning more about new and emerging AIS technologies that the organization should consider. You have been asked to provide a report on these areas. Your report will be used as a basis for planning and developing improvements to the AIS.

Disaster recovery/contingency plan that includes the following:
A disaster recovery plan (DRP) - sometimes referred to as a business continuity plan (BCP) or business process contingency plan (BPCP) - describes how an organization is to deal with potential disasters.
Disaster recovery is becoming an increasingly important aspect of enterprise computing. Appropriate plans vary from one enterprise to another, depending on variables such as the type of business, the processes involved, and the level of security

The document that defines the resources, actions, tasks and data required to manage the business recovery process in the event of a business interruption. The plan is designed to assist in restoring the business process within the stated disaster recovery goals.

Thus Disaster recovery planning involves an analysis of business processes and continuity needs; it may also include a significant focus on disaster prevention. Disaster recovery plan covers the data, hardware and software critical for a business to restart operations in the event of a natural or human-caused disaster.

II. The Importance of Disaster Recovery Planning

Need for Disaster Recovery Plans

There are many different risks that the company faces which can be:

? Natural disasters
? Fire
? Power Outages
? Terrorist attacks
? Organized or deliberate disruptions
? System and/or equipment failures
? Human error
? Computer Viruses
? Legal programs


According to Jon William Toigo (the author of Disaster Recovery Planning), fifteen years ago a disaster recovery plan might be more simple but the current enterprise systems tend to be too complicated and loss of data can have serious financial impact.

It is believed that some companies spend up to 25% of their budget on disaster recovery plans; however, this is to avoid bigger losses. Of companies that had a major loss of computerized records 43% never reopen, 51% close within two years, and only 6% will survive long term. (Cummings, Haag & McCubbrey 2005.)


Thus the planning gave help in the inculcating the disciplines and efficiencies in the organization to tackle the risks in an effective manner. It helps in mitigating the losses and improving the confidence in the employees

III. Implementing a Disaster Recovery Plan

It is a part of the risk management process plan and the steps will include:
? Identification of the risks
One has to identify the various risks that can affect the organization. It will include the problem definition, project objectives and selection of the disaster recovery team.
As per the below link the important documents required for the preparing the plan are:

? Organization chart showing names and positions

? Existing plan (if available)

? Staff emergency contact information

? List of suppliers and contact numbers

? List of emergency services and contact numbers

? Premises addresses and maps

? Existing evacuation procedures and fire regulations

? Health and Safety procedures

? Operations and Administrative procedures

? List of professional advisers and emergency contact information

? Personnel administrative procedures

? Copies of floor ...

