Business Continuity and Disaster Recovery Policy

Version 2.0

For Students, Faculty, Staff, Guests, Alumni

Purpose

The purpose of this policy is to ensure the continuity and recovery of the University's IT Resources. 

Scope

This IT security policy, and all policies referenced herein, shall apply to all members of the University community, including faculty, students, administrative officials, staff, alumni, authorized guests, delegates, and independent contractors (the "User(s)" or "you") who use, access, or otherwise employ, locally or remotely, the University's IT Resources, whether individually controlled, shared, stand-alone, or networked. 

Policy Statement

  • Users accountable for the University's IT Resources must have documented Business Continuity (BC) and Disaster Recovery (DR) plans appropriate to the criticality of the supported business functions and IT Resources. 
  • BC/DR planning must be informed by a Business Impact Analysis (BIA) or an equivalent criticality assessment that identifies essential business functions, critical applications, systems, data, and interdependencies; recovery priorities; and applicable Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs). 
  • BC/DR plans must, as applicable: 
    • Identify assigned roles and responsibilities, responsible personnel, and current internal and external contact information. 
    • Define procedures for maintaining essential business functions during an emergency or system disruption and for recovering and reconstituting IT Resources to a known operational state within established recovery objectives. 
    • Address dependencies on personnel, facilities or workspace, communications, equipment, data and records, third-party service providers, and related recovery plans. 
    • Identify alternate storage, processing, and telecommunications arrangements where required to meet established recovery objectives, with protections commensurate with the primary environment. 
    • Be reviewed and approved by the appropriate leadership. 
    • Protected against unauthorized access and modification. 
  • BC/DR plans must be stored in accessible, secure locations (e.g., a recovery planning tool managed by Information Security and Assurance) and, when possible, in geographically diverse locations (e.g., on-premises, off-premises) to ensure immediate availability and resilience during disruptive events. 
  • A documented, tested secondary authentication method, approved by Information Security and Assurance, must operate independently of the centrally managed identity provider and be used during authentication service outages. 

Users accountable for IT Resources must ensure personnel with assigned BC/DR roles receive role-based training annually or following significant changes. 

  • Appropriate leadership and Users accountable for IT Resources must ensure sufficient financial, personnel, and other resources are available to develop, maintain, test, and execute technological BC/DR plans. 
  • Backups supporting critical IT Resources must be performed at frequencies consistent with established RTOs and RPOs, protected for confidentiality, integrity, and availability, and periodically tested to verify reliability and integrity. 
  • The following BC/DR maintenance and testing activities must be conducted annually, following significant changes to IT Resources or BC/DR plans, or when new critical IT Resources are implemented: 
    • Review the BC/DR objectives and strategy, including business criticality, recovery priorities, RTOs, and RPOs, 
    • Update/create BC/DR plans, including applicable dependencies and recovery procedures, 
    • Update/create the internal and external contacts lists and communicate material plan changes to assigned personnel, 
    • Conduct BC/DR simulation/tabletop exercise(s), review test results, document identified deficiencies, and initiate corrective actions as needed, 
    • Verify the alternate site, storage, processing, and telecommunications infrastructure, if applicable, 
    • Test recovery and restoration procedures using backup information, as appropriate,
    • Incorporate lessons learned from training, testing, and actual contingency events into BC/DR plans and future exercises, 
    • Verify that all components of the BC/DR plans remain applicable and effective. 

Definitions

Business Continuity refers to an organization's ability to continue essential processes in the face of disruptive events.

Business Impact Analysis (BIA) is an assessment used to identify essential business functions, dependencies, and the impacts of disruption to support recovery priorities and objectives.  

Disaster Recovery is the ability to restore an organization's critical systems and services to return the entity to an acceptable operating condition following a catastrophic event by activating a Disaster Recovery Plan. Disaster recovery is a subset of business continuity planning. 

Disaster Recovery Plan is procedural documentation to reestablish an organization's critical business applications and services following a disaster or a significant event. 

IT Resources include computing, networking, communications, applications, and telecommunications systems, infrastructure, hardware, software, data, databases, personnel, procedures, physical facilities, cloud-based vendors, Software as a Service (SaaS) vendors, and any related materials and services.  

Recovery Point Objective (RPO) is the maximum acceptable amount of data loss measured in time following a disruption. 

Recovery Time Objective (RTO) is the target period within which an IT Resource or service must be restored following a disruption. 

NIST SP 800-53 Rev. 5 Alignment

Contingency Planning: CP-1 Policy and Procedures; CP-2 Contingency Plan; CP-3 Contingency Training; CP-4 Contingency Plan Testing; CP-6 Alternate Storage Site; CP-7 Alternate Processing Site; CP-8 Telecommunications Services; CP-9 System Backup; CP-9(1) System Backup – Testing for Reliability and Integrity; CP-10 System Recovery and Reconstitution. 

Related Policies and Procedures

Implementation Information

Review Frequency: Triennial
Responsible Person: Senior Director of IT Security and Assurance
Approved By: CISO
Approval Date: March 30, 2020

Revision History

Version: Date:
Description:
1.0 03/30/2020 Initial document
1.1 04/04/2023 Updated policy statement, definitions, links
1.2 04/27/2026 Updated policy statement
2.0 09/18/2026 Remediated BC/DR requirements for criticality analysis, governance and approval, role-based training, testing and corrective action, alternate recovery arrangements, backups, and recovery/reconstitution; aligned to NIST SP 800-53 Rev. 5 CP-1, CP-2, CP-3, CP-4, CP-6, CP-7, CP-8, CP-9, CP-9(1), and CP-10. 

Policy Disclaimer Statement

Deviations from policies, procedures, or guidelines published and approved by Information Security and Assurance (ISA) will only be considered cooperatively between ISA and the requesting entity with sufficient notice to allow for conducting appropriate risk analysis, documentation, review, and notification to authorized University representatives where necessary. Failure to adhere to ISA written policies may be met with University sanctions up to and including dismissal.

Need Help?


Walk-In Centers

McShane Center 266 | RH
Leon Lowenstein SL18 | LC

View Our Walk-In Hours