CONTINUITY PLANNING IN THE NEW MILLENIUM
The Convergence of Disciplines

By Robert P. Campbell


THE ACCELERATING CONVERGENCE OF DISCIPLINES
In the last decade, emergency preparedness, crisis management, incident response and other related disciplines heavily influenced the evolution of continuity planning. We saw the tenets of disaster recovery and business resumption broadened to embrace important concepts from each of those disciplines.

In the new Millennium, look for more significant changes in the way we do business. One area that is underway, is the accelerating convergence of the information security and continuity planning disciplines. Quite simply, as disruption tolerances shrink to hours, minutes and nano-seconds, the business continuity planner must move into areas of computer viruses, unauthorized access, denial-of-service attacks, and other hostile actions where potential abuse and misuse can seriously disrupt critical operations.

THE RISING WORLD OF E-CONTINUITY
Increasingly distributed technology, highly integrated applications and systems, and greater dependence upon complex electronic relationships are all factors that can threaten the security and survivability of mission critical applications and continuity of vital business activities. Add to this the growth of e-business through the Internet, extranets and virtual private networks. The threat of devastating compromise of sensitive information or catastrophic disruption of critical systems looms heavily. Unless careful attention is paid to the dynamics of security, survivability, fault tolerance, fail-over and privacy needs of vital network-based technology, the potential exposures can be life threatening to the enterprise.

URGENT NEEDS FUELING CHANGE
The most influential forces fueling this convergence are the federal government’s urgent concerns over cyber-terrorism, information warfare and its National Plan for Infrastructure Protection, which will pour an average of $2 billion per year over the next two years to jump-start vitally needed protections. Its key elements are a mix of information security/mission continuity requirements, presented in the Plan without concern for boundaries between the disciplines.

Additional forces and influences are summarized below:

Continuity Planning – More than ever, the burgeoning web of electronic interdependencies is creating the potential for minor failure to cascade throughout the enterprise and beyond – a virtual meltdown. This exposure to potentially catastrophic disruption of critical business activities must be dealt with aggressively and thoroughly. New technologies for survivability and fail-over, combined with careful disaster prevention and business continuity planning, are needed to eliminate potentially catastrophic architectural flaws and single points of failure.

We must develop new tools and measurement techniques for e-business vulnerability assessment, business impact analysis, evaluation of recovery and continuity alternatives, and replacement for the recovery and continuity exercises that have offered false comfort for so many years. Traditional software-based and hard-bound recovery plans will give way to exciting new continuity-driven technology that will allow modeling, simulation and prediction of potential failure points, disruptions and defined responses. New products for documenting complex e-business processes and relationships will be desperately needed for all of this to work.

Network Security – Explosive growth in networking has brought all aspects of information technology into highly integrated and efficient business-oriented processes. At the same time, this degree of automation and electronic integration has created electronic pathways reachable by interlopers from anywhere on the globe, which poses a serious threat to the continuity of mission-critical systems.

Careful attention to security in the implementation of these electronic highways is essential to minimizing devastating compromises and business losses. At the same time, highly sophisticated security technologies and schemes will vastly complicate continuity planning and thus must be factored into new and forward-thinking solutions. New security software for intrusion detection and response will also serve to document business processes and relationships, and will be useful in creating modeling and simulation capabilities for business continuity purposes. Maintaining global synchronization of highly integrated but dislocated and encrypted databases in the midst of a dissembling network, for example, sounds like the continuity planner’s worst nightmare. It could well be.

Privacy – Increasing focus upon consumer privacy, federal legislation and mandated controls demands a more aggressive approach to protection of sensitive personal information. At the same time, new security technologies are now making it possible to reasonably plan, design and implement the level of safeguards required to protect these records. These changes have dramatically increased the ante for failure to apply adequate safeguards.

Mandated control and accountability requirements for consumer information, particularly as it flows through surging Internet-based business-to-consumer relationships, will require new thinking, advanced record protection and retention, and business continuity solutions. New federal guidelines and proposed legislation, especially dealing with patient medical records, increasingly speak to continuity planning issues.

THINKING "OUTSIDE THE BOX"
Thus, a new paradigm will confront conventional wisdom in the areas of information security and disaster recovery/business continuity. Old solutions likely will not work. New, "outside the box" thinking will be required to avoid flawed network security implementations and ensure the level of continuity required. These forces will reshape our industry and dramatically alter the landscape. Look for them.


About the Author
Robert P. Campbell, Managing Director, Peak Consulting, is a recognized international expert in information security and buisiness continuity planning. An early pioneer, he has testified before the US Congress as an expert witness and has helped influence our national posture on Computer security/continuity planning. contact him at rcampbell@peakcons.com