SlideShare a Scribd company logo
IT Disaster Recovery
Readiness
MATURITY MODEL TO ASSESS YOUR IT DR PROGRAM
Maturity Model Purpose
 The purpose of this model is to help the reader in evaluating the current
status of his/her Disaster Recovery program.
 Beside that, below sample use-cases for this maturity model:
 Evaluate the current Risk level on business continuity in event of disaster.
 Anticipate a road-map or desire state for IT Disaster Recovery planning.
 business case input for Disaster Recovery initiative.
 Driver for Integration plan for multiple enterprise wide capabilities into
Disaster recovery planning.
 Use as scale to evaluate multiple capabilities or line of businesses against
each other in term of disaster recovery readiness.
Maturity levels Definition
Level Definition Description
1 Initial or Ad hoc minimal or ineffective recovery capabilities in-place.
2 Established or
Reactive
disaster recovery strategy in-place but lack proper capabilities
and handled on best-efforts bases.
3 Prepared or business
enabled
disaster recovery strategy in-place and align with business
demands.
4 Managed or
Proactive
disaster recovery managed as program where dedicated team
manage/maintain/validate various components of disaster
recovery program.
5 Optimized or
resilient
disaster recovery program complement & seamlessly
integrate with various enterprise wide practices (IT/none-IT)
and address growth requirement.
This Model has five levels of readiness or maturity for Disaster Recovery “DR” capabilities,
where level 0 “Non-existent” removed due to easiness of determining the same “lack of
recovery strategy or capabilities”.
Maturity Model Structure
 I have structured this model into three (3) main ITDR components (21 ITDR
capabilities), each of them measure different aspects of DR capabilities:
 ITDR Strategy (measure stakeholder engagement “reflected as Interest & Power”
in ITDR)
 ITDR Implementation (measure IT alignment with business demands)
 ITDR Exercise & Maintenance (measure the effectiveness “reflected on Success
rate & Credibility/Confidence level” of ITDR program)
 The outcome of overall review of these three ITDR components, will be
Maturity/Readiness level for Enterprise’s recovery capabilities in term of:
 Recovery likelihood
 Risk to business
Measuring Capabilities
 For each ITDR component, set of measuring capabilities identified to help
differentiating different maturity level:
ITDR Strategy ITDR Implementation ITDR Exercise &
Maintenance
ITDR Plan Recovery site setup & connectivity Support/SLA for ITDR infrastructure
ITDR Processes & Procedures
(BIA/RA)
Data Backup/Restore & Replication Backup/Restore testing & validation
ITDR Team , Roles, & Responsibilities Configuration synchronization Infrastructure Monitoring
Backup/Recovery practice DR Facility & User connectivity ITDR Training
ITDR Budget & fund ITDR Run-book or Play-book ITDR Infrastructure/Application/OS
Patching Practice
ITDR integration with Enterprise wide
practices
ITDR Infrastructure ITDR testing exercise
ITDR Road-map ITDR Failover/Failback
Implementation
ITDR Audit , Report & document
review.
ITDR Strategy Maturity
LEVEL TO CAPABILITY MAPPING
Level to capability Mapping
ITDRStrategy Level1 (Unaware) Level 2 (Neutral) Level 3 (Sponsor) Level 4 (Involved) Level 5 (Empower)
 Basic Backup/Recovery
Procedure documented.
 Lack of ITDR plan, processes
or procedures documented.
 Lack of BIA/RA Performed to
identify IT Critical services &
its RTO/RPO demands .
 Lack of ITDR Team structure
(best-efforts bases).
 Lack of dedicated Budget.
 Basic definition of critical
services documented (IT
point of view).
 Backup/Recovery Procedure
documented.
 One General Definition for
recovery strategy for all IT
services.
 High-level or Basic ITDR Plan
documented (usually as part
of IT procedures).
 Budget funded from other IT
initiatives.
 Partial recovery team
structure, but roles
responsibilities not clearly
defined (lack of ownership).
 Chaotic DR communication ,
declaration & escalation
structure ( lack of
governance structure)
 Business RTO/RPO defined
(through Business Impact
Analysis “BIA”).
 Backup/Recovery Procedure
documented & align with
defined RTO/RPO.
 ITDR Plan documented but
not reviewed or it is
reviewed but on best efforts
bases.
 ITDR BIA/RA processes &
procedures documented.
 Criticality-based recovery
strategy (ex. Replication for
critical services and restore
from backup for others).
 ITDR recovery strategy cover
both Failover/Failback.
 Lack of dedicated ITDR lead
identified but the “acting-
as” defined.
 Recovery team member
identified.
 ITDR communication,
declaration & escalation
structure documented.
 Level 3 (in addition to the
following).
 ITDR Plan Reviewed in
Frequent bases.
 KPI Defined for various IT DR
Plan components.
 ITDR Road-Map defined.
 ITDR Budget allocated.
 Recovery Strategy Defined
Per-service.
 ITDR Roles and
Responsibilities Defined.
 ITDR process automation
(BIA/RA) in-place.
 ITDR Plan cover full, partial
(multiple-services), &
service-level
Failover/Failback.
 ITDR planned as part of IT
budget & infrastructure
capacity planning.
 Level 4 (in addition to the
following).
 ITDR integrated with change
management process.
 ITDR Road-map integrated
with business plan/IT
strategy.
 ITDR Processes and
procedures integrated in
enterprise architect as well
 ITDR requirements collected
as part of business
requirements gathering for
any new IT initiative.
 ITDR Integrated with both
business continuity plan
(BCP) and Crisis
Management Plan (CMP) for
the enterprise.
 IT DR Roles &
Responsibilities integrated
as part of job description.
 (in case of insurance) IT DR
integrated with Enterprise
insurance plan.
 ITDR communication plan
align with enterprise
communication guidelines.
Indicator
Low (Power , Interest)
Stakeholder Engagement
High (Power, Interest )
ITDR Implementation Maturity
LEVEL TO CAPABILITY MAPPING
Level to capability Mapping
ITDRImplementation
Level1 (Siloed) Level 2 (best-
efforts)
Level 3 Level 4 (Improve) Level 5 (Value
Creator)
 Basic backup/restore
capability.
 Cold recovery site
capabilities.
 Lack of resiliency for DR site
connectivity.
 Shared and/or Low
Bandwidth DR link.
 Legacy or limited DR
infrastructure components
implement.
 Lack of user’s connectivity
planned.
 Advanced backup/restore
capability (restoration
testing capability in-place).
 Basic data replication
capability in-place.
 Warm recovery site
capabilities.
 Active/standby connectivity
for DR site.
 DR infrastructure
configuration is not up-to-
date (Manual Configuration
required in case of Disaster).
 Recovery procedure
documented at high-level
(lack of run-book concept).
 Most of user’s access
planned –in event of
disaster- based on remote
access (no dedicated DR
facility).
 Both Replication and
Backup/restore capabilities
in-place.
 Warm or hot recovery site
capabilities with highly
available connectivity.
 Most of DR infrastructure
configuration up-to-date.
 Per-service Disaster recovery
run-book in-place.
 Both remote access and
onsite access planned (DR
Facility secured).
 Technology support
recovery strategy in-place.
 Technology implementation
cover both failover/failback
demands.
 Both Main & Remote site
connectivity toward the
recovery site planned/
secured.
 Level 3 (in addition to the
following).
 Run-book maintained &
updated by owners.
 DNS load-balancing
techniques (Global service
Load Balancing)
implemented for seamless
DR Failover.
 Automated DR
Failover/Failback capability
in-place (software or
network based).
 DR Implementation support
full, partial (multiple-
services), & service-level
Failover/Failback.
 Level 4 (in addition to the
following).
 Technology/capability to
align/sync configuration
from Main site to recovery
site in-place and support
real-time synchronization.
 DR recovery site can expand
to permanent.
 DR Run-book automated for
both failover/failback
 capability to provide real-
time (RTO/RPO) calculation
for IT services.
 capability to integrate/feed
company’s BCP/CM platform
(in case of any).
 Users Recovery facility used
for day to day operation by
set of actual users.
 Tap backup/restore
capability implemented as
last restoration option.
 Advanced user connectivity
techniques planned in case
of disaster (ex. VDI).
Indicator
Low (Alignment , Added Value)
IT alignment with business
High (Alignment , Added Value)
ITDR Exercise & Maintenance Maturity
LEVEL TO CAPABILITY MAPPING
Level to capability Mapping
ITDRExercise&Maintenance
Level1(Ineffective) Level 2 (Reactive) Level 3 (Effective) Level 4 (Proactive) Level 5 (Reliable)
 Basic restoration testing
conducted (usually done by
IT and application owner not
in the picture).
 Random testing cycle taken
place and cover only backup
restoration for critical
services.
 Lack of monitoring for
backup jobs/disaster
recovery link/infrastructure.
 Some DR infrastructure
components end-of-life/end-
of-support.
 Backup Restoration
conducted for critical
services and application
owner engaged.
 Support & maintenance
secured for DR
infrastructure.
 Backup job monitoring in-
place, but lack DR
infrastructure monitoring.
 Limited or Partial DR testing
exercise (usually due to
limitation DR infrastructure
capabilities or lack of
management approval).
 DR testing taken place out of
working hours.
 DR Application/OS patching
performed on best-efforts
bases.
 Backup restoration testing
conducted in frequent bases.
 Both Main & Recovery site
has same level of
monitoring.
 Both Main & Recovery site
has same level of
Application/OS Patching.
 DR testing include user-level
testing from DR facility.
 DR testing perfumed in form
of partial testing (cover
business critical
applications) and cover both
failover/failback.
 ITDR training program in-
place and individual aware
of their Roles &
Responsibilities.
 Test results and lessons
learned captured within post
exercise report.
 Conduct ITDR Training in
frequent bases.
 Level 3 (in addition to the
following).
 DR testing include run some
actual transactions from
recovery site.
 Test results and lessons
learned used to update the
ITDR Plan as well as services
RTO/RPO values.
 ITDR Plan, Policies &
Procedures reviewed in
frequent bases.
 Different ITDR testing
exercises performed (full,
Partial, table-top &
simulation).
 ITDR testing performed
during working hours.
 Level 4 (in addition to the
following).
 Unannounced ITDR testing
may take place during
business hours.
 ITDR testing/exercise has a
defined KPI.
 ITDR training is part of IT
employee induction
program.
 Established Capability to
communicate DR individuals
Roles & Responsibility in
event of disaster
declaration.
 Multiple DR communication
media capabilities.
 ITDR focal participate
effectively in overall
enterprise BCP and CMP
exercise.
 Regular audit performed for
ITDR program as well as
ITDR budget spending.
Indicator
Low (Success, Credible)
Program Effectiveness
High (Success, Credible)
ITDR Overall Maturity View
RISK & RECOVERY
Overall Maturity View
Level 1 Level 2 Level 3 Level 4 Level 5
ITDR
Strategy
Unaware Neutral Sponsor Involved Empower
ITDR
Implementation
Siloed best-efforts Consistent Improve Value Creator
ITDR Exercise &
Maintenance
Ineffective Reactive Effective Proactive Reliable
RISK
Catastrophic Significant Manageable Minor Limited (expected)
High (Unpredictable)
Risk to Business
Low (Predictable)
RECOVERY
No Recovery
Limited Recovery
(Depend on IT Team
Capabilities)
Mission-Critical
applications/services
Recovery but not all
RTO/RPO achieved
Mission-Critical
applications/services
Recovery with
RTO/RPO agreed
Full applications
/services Recovery
with RTO/RPO agreed
Low (high efforts)
Recovery Likelihood
High (low efforts)
Quantitative ITDR Maturity
Assessment
WEIGHTED MODEL
Maturity level Calculation
 To Provide Quantitative spin for the ITDR maturity readiness, ITDR measuring capabilities (refer
to slide 5) can be utilized for the same, where a weight assigned for each individual measuring
capability.
 these weights used to calculate individual ITDR component’s scoring, which in turn used to
calculate ITDR overall maturity scoring (as illustrated in next two slides).
Note: The assigned weight may differ depend on user point-of-view, however the overall weight distribution need to follow same logic (sum per ITDR component =100)
Maturity level Calculation (Cont.)
To add more granularity to the Maturity level calculation, another multiplier “completeness" drafted wherein
each ITDR capability evaluated/scored against the same Maturity levels used earlier (as shown below), then both
weight and completeness are used to calculate ITDR capability Score: Capability(n) Score = ((Capability(n)
Weight) X Completeness (%))
Then ITDR component scoring (ITDR Component Maturity) will be:
ITDR Component Score = Sum (Capability 1 score + Capability 2 score + … + Capability 7 score)
Maturity level Calculation (Cont.)
Once individual ITDR component scored, ITDR overall Maturing scoring will be:
ITDR Maturity = (Sum of “ITDR Strategy Capabilities Scoring” + Sum of “ITDR Implementation
capabilities Scoring” + Sum of “ITDR Exercise & Maintenance Capabilities Scoring” )/3
Finally, we can map the maturity scoring to our 5 Risk levels as shown below:
ITDR Maturity Presentation
MATURITY DASHBOARD
ITDR Executive Presentation
 There are a lot of methods to present the output(s) of any maturity model
depend on demands and audience, in coming slides I have added three models
for maturity profile representation:
 Milestone or state-based Model (can be used for Road-Map presentation).
 Maturity Dashboard (can be used to represent current state ITDR maturity).
 Per-component Model (can be used to provide a quick visual gab analysis per ITDR
component as well as areas of improvement).
 Other presentation method can be used as well to factor the risk level and
recovery likelihood, however In this presentation I am covering the previous
three only.
Milestone or state-based Model
2017
2018
2019
Green: available
Umber: Partially available
Red: Not available
Maturity Dashboard
Per-component Model
“
”
Finally I would highlight that this effort is a human product,
and like any other human products, it is a reflection of
his/her creator experience & knowledge, and will not reach
perfection. So if you find it useful feel free to use it,
otherwise send me your inputs (my contact below).
Bashar Al-Khatib
Bashar_khatis83@yahoo.com
https://www.linkedin.com/in/bashar-alkhatib-59861518/

More Related Content

What's hot

BUSINESS-CONTINUITY-AND-DISASTER-RECOVERY.pptx
BUSINESS-CONTINUITY-AND-DISASTER-RECOVERY.pptxBUSINESS-CONTINUITY-AND-DISASTER-RECOVERY.pptx
BUSINESS-CONTINUITY-AND-DISASTER-RECOVERY.pptx
JayLloyd8
 
Business Continuity & Disaster Recovery
Business Continuity & Disaster RecoveryBusiness Continuity & Disaster Recovery
Business Continuity & Disaster Recovery
EC-Council
 
Disaster Recovery Planning PowerPoint Presentation Slides
Disaster Recovery Planning PowerPoint Presentation SlidesDisaster Recovery Planning PowerPoint Presentation Slides
Disaster Recovery Planning PowerPoint Presentation Slides
SlideTeam
 
Bcp drp
Bcp drpBcp drp
Bcp drp
aqel aqel
 
Effective Business Continuity Plan Powerpoint Presentation Slides
Effective Business Continuity Plan Powerpoint Presentation SlidesEffective Business Continuity Plan Powerpoint Presentation Slides
Effective Business Continuity Plan Powerpoint Presentation Slides
SlideTeam
 
Disaster Recovery Plan
Disaster Recovery PlanDisaster Recovery Plan
Disaster Recovery PlanDavid Donovan
 
How to write an IT DR plan
How to write an IT DR planHow to write an IT DR plan
How to write an IT DR plan
Databarracks
 
Information Technology Disaster Planning
Information Technology Disaster PlanningInformation Technology Disaster Planning
Information Technology Disaster Planningguest340570
 
Disaster Recovery Plan
Disaster Recovery PlanDisaster Recovery Plan
Disaster Recovery Plan
Indeevari Ramanayake
 
Bcp
BcpBcp
Bcp
madunix
 
9 Bcp+Drp
9 Bcp+Drp9 Bcp+Drp
9 Bcp+Drp
Alfred Ouyang
 
IT Disaster Recovery & Business Continuity
IT Disaster Recovery & Business ContinuityIT Disaster Recovery & Business Continuity
IT Disaster Recovery & Business Continuity
mascot4u
 
What is business continuity planning-bcp
What is business continuity planning-bcpWhat is business continuity planning-bcp
What is business continuity planning-bcp
Adv Prashant Mali
 
Disaster Recovery Plan
Disaster Recovery PlanDisaster Recovery Plan
Disaster Recovery Plan
mhdpaknejad
 
What is dr and bc 12-2017
What is dr and bc 12-2017What is dr and bc 12-2017
What is dr and bc 12-2017
Atef Yassin
 
Data center disaster recovery.ppt
Data center disaster recovery.ppt Data center disaster recovery.ppt
Data center disaster recovery.ppt
omalreda
 
Business continuity planning
Business continuity planningBusiness continuity planning
Business continuity planningSandeep Kashyap
 
Disaster recovery plan sample 2
Disaster recovery plan sample 2Disaster recovery plan sample 2
Disaster recovery plan sample 2
AbenetAsmellash
 
Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)
Narudom Roongsiriwong, CISSP
 
Disaster Recovery Planning
Disaster Recovery PlanningDisaster Recovery Planning
Disaster Recovery Planning
Kathy Pelletier
 

What's hot (20)

BUSINESS-CONTINUITY-AND-DISASTER-RECOVERY.pptx
BUSINESS-CONTINUITY-AND-DISASTER-RECOVERY.pptxBUSINESS-CONTINUITY-AND-DISASTER-RECOVERY.pptx
BUSINESS-CONTINUITY-AND-DISASTER-RECOVERY.pptx
 
Business Continuity & Disaster Recovery
Business Continuity & Disaster RecoveryBusiness Continuity & Disaster Recovery
Business Continuity & Disaster Recovery
 
Disaster Recovery Planning PowerPoint Presentation Slides
Disaster Recovery Planning PowerPoint Presentation SlidesDisaster Recovery Planning PowerPoint Presentation Slides
Disaster Recovery Planning PowerPoint Presentation Slides
 
Bcp drp
Bcp drpBcp drp
Bcp drp
 
Effective Business Continuity Plan Powerpoint Presentation Slides
Effective Business Continuity Plan Powerpoint Presentation SlidesEffective Business Continuity Plan Powerpoint Presentation Slides
Effective Business Continuity Plan Powerpoint Presentation Slides
 
Disaster Recovery Plan
Disaster Recovery PlanDisaster Recovery Plan
Disaster Recovery Plan
 
How to write an IT DR plan
How to write an IT DR planHow to write an IT DR plan
How to write an IT DR plan
 
Information Technology Disaster Planning
Information Technology Disaster PlanningInformation Technology Disaster Planning
Information Technology Disaster Planning
 
Disaster Recovery Plan
Disaster Recovery PlanDisaster Recovery Plan
Disaster Recovery Plan
 
Bcp
BcpBcp
Bcp
 
9 Bcp+Drp
9 Bcp+Drp9 Bcp+Drp
9 Bcp+Drp
 
IT Disaster Recovery & Business Continuity
IT Disaster Recovery & Business ContinuityIT Disaster Recovery & Business Continuity
IT Disaster Recovery & Business Continuity
 
What is business continuity planning-bcp
What is business continuity planning-bcpWhat is business continuity planning-bcp
What is business continuity planning-bcp
 
Disaster Recovery Plan
Disaster Recovery PlanDisaster Recovery Plan
Disaster Recovery Plan
 
What is dr and bc 12-2017
What is dr and bc 12-2017What is dr and bc 12-2017
What is dr and bc 12-2017
 
Data center disaster recovery.ppt
Data center disaster recovery.ppt Data center disaster recovery.ppt
Data center disaster recovery.ppt
 
Business continuity planning
Business continuity planningBusiness continuity planning
Business continuity planning
 
Disaster recovery plan sample 2
Disaster recovery plan sample 2Disaster recovery plan sample 2
Disaster recovery plan sample 2
 
Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)
 
Disaster Recovery Planning
Disaster Recovery PlanningDisaster Recovery Planning
Disaster Recovery Planning
 

Similar to IT Disaster Recovery Readiness (Maturity Assessement)

COMPANY Disaster Recovery Plan (DRP) for [PRODU.docx
COMPANY    Disaster Recovery Plan (DRP) for [PRODU.docxCOMPANY    Disaster Recovery Plan (DRP) for [PRODU.docx
COMPANY Disaster Recovery Plan (DRP) for [PRODU.docx
monicafrancis71118
 
BUSINESS CONTINUITY MANAGEMENT
BUSINESS CONTINUITY MANAGEMENTBUSINESS CONTINUITY MANAGEMENT
BUSINESS CONTINUITY MANAGEMENT
Skillmine Technology Consulting
 
Disaster Biz Resumpt
Disaster Biz ResumptDisaster Biz Resumpt
Disaster Biz ResumptJimGroark
 
Templateplanodedisponibilidadedosservios 120602150709-phpapp02
Templateplanodedisponibilidadedosservios 120602150709-phpapp02Templateplanodedisponibilidadedosservios 120602150709-phpapp02
Templateplanodedisponibilidadedosservios 120602150709-phpapp02Ismael Rodrigues
 
Business Continuity for Mission Critical Applications
Business Continuity for Mission Critical ApplicationsBusiness Continuity for Mission Critical Applications
Business Continuity for Mission Critical Applications
DataCore Software
 
Document the drp now
Document the drp nowDocument the drp now
Document the drp now
Info-Tech Research Group
 
FacilitySystem Continuity PlanContinuity Plan Template.docx
FacilitySystem Continuity PlanContinuity Plan Template.docxFacilitySystem Continuity PlanContinuity Plan Template.docx
FacilitySystem Continuity PlanContinuity Plan Template.docx
ssuser454af01
 
Kept up by Potential IT Disasters? Your Guide to Disaster Recovery as a Servi...
Kept up by Potential IT Disasters? Your Guide to Disaster Recovery as a Servi...Kept up by Potential IT Disasters? Your Guide to Disaster Recovery as a Servi...
Kept up by Potential IT Disasters? Your Guide to Disaster Recovery as a Servi...
VAST
 
Building a Business Continuity Capability
Building a Business Continuity CapabilityBuilding a Business Continuity Capability
Building a Business Continuity Capability
Rod Davis
 
Business Continuity Awareness Week 2009
Business Continuity Awareness Week 2009Business Continuity Awareness Week 2009
Business Continuity Awareness Week 2009
Brigitte Theuma
 
rto vs rpo
rto vs rporto vs rpo
rto vs rpo
ssuser1eca7d
 
Disaster Recovery: Develop Efficient Critique for an Emergency
Disaster Recovery: Develop Efficient Critique for an EmergencyDisaster Recovery: Develop Efficient Critique for an Emergency
Disaster Recovery: Develop Efficient Critique for an Emergency
sco813f8ko
 
This sample template is designed to assist the user in performing .docx
This sample template is designed to assist the user in performing .docxThis sample template is designed to assist the user in performing .docx
This sample template is designed to assist the user in performing .docx
juliennehar
 
This sample template is designed to assist the user in performing .docx
This sample template is designed to assist the user in performing .docxThis sample template is designed to assist the user in performing .docx
This sample template is designed to assist the user in performing .docx
herthalearmont
 
Sfeldman performance bb_worldemea07
Sfeldman performance bb_worldemea07Sfeldman performance bb_worldemea07
Sfeldman performance bb_worldemea07Steve Feldman
 
Network Strategy and Design Final assignment disaster rec
Network Strategy and Design Final assignment disaster recNetwork Strategy and Design Final assignment disaster rec
Network Strategy and Design Final assignment disaster rec
rosu555
 
DRP.ppt
DRP.pptDRP.ppt
Create a Right Sized Disaster Recovery Plan
Create a Right Sized Disaster Recovery PlanCreate a Right Sized Disaster Recovery Plan
Create a Right Sized Disaster Recovery Plan
Info-Tech Research Group
 
This sample template is designed to assist the user in performing .docx
This sample template is designed to assist the user in performing .docxThis sample template is designed to assist the user in performing .docx
This sample template is designed to assist the user in performing .docx
rhetttrevannion
 

Similar to IT Disaster Recovery Readiness (Maturity Assessement) (20)

COMPANY Disaster Recovery Plan (DRP) for [PRODU.docx
COMPANY    Disaster Recovery Plan (DRP) for [PRODU.docxCOMPANY    Disaster Recovery Plan (DRP) for [PRODU.docx
COMPANY Disaster Recovery Plan (DRP) for [PRODU.docx
 
BUSINESS CONTINUITY MANAGEMENT
BUSINESS CONTINUITY MANAGEMENTBUSINESS CONTINUITY MANAGEMENT
BUSINESS CONTINUITY MANAGEMENT
 
Disaster Biz Resumpt
Disaster Biz ResumptDisaster Biz Resumpt
Disaster Biz Resumpt
 
Templateplanodedisponibilidadedosservios 120602150709-phpapp02
Templateplanodedisponibilidadedosservios 120602150709-phpapp02Templateplanodedisponibilidadedosservios 120602150709-phpapp02
Templateplanodedisponibilidadedosservios 120602150709-phpapp02
 
Business Continuity for Mission Critical Applications
Business Continuity for Mission Critical ApplicationsBusiness Continuity for Mission Critical Applications
Business Continuity for Mission Critical Applications
 
Document the drp now
Document the drp nowDocument the drp now
Document the drp now
 
FacilitySystem Continuity PlanContinuity Plan Template.docx
FacilitySystem Continuity PlanContinuity Plan Template.docxFacilitySystem Continuity PlanContinuity Plan Template.docx
FacilitySystem Continuity PlanContinuity Plan Template.docx
 
Kept up by Potential IT Disasters? Your Guide to Disaster Recovery as a Servi...
Kept up by Potential IT Disasters? Your Guide to Disaster Recovery as a Servi...Kept up by Potential IT Disasters? Your Guide to Disaster Recovery as a Servi...
Kept up by Potential IT Disasters? Your Guide to Disaster Recovery as a Servi...
 
Building a Business Continuity Capability
Building a Business Continuity CapabilityBuilding a Business Continuity Capability
Building a Business Continuity Capability
 
BAKKIYA_4YR
BAKKIYA_4YRBAKKIYA_4YR
BAKKIYA_4YR
 
Business Continuity Awareness Week 2009
Business Continuity Awareness Week 2009Business Continuity Awareness Week 2009
Business Continuity Awareness Week 2009
 
rto vs rpo
rto vs rporto vs rpo
rto vs rpo
 
Disaster Recovery: Develop Efficient Critique for an Emergency
Disaster Recovery: Develop Efficient Critique for an EmergencyDisaster Recovery: Develop Efficient Critique for an Emergency
Disaster Recovery: Develop Efficient Critique for an Emergency
 
This sample template is designed to assist the user in performing .docx
This sample template is designed to assist the user in performing .docxThis sample template is designed to assist the user in performing .docx
This sample template is designed to assist the user in performing .docx
 
This sample template is designed to assist the user in performing .docx
This sample template is designed to assist the user in performing .docxThis sample template is designed to assist the user in performing .docx
This sample template is designed to assist the user in performing .docx
 
Sfeldman performance bb_worldemea07
Sfeldman performance bb_worldemea07Sfeldman performance bb_worldemea07
Sfeldman performance bb_worldemea07
 
Network Strategy and Design Final assignment disaster rec
Network Strategy and Design Final assignment disaster recNetwork Strategy and Design Final assignment disaster rec
Network Strategy and Design Final assignment disaster rec
 
DRP.ppt
DRP.pptDRP.ppt
DRP.ppt
 
Create a Right Sized Disaster Recovery Plan
Create a Right Sized Disaster Recovery PlanCreate a Right Sized Disaster Recovery Plan
Create a Right Sized Disaster Recovery Plan
 
This sample template is designed to assist the user in performing .docx
This sample template is designed to assist the user in performing .docxThis sample template is designed to assist the user in performing .docx
This sample template is designed to assist the user in performing .docx
 

Recently uploaded

Colors of Wall Paint and Their Mentally Properties.pptx
Colors of Wall Paint and Their Mentally Properties.pptxColors of Wall Paint and Their Mentally Properties.pptx
Colors of Wall Paint and Their Mentally Properties.pptx
Brendon Jonathan
 
The Best Premium IPTV Service Frane.docx
The Best Premium IPTV Service Frane.docxThe Best Premium IPTV Service Frane.docx
The Best Premium IPTV Service Frane.docx
Industry Foods UK
 
What Are the Latest Trends in Endpoint Security for 2024?
What Are the Latest Trends in Endpoint Security for 2024?What Are the Latest Trends in Endpoint Security for 2024?
What Are the Latest Trends in Endpoint Security for 2024?
VRS Technologies
 
Get your dream bridal look with top North Indian makeup artist - Pallavi Kadale
Get your dream bridal look with top North Indian makeup artist - Pallavi KadaleGet your dream bridal look with top North Indian makeup artist - Pallavi Kadale
Get your dream bridal look with top North Indian makeup artist - Pallavi Kadale
Pallavi Makeup Artist
 
Top Email Marketing Trends to Watch in 2024
Top Email Marketing Trends to Watch in 2024Top Email Marketing Trends to Watch in 2024
Top Email Marketing Trends to Watch in 2024
time4servers technologies
 
Waikiki Sunset Catamaran ! MAITAI Catamaran
Waikiki Sunset Catamaran !  MAITAI CatamaranWaikiki Sunset Catamaran !  MAITAI Catamaran
Waikiki Sunset Catamaran ! MAITAI Catamaran
maitaicatamaran
 
How Does Littering Affect the Environment.
How Does Littering Affect the Environment.How Does Littering Affect the Environment.
How Does Littering Affect the Environment.
ClenliDirect
 
BEst VASHIKARAN SPECIALIST 9463629203 in UK Baba ji Love Marriage problem sol...
BEst VASHIKARAN SPECIALIST 9463629203 in UK Baba ji Love Marriage problem sol...BEst VASHIKARAN SPECIALIST 9463629203 in UK Baba ji Love Marriage problem sol...
BEst VASHIKARAN SPECIALIST 9463629203 in UK Baba ji Love Marriage problem sol...
gitapress3
 
Top Best Astrologer +91-9463629203 LoVe Problem SolUtion specialist In InDia ...
Top Best Astrologer +91-9463629203 LoVe Problem SolUtion specialist In InDia ...Top Best Astrologer +91-9463629203 LoVe Problem SolUtion specialist In InDia ...
Top Best Astrologer +91-9463629203 LoVe Problem SolUtion specialist In InDia ...
gitapress3
 
Maximizing Efficiency with Integrated Water Management Systems
Maximizing Efficiency with Integrated Water Management SystemsMaximizing Efficiency with Integrated Water Management Systems
Maximizing Efficiency with Integrated Water Management Systems
Irri Design Studio
 
BesT panDit Ji LoVe problem solution 9463629203 UK uSA California New Zealand...
BesT panDit Ji LoVe problem solution 9463629203 UK uSA California New Zealand...BesT panDit Ji LoVe problem solution 9463629203 UK uSA California New Zealand...
BesT panDit Ji LoVe problem solution 9463629203 UK uSA California New Zealand...
gitapress3
 
Best Catering Event Planner Miso-Hungry.pptx
Best Catering Event Planner  Miso-Hungry.pptxBest Catering Event Planner  Miso-Hungry.pptx
Best Catering Event Planner Miso-Hungry.pptx
Miso Hungry
 
Unlocking Insights: AI-powered Enhanced Due Diligence Strategies for Increase...
Unlocking Insights: AI-powered Enhanced Due Diligence Strategies for Increase...Unlocking Insights: AI-powered Enhanced Due Diligence Strategies for Increase...
Unlocking Insights: AI-powered Enhanced Due Diligence Strategies for Increase...
RNayak3
 
SECUREX UK FOR SECURITY SERVICES AND MOBILE PATROL
SECUREX UK FOR SECURITY SERVICES AND MOBILE PATROLSECUREX UK FOR SECURITY SERVICES AND MOBILE PATROL
SECUREX UK FOR SECURITY SERVICES AND MOBILE PATROL
securexukweb
 
The Jamstack Revolution: Building Dynamic Websites with Static Site Generator...
The Jamstack Revolution: Building Dynamic Websites with Static Site Generator...The Jamstack Revolution: Building Dynamic Websites with Static Site Generator...
The Jamstack Revolution: Building Dynamic Websites with Static Site Generator...
Softradix Technologies
 
WORK PERMIT IN BULGARIA | Work Visa Services
WORK PERMIT IN BULGARIA | Work Visa ServicesWORK PERMIT IN BULGARIA | Work Visa Services
WORK PERMIT IN BULGARIA | Work Visa Services
RKIMT
 
Comprehensive Water Damage Restoration Services
Comprehensive Water Damage Restoration ServicesComprehensive Water Damage Restoration Services
Comprehensive Water Damage Restoration Services
kleenupdisaster
 
SIMBA SQUAD : Best seo company in perth
SIMBA SQUAD :  Best seo company in perthSIMBA SQUAD :  Best seo company in perth
SIMBA SQUAD : Best seo company in perth
ridebiler
 
Best steel industrial company LLC in UAE
Best steel industrial company LLC in UAEBest steel industrial company LLC in UAE
Best steel industrial company LLC in UAE
alafnanmetals
 
Importance of BWTS in the Maritime Industry
Importance of BWTS in the Maritime IndustryImportance of BWTS in the Maritime Industry
Importance of BWTS in the Maritime Industry
Blessed Marine Automation
 

Recently uploaded (20)

Colors of Wall Paint and Their Mentally Properties.pptx
Colors of Wall Paint and Their Mentally Properties.pptxColors of Wall Paint and Their Mentally Properties.pptx
Colors of Wall Paint and Their Mentally Properties.pptx
 
The Best Premium IPTV Service Frane.docx
The Best Premium IPTV Service Frane.docxThe Best Premium IPTV Service Frane.docx
The Best Premium IPTV Service Frane.docx
 
What Are the Latest Trends in Endpoint Security for 2024?
What Are the Latest Trends in Endpoint Security for 2024?What Are the Latest Trends in Endpoint Security for 2024?
What Are the Latest Trends in Endpoint Security for 2024?
 
Get your dream bridal look with top North Indian makeup artist - Pallavi Kadale
Get your dream bridal look with top North Indian makeup artist - Pallavi KadaleGet your dream bridal look with top North Indian makeup artist - Pallavi Kadale
Get your dream bridal look with top North Indian makeup artist - Pallavi Kadale
 
Top Email Marketing Trends to Watch in 2024
Top Email Marketing Trends to Watch in 2024Top Email Marketing Trends to Watch in 2024
Top Email Marketing Trends to Watch in 2024
 
Waikiki Sunset Catamaran ! MAITAI Catamaran
Waikiki Sunset Catamaran !  MAITAI CatamaranWaikiki Sunset Catamaran !  MAITAI Catamaran
Waikiki Sunset Catamaran ! MAITAI Catamaran
 
How Does Littering Affect the Environment.
How Does Littering Affect the Environment.How Does Littering Affect the Environment.
How Does Littering Affect the Environment.
 
BEst VASHIKARAN SPECIALIST 9463629203 in UK Baba ji Love Marriage problem sol...
BEst VASHIKARAN SPECIALIST 9463629203 in UK Baba ji Love Marriage problem sol...BEst VASHIKARAN SPECIALIST 9463629203 in UK Baba ji Love Marriage problem sol...
BEst VASHIKARAN SPECIALIST 9463629203 in UK Baba ji Love Marriage problem sol...
 
Top Best Astrologer +91-9463629203 LoVe Problem SolUtion specialist In InDia ...
Top Best Astrologer +91-9463629203 LoVe Problem SolUtion specialist In InDia ...Top Best Astrologer +91-9463629203 LoVe Problem SolUtion specialist In InDia ...
Top Best Astrologer +91-9463629203 LoVe Problem SolUtion specialist In InDia ...
 
Maximizing Efficiency with Integrated Water Management Systems
Maximizing Efficiency with Integrated Water Management SystemsMaximizing Efficiency with Integrated Water Management Systems
Maximizing Efficiency with Integrated Water Management Systems
 
BesT panDit Ji LoVe problem solution 9463629203 UK uSA California New Zealand...
BesT panDit Ji LoVe problem solution 9463629203 UK uSA California New Zealand...BesT panDit Ji LoVe problem solution 9463629203 UK uSA California New Zealand...
BesT panDit Ji LoVe problem solution 9463629203 UK uSA California New Zealand...
 
Best Catering Event Planner Miso-Hungry.pptx
Best Catering Event Planner  Miso-Hungry.pptxBest Catering Event Planner  Miso-Hungry.pptx
Best Catering Event Planner Miso-Hungry.pptx
 
Unlocking Insights: AI-powered Enhanced Due Diligence Strategies for Increase...
Unlocking Insights: AI-powered Enhanced Due Diligence Strategies for Increase...Unlocking Insights: AI-powered Enhanced Due Diligence Strategies for Increase...
Unlocking Insights: AI-powered Enhanced Due Diligence Strategies for Increase...
 
SECUREX UK FOR SECURITY SERVICES AND MOBILE PATROL
SECUREX UK FOR SECURITY SERVICES AND MOBILE PATROLSECUREX UK FOR SECURITY SERVICES AND MOBILE PATROL
SECUREX UK FOR SECURITY SERVICES AND MOBILE PATROL
 
The Jamstack Revolution: Building Dynamic Websites with Static Site Generator...
The Jamstack Revolution: Building Dynamic Websites with Static Site Generator...The Jamstack Revolution: Building Dynamic Websites with Static Site Generator...
The Jamstack Revolution: Building Dynamic Websites with Static Site Generator...
 
WORK PERMIT IN BULGARIA | Work Visa Services
WORK PERMIT IN BULGARIA | Work Visa ServicesWORK PERMIT IN BULGARIA | Work Visa Services
WORK PERMIT IN BULGARIA | Work Visa Services
 
Comprehensive Water Damage Restoration Services
Comprehensive Water Damage Restoration ServicesComprehensive Water Damage Restoration Services
Comprehensive Water Damage Restoration Services
 
SIMBA SQUAD : Best seo company in perth
SIMBA SQUAD :  Best seo company in perthSIMBA SQUAD :  Best seo company in perth
SIMBA SQUAD : Best seo company in perth
 
Best steel industrial company LLC in UAE
Best steel industrial company LLC in UAEBest steel industrial company LLC in UAE
Best steel industrial company LLC in UAE
 
Importance of BWTS in the Maritime Industry
Importance of BWTS in the Maritime IndustryImportance of BWTS in the Maritime Industry
Importance of BWTS in the Maritime Industry
 

IT Disaster Recovery Readiness (Maturity Assessement)

  • 1. IT Disaster Recovery Readiness MATURITY MODEL TO ASSESS YOUR IT DR PROGRAM
  • 2. Maturity Model Purpose  The purpose of this model is to help the reader in evaluating the current status of his/her Disaster Recovery program.  Beside that, below sample use-cases for this maturity model:  Evaluate the current Risk level on business continuity in event of disaster.  Anticipate a road-map or desire state for IT Disaster Recovery planning.  business case input for Disaster Recovery initiative.  Driver for Integration plan for multiple enterprise wide capabilities into Disaster recovery planning.  Use as scale to evaluate multiple capabilities or line of businesses against each other in term of disaster recovery readiness.
  • 3. Maturity levels Definition Level Definition Description 1 Initial or Ad hoc minimal or ineffective recovery capabilities in-place. 2 Established or Reactive disaster recovery strategy in-place but lack proper capabilities and handled on best-efforts bases. 3 Prepared or business enabled disaster recovery strategy in-place and align with business demands. 4 Managed or Proactive disaster recovery managed as program where dedicated team manage/maintain/validate various components of disaster recovery program. 5 Optimized or resilient disaster recovery program complement & seamlessly integrate with various enterprise wide practices (IT/none-IT) and address growth requirement. This Model has five levels of readiness or maturity for Disaster Recovery “DR” capabilities, where level 0 “Non-existent” removed due to easiness of determining the same “lack of recovery strategy or capabilities”.
  • 4. Maturity Model Structure  I have structured this model into three (3) main ITDR components (21 ITDR capabilities), each of them measure different aspects of DR capabilities:  ITDR Strategy (measure stakeholder engagement “reflected as Interest & Power” in ITDR)  ITDR Implementation (measure IT alignment with business demands)  ITDR Exercise & Maintenance (measure the effectiveness “reflected on Success rate & Credibility/Confidence level” of ITDR program)  The outcome of overall review of these three ITDR components, will be Maturity/Readiness level for Enterprise’s recovery capabilities in term of:  Recovery likelihood  Risk to business
  • 5. Measuring Capabilities  For each ITDR component, set of measuring capabilities identified to help differentiating different maturity level: ITDR Strategy ITDR Implementation ITDR Exercise & Maintenance ITDR Plan Recovery site setup & connectivity Support/SLA for ITDR infrastructure ITDR Processes & Procedures (BIA/RA) Data Backup/Restore & Replication Backup/Restore testing & validation ITDR Team , Roles, & Responsibilities Configuration synchronization Infrastructure Monitoring Backup/Recovery practice DR Facility & User connectivity ITDR Training ITDR Budget & fund ITDR Run-book or Play-book ITDR Infrastructure/Application/OS Patching Practice ITDR integration with Enterprise wide practices ITDR Infrastructure ITDR testing exercise ITDR Road-map ITDR Failover/Failback Implementation ITDR Audit , Report & document review.
  • 6. ITDR Strategy Maturity LEVEL TO CAPABILITY MAPPING
  • 7. Level to capability Mapping ITDRStrategy Level1 (Unaware) Level 2 (Neutral) Level 3 (Sponsor) Level 4 (Involved) Level 5 (Empower)  Basic Backup/Recovery Procedure documented.  Lack of ITDR plan, processes or procedures documented.  Lack of BIA/RA Performed to identify IT Critical services & its RTO/RPO demands .  Lack of ITDR Team structure (best-efforts bases).  Lack of dedicated Budget.  Basic definition of critical services documented (IT point of view).  Backup/Recovery Procedure documented.  One General Definition for recovery strategy for all IT services.  High-level or Basic ITDR Plan documented (usually as part of IT procedures).  Budget funded from other IT initiatives.  Partial recovery team structure, but roles responsibilities not clearly defined (lack of ownership).  Chaotic DR communication , declaration & escalation structure ( lack of governance structure)  Business RTO/RPO defined (through Business Impact Analysis “BIA”).  Backup/Recovery Procedure documented & align with defined RTO/RPO.  ITDR Plan documented but not reviewed or it is reviewed but on best efforts bases.  ITDR BIA/RA processes & procedures documented.  Criticality-based recovery strategy (ex. Replication for critical services and restore from backup for others).  ITDR recovery strategy cover both Failover/Failback.  Lack of dedicated ITDR lead identified but the “acting- as” defined.  Recovery team member identified.  ITDR communication, declaration & escalation structure documented.  Level 3 (in addition to the following).  ITDR Plan Reviewed in Frequent bases.  KPI Defined for various IT DR Plan components.  ITDR Road-Map defined.  ITDR Budget allocated.  Recovery Strategy Defined Per-service.  ITDR Roles and Responsibilities Defined.  ITDR process automation (BIA/RA) in-place.  ITDR Plan cover full, partial (multiple-services), & service-level Failover/Failback.  ITDR planned as part of IT budget & infrastructure capacity planning.  Level 4 (in addition to the following).  ITDR integrated with change management process.  ITDR Road-map integrated with business plan/IT strategy.  ITDR Processes and procedures integrated in enterprise architect as well  ITDR requirements collected as part of business requirements gathering for any new IT initiative.  ITDR Integrated with both business continuity plan (BCP) and Crisis Management Plan (CMP) for the enterprise.  IT DR Roles & Responsibilities integrated as part of job description.  (in case of insurance) IT DR integrated with Enterprise insurance plan.  ITDR communication plan align with enterprise communication guidelines. Indicator Low (Power , Interest) Stakeholder Engagement High (Power, Interest )
  • 8. ITDR Implementation Maturity LEVEL TO CAPABILITY MAPPING
  • 9. Level to capability Mapping ITDRImplementation Level1 (Siloed) Level 2 (best- efforts) Level 3 Level 4 (Improve) Level 5 (Value Creator)  Basic backup/restore capability.  Cold recovery site capabilities.  Lack of resiliency for DR site connectivity.  Shared and/or Low Bandwidth DR link.  Legacy or limited DR infrastructure components implement.  Lack of user’s connectivity planned.  Advanced backup/restore capability (restoration testing capability in-place).  Basic data replication capability in-place.  Warm recovery site capabilities.  Active/standby connectivity for DR site.  DR infrastructure configuration is not up-to- date (Manual Configuration required in case of Disaster).  Recovery procedure documented at high-level (lack of run-book concept).  Most of user’s access planned –in event of disaster- based on remote access (no dedicated DR facility).  Both Replication and Backup/restore capabilities in-place.  Warm or hot recovery site capabilities with highly available connectivity.  Most of DR infrastructure configuration up-to-date.  Per-service Disaster recovery run-book in-place.  Both remote access and onsite access planned (DR Facility secured).  Technology support recovery strategy in-place.  Technology implementation cover both failover/failback demands.  Both Main & Remote site connectivity toward the recovery site planned/ secured.  Level 3 (in addition to the following).  Run-book maintained & updated by owners.  DNS load-balancing techniques (Global service Load Balancing) implemented for seamless DR Failover.  Automated DR Failover/Failback capability in-place (software or network based).  DR Implementation support full, partial (multiple- services), & service-level Failover/Failback.  Level 4 (in addition to the following).  Technology/capability to align/sync configuration from Main site to recovery site in-place and support real-time synchronization.  DR recovery site can expand to permanent.  DR Run-book automated for both failover/failback  capability to provide real- time (RTO/RPO) calculation for IT services.  capability to integrate/feed company’s BCP/CM platform (in case of any).  Users Recovery facility used for day to day operation by set of actual users.  Tap backup/restore capability implemented as last restoration option.  Advanced user connectivity techniques planned in case of disaster (ex. VDI). Indicator Low (Alignment , Added Value) IT alignment with business High (Alignment , Added Value)
  • 10. ITDR Exercise & Maintenance Maturity LEVEL TO CAPABILITY MAPPING
  • 11. Level to capability Mapping ITDRExercise&Maintenance Level1(Ineffective) Level 2 (Reactive) Level 3 (Effective) Level 4 (Proactive) Level 5 (Reliable)  Basic restoration testing conducted (usually done by IT and application owner not in the picture).  Random testing cycle taken place and cover only backup restoration for critical services.  Lack of monitoring for backup jobs/disaster recovery link/infrastructure.  Some DR infrastructure components end-of-life/end- of-support.  Backup Restoration conducted for critical services and application owner engaged.  Support & maintenance secured for DR infrastructure.  Backup job monitoring in- place, but lack DR infrastructure monitoring.  Limited or Partial DR testing exercise (usually due to limitation DR infrastructure capabilities or lack of management approval).  DR testing taken place out of working hours.  DR Application/OS patching performed on best-efforts bases.  Backup restoration testing conducted in frequent bases.  Both Main & Recovery site has same level of monitoring.  Both Main & Recovery site has same level of Application/OS Patching.  DR testing include user-level testing from DR facility.  DR testing perfumed in form of partial testing (cover business critical applications) and cover both failover/failback.  ITDR training program in- place and individual aware of their Roles & Responsibilities.  Test results and lessons learned captured within post exercise report.  Conduct ITDR Training in frequent bases.  Level 3 (in addition to the following).  DR testing include run some actual transactions from recovery site.  Test results and lessons learned used to update the ITDR Plan as well as services RTO/RPO values.  ITDR Plan, Policies & Procedures reviewed in frequent bases.  Different ITDR testing exercises performed (full, Partial, table-top & simulation).  ITDR testing performed during working hours.  Level 4 (in addition to the following).  Unannounced ITDR testing may take place during business hours.  ITDR testing/exercise has a defined KPI.  ITDR training is part of IT employee induction program.  Established Capability to communicate DR individuals Roles & Responsibility in event of disaster declaration.  Multiple DR communication media capabilities.  ITDR focal participate effectively in overall enterprise BCP and CMP exercise.  Regular audit performed for ITDR program as well as ITDR budget spending. Indicator Low (Success, Credible) Program Effectiveness High (Success, Credible)
  • 12. ITDR Overall Maturity View RISK & RECOVERY
  • 13. Overall Maturity View Level 1 Level 2 Level 3 Level 4 Level 5 ITDR Strategy Unaware Neutral Sponsor Involved Empower ITDR Implementation Siloed best-efforts Consistent Improve Value Creator ITDR Exercise & Maintenance Ineffective Reactive Effective Proactive Reliable RISK Catastrophic Significant Manageable Minor Limited (expected) High (Unpredictable) Risk to Business Low (Predictable) RECOVERY No Recovery Limited Recovery (Depend on IT Team Capabilities) Mission-Critical applications/services Recovery but not all RTO/RPO achieved Mission-Critical applications/services Recovery with RTO/RPO agreed Full applications /services Recovery with RTO/RPO agreed Low (high efforts) Recovery Likelihood High (low efforts)
  • 15. Maturity level Calculation  To Provide Quantitative spin for the ITDR maturity readiness, ITDR measuring capabilities (refer to slide 5) can be utilized for the same, where a weight assigned for each individual measuring capability.  these weights used to calculate individual ITDR component’s scoring, which in turn used to calculate ITDR overall maturity scoring (as illustrated in next two slides). Note: The assigned weight may differ depend on user point-of-view, however the overall weight distribution need to follow same logic (sum per ITDR component =100)
  • 16. Maturity level Calculation (Cont.) To add more granularity to the Maturity level calculation, another multiplier “completeness" drafted wherein each ITDR capability evaluated/scored against the same Maturity levels used earlier (as shown below), then both weight and completeness are used to calculate ITDR capability Score: Capability(n) Score = ((Capability(n) Weight) X Completeness (%)) Then ITDR component scoring (ITDR Component Maturity) will be: ITDR Component Score = Sum (Capability 1 score + Capability 2 score + … + Capability 7 score)
  • 17. Maturity level Calculation (Cont.) Once individual ITDR component scored, ITDR overall Maturing scoring will be: ITDR Maturity = (Sum of “ITDR Strategy Capabilities Scoring” + Sum of “ITDR Implementation capabilities Scoring” + Sum of “ITDR Exercise & Maintenance Capabilities Scoring” )/3 Finally, we can map the maturity scoring to our 5 Risk levels as shown below:
  • 19. ITDR Executive Presentation  There are a lot of methods to present the output(s) of any maturity model depend on demands and audience, in coming slides I have added three models for maturity profile representation:  Milestone or state-based Model (can be used for Road-Map presentation).  Maturity Dashboard (can be used to represent current state ITDR maturity).  Per-component Model (can be used to provide a quick visual gab analysis per ITDR component as well as areas of improvement).  Other presentation method can be used as well to factor the risk level and recovery likelihood, however In this presentation I am covering the previous three only.
  • 20. Milestone or state-based Model 2017 2018 2019 Green: available Umber: Partially available Red: Not available
  • 23. “ ” Finally I would highlight that this effort is a human product, and like any other human products, it is a reflection of his/her creator experience & knowledge, and will not reach perfection. So if you find it useful feel free to use it, otherwise send me your inputs (my contact below). Bashar Al-Khatib Bashar_khatis83@yahoo.com https://www.linkedin.com/in/bashar-alkhatib-59861518/