Business Risk Analysis
The starting point must always be based on the perceived risk to the business by it's managers. An interview with the CEO quickly reveals how much risk the business is exposed to and how much 'down-time' Management is able to withstand.
Of course it is our job to identify if the Information Technology poses sufficient threat to the continuity of the business.
IT Infrastructure Audit
Once Business Risk Analysis is completed, an IT Infrastructure Audit is required to be able to identify the current status of the Network and available IT Services.
IT Security Audit
Shortly after the Infrastructure Audit (usually During this audit) an IT Security Audit is conducted. This Audit is important to identify possible breaches of security, and infiltration points.
We often think of Spy-type problems, but if an employee took one of your server tapes, would they know the password to copy the entire customer database?
IT Hardware Assessment
To be able to provide a reasonably redundancy during inevitable Hardware Failure, an Initial Hardware Assessment must be done. The hardware assessment will provide insight into the systems ability to withstand Hardware Failures but it will also identify if systems are underutilized or mis-configured. Often we come across tape backup systems which are religiously swapped each night, only to find that the backup software isn't backing up the data directory.
Critical Systems Identification
What does the business need to operate? What can be replaced in case of failure or disaster, and what is critical?
This phase is a continuation of the first phase, Business Risk Analysis, but this time WITH the Audits and Assessments 'in hand' providing Real-Life and Meaningful answers to Business questions.
These Meaningful answers must be incorporated into the next phase:
Compliance Phase
The Compliance Phase is where we take the current situation and bring it to a level whereby we can confidently and positively answer the question: Can we recover sufficiently from potential Down-time occurrences?
And we update the Business Risk Analysis and Critical Systems with a new Outlook of Confidence.
Procedure Phase
Hardware and Software Compliance is not enough. Simple procedural changes are often required to maintain a serviceable IT Model and a Secure Envelope around the Business.
Locking the door to the server room, taking a tape off-site, encrypting the backups, logging-OFF from servers when not in use, etc. are all simple procedural recommendations which will provide peace of mind.
Monitoring
Service, Software and Compliance Monitoring provides a level of certainty which should be considered.
Additional measures such as Unified Threat Management should also be considered to Monitor, Report and Block Internet Use, which is detrimental to the continuing operation of the Business.
We can install and maintain server based monitoring to monitor backup status, hard drive use, etc.
Maintenance
When systems are maintained, they are less likely to fail. Not just Hardware failure.
A Server should be monitored and it's tapes and fans cleaned on time.
A virus licence which expires, is not effective against new threats, and leaves the network open to abuse.
We provide regular scans and checkups to ensure that your systems are running optimal and identify possible problems for the future, allowing you to focus on your business.
Regular Auditing
Based on the Business Risk and the Compliance Phase, we will perform regular audits to be able to warn you of possible failures, business risks and/or upgrade requirements. For Smaller Businesses, we can often simply keep track of your network and appliances during our regular visits and provide you with the information you need to make decisions along the way. |