Learning Objectives:
-
Understand the relationship between operational resilience and ICT risk management.
-
Develop business continuity plans that address ICT-related disruptions.
-
Implement disaster recovery and data backup strategies.
-
Recognise the importance of testing and exercising continuity plans.
8.1 Operational Resilience and ICT Risk
Operational resilience is the ability of an organisation to continue delivering critical services during and after a disruption. Operational resilience in a digital environment depends on robust ICT risk management. The RBI requires that regulated entities should develop and implement response and recovery plans to manage incidents that could disrupt the delivery of critical operations .
The Central Bank of Ireland’s Regulatory & Supervisory Outlook identifies operational and cyber risks as key concerns given rising risk and threat levels . As the Governor noted, there will be a significant focus again this year on operational resilience given its critical nature .
8.2 Business Continuity Planning for ICT Disruptions
Business continuity planning (BCP) ensures that critical business functions can continue during and after a disruptive event. The ECB’s SREP methodology assesses ICT availability and continuity risk, including the number of times ICT continuity or disaster recovery plans have been triggered and the annual unplanned downtime of critical ICT systems .
Key BCP Elements:
Critical Service Identification:Â Identifying the critical services that must be maintained during a disruption.
Risk Assessment:Â Assessing the risks to critical services, including ICT-related risks.
Recovery Strategies:Â Developing strategies to recover critical services, including alternative systems and manual workarounds.
Testing and Exercising:Â Regularly testing and exercising BCPs to ensure their effectiveness.
8.3 Disaster Recovery and Data Backup
Disaster recovery (DR) focuses on restoring IT systems and data after a disruptive event. The IT Security Controls book includes Disaster Recovery as a key on-premises support control. The IT Security Controls book includes backups as a key control for on-premises support.
Key DR and Data Backup Strategies:
Backup Frequency:Â Regular backups of critical data and systems.
Backup Location:Â Storing backups in geographically separate locations.
Recovery Time Objective (RTO):Â The maximum acceptable time to restore a service.
Recovery Point Objective (RPO):Â The maximum acceptable data loss.
Testing:Â Regularly testing DR procedures to ensure their effectiveness.
8.4 Testing and Exercising Continuity Plans
The RBI requires that regulated entities should continuously improve their incident response and recovery plans by incorporating the lessons learned from previous incidents . The SEACEN course identifies “the design and execution of cyber exercises at institutional and industry levels” as a key topic .
Key Testing and Exercising Activities:
Tabletop Exercises:Â Discussion-based exercises to test plans and procedures.
Technical Drills:Â Hands-on testing of technical capabilities.
Full-Scale Exercises:Â Comprehensive tests involving multiple teams and stakeholders.
Lessons Learned:Â Post-exercise reviews to identify improvements