{"id":5277,"date":"2015-09-22T22:22:48","date_gmt":"2015-09-22T22:22:48","guid":{"rendered":"https:\/\/multiacademstg.wpengine.com\/20000academy\/?p=5277"},"modified":"2025-07-05T08:55:02","modified_gmt":"2025-07-05T08:55:02","slug":"itil-risk-response-measures-and-recovery-options-from-catastrophic-events","status":"publish","type":"post","link":"https:\/\/staging.advisera.com\/20000academy\/blog\/2015\/09\/22\/itil-risk-response-measures-and-recovery-options-from-catastrophic-events\/","title":{"rendered":"ITIL Risk response measures and recovery options from catastrophic events"},"content":{"rendered":"<p><strong>IT Service Continuity<\/strong> is one of those <a href=\"https:\/\/staging.advisera.com\/20000academy\/what-is-itil\/\" target=\"_blank\" rel=\"noopener noreferrer\">ITIL<\/a>\u00a0chapters that emphasizes the strong relationship between business needs (and requirements) and the IT service provider, because once a worst-case scenario happens \u2013 everything after that will either look like a well-performed ballet or someone\u2019s worst nightmare.<\/p>\n<p>One of the key areas that require great alignment between business and IT are those events that will \u201cnever happen,\u201d but if they do, there is no more business or IT. Within ITIL, IT Service Continuity Management is part of the <strong>Service Design<\/strong> stage of the service lifecycle, and is responsible for aligning IT service continuity strategy with <strong>Business continuity strategy<\/strong>, ensuring that the required IT technical and service facilities (including computer systems, networks, applications, data repositories, telecommunications, environment, technical support, and Service Desk) can be resumed within required, and agreed, business timescales.<\/p>\n<h2 style=\"padding-top: 10px; padding-bottom: 10px;\">Risk response measures<\/h2>\n<p>We are all well aware of the typical risks that exist within our line of business, and some of them could probably be found in your IT environment as well. Such risks generally fall under <strong><a href=\"https:\/\/staging.advisera.com\/20000academy\/iso-20000-documentation-toolkit\/?rel=resolution-and-fulfillment-processes&amp;doc=incident-management-process\" target=\"_blank\" rel=\"noopener\">Incident Management<\/a><\/strong> and\u00a0<strong><a href=\"https:\/\/staging.advisera.com\/20000academy\/iso-20000-documentation-toolkit\/?rel=service-assurance-processes&amp;doc=availability-management-process\" target=\"_blank\" rel=\"noopener\">Availability Management<\/a><\/strong>, because they are simply part of everyday life. However, if none of the following risk response measures exists, they may also cause the same effect as a catastrophic event on a larger scale.<br \/>\n<div id=\"middle-banner\" class=\"banner-shortcode\"><\/div><script>loadMiddleBanner();<\/script><br \/>\n<div id=\"side-banner-trigger\" class=\"banner-shortcode\"><\/div><br \/>\nExamples of typical <a href=\"https:\/\/staging.advisera.com\/20000academy\/documentation\/risk-assessment-and-treatment\/\" target=\"_blank\" rel=\"noopener noreferrer\">risk<\/a> response measures include:<\/p>\n<ul>\n<li>Installation of UPS (Uninterruptible Power Supply)<\/li>\n<li>Installation of fault-tolerant systems for critical business applications<\/li>\n<li>Configuration of disk drives in RAID arrays with mirroring<\/li>\n<li>Stocking critical spare parts for quick replacement<\/li>\n<li>Designing systems with no SPoF (Single Point of Failure) \u2013 e.g., redundant internet links<\/li>\n<li>Implementation of resilient IT systems and networks<\/li>\n<li>Outsourcing services to more than one provider<\/li>\n<li>Implementation of greater physical and IT-based security controls<\/li>\n<li>Integration of Cloud and Cloud-based services<\/li>\n<li>Implementation of fault detection and monitoring services<\/li>\n<li>Implementation of automated fire detection &amp; suppression systems<\/li>\n<li>Implementation of comprehensive backup &amp; recovery strategy<\/li>\n<\/ul>\n<p>On top of typical response measures, one of the most popular additional measures is surely off-site storage, which involves storage of all the relevant data needed for recovery at a separate location in case something happens to the primary location.<\/p>\n<h2 style=\"padding-top: 10px; padding-bottom: 10px;\">Recovery options<\/h2>\n<p>When designing the <a href=\"https:\/\/staging.advisera.com\/20000academy\/iso-20000-documentation-toolkit\/?rel=service-assurance-processes&amp;doc=it-service-continuity-management-plan\" target=\"_blank\" rel=\"noopener\">IT Service Continuity Strategy<\/a>, note that there may be several feasible recovery options, depending on the root cause of service unavailability. Since these recovery options vary in complexity and duration required for service restoration, they must be planned and put into operation well ahead of any event that may cause the service to halt.<\/p>\n<p><strong>Manual work-around<\/strong> \u2013 In some cases, manual workarounds may provide cheap, fast, and \u201cgood enough\u201d solutions for an extremely complex situation, but for a limited time.<\/p>\n<p><strong>Reciprocal arrangements<\/strong> \u2013 These represent a method of ensuring contingency for business services, where similar organizations would agree to share resources in case of a catastrophic event. Due to the specific nature of IT, we don\u2019t see such arrangements in our everyday lives.<\/p>\n<p><strong>Gradual recovery<\/strong> \u2013 Also known as \u201ccold standby,\u201d this includes provision of empty facilities, infrastructure (such as cabling and telecommunication), and power, but with no actual computing equipment. This recovery method is feasible if service recovery is expected in days (even weeks), as computing hardware has to be purchased, installed and set up.<\/p>\n<p><strong>Intermediate recovery<\/strong> \u2013 Also called \u201cwarm standby,\u201d this includes everything listed under \u201cgradual recovery,\u201d with the addition of actual computing equipment that is necessary. This equipment still has to be set up and configured, but recovery time is much faster than the one mentioned previously.<\/p>\n<p><strong>Fast recovery<\/strong> \u2013 Sometimes referred to as \u201chot standby,\u201d in reality this recovery option may consist of everything listed in \u201cintermediate recovery,\u201d but data and equipment are not mirror images of the production site. It takes a shorter time to prepare, but some services or data may be missing (e.g., data is copied from the main site to off-site every night).<\/p>\n<p><strong>Immediate recovery<\/strong> \u2013 This can truly be called \u201chot standby,\u201d as a secondary location is the mirror image of the primary location, equipment, service, and data-wise. Such locations are often used for load balancing (split site) and provide no loss of service in case of catastrophic event. Due to the fact that everything is doubled, immediate recovery is the most expensive recovery option.<\/p>\n<h2 style=\"padding-top: 10px; padding-bottom: 10px;\">Are there any other options?<\/h2>\n<p>Believe it or not, not doing anything is also an option, but not one that IT can make on their own. If the business evaluates their data stored within information systems as not worth extra safekeeping (and paying for any costs that may arise), then there is nothing IT can do, other than the typical risk responses listed within this article. But, this must be a business decision, and a business decision only.<\/p>\n<p>While ITIL 2011 may look pretty fresh, it is merely an update to ITIL 2007 (V3). At that point in time, terms like \u201cCloud\u201d were not this widespread, and effectively, there was no public (or private) Cloud providers that could offer IaaS (infrastructure as a Service), PaaS (Platform as a Service), or SaaS (Software as a Service), disregarding the size. So, each and every one of the mentioned Cloud services may well fit into any recovery option. Nowadays even Cloud providers offer recovery options to their clients; if anything happens to a whole world region \u2013 they\u2019ll move all the data and services seamlessly to another region, effectively ensuring service continuity.<\/p>\n<p>When everything runs smoothly, it\u2019s hard to talk about worst-case scenarios, but trust me, it\u2019s the best possible time.<\/p>\n<p><em>To implement ISO 20000 easily and efficiently, use our<\/em> <a href=\"https:\/\/staging.advisera.com\/20000academy\/iso-20000-documentation-toolkit\/\" target=\"_blank\" rel=\"noopener\">ISO 20000 Documentation Toolkit<\/a> <em>that provides step-by-step guidance for full ISO 20000 compliance.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>IT Service Continuity is one of those ITIL\u00a0chapters that emphasizes the strong relationship between business needs (and requirements) and the IT service provider, because once a worst-case scenario happens \u2013 everything after that will either look like a well-performed ballet or someone\u2019s worst nightmare. One of the key areas that require great alignment between business &#8230;<\/p>\n","protected":false},"author":33,"featured_media":17236,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[492,489,357,344,191,490,491,380],"class_list":["post-5277","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-availability-management","tag-business-continuity","tag-incident-management","tag-itil","tag-process","tag-service-continuity","tag-service-recovery","tag-strategy"],"acf":[],"_links":{"self":[{"href":"https:\/\/staging.advisera.com\/20000academy\/wp-json\/wp\/v2\/posts\/5277","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/staging.advisera.com\/20000academy\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/staging.advisera.com\/20000academy\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/staging.advisera.com\/20000academy\/wp-json\/wp\/v2\/users\/33"}],"replies":[{"embeddable":true,"href":"https:\/\/staging.advisera.com\/20000academy\/wp-json\/wp\/v2\/comments?post=5277"}],"version-history":[{"count":3,"href":"https:\/\/staging.advisera.com\/20000academy\/wp-json\/wp\/v2\/posts\/5277\/revisions"}],"predecessor-version":[{"id":18504,"href":"https:\/\/staging.advisera.com\/20000academy\/wp-json\/wp\/v2\/posts\/5277\/revisions\/18504"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/staging.advisera.com\/20000academy\/wp-json\/wp\/v2\/media\/17236"}],"wp:attachment":[{"href":"https:\/\/staging.advisera.com\/20000academy\/wp-json\/wp\/v2\/media?parent=5277"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/staging.advisera.com\/20000academy\/wp-json\/wp\/v2\/categories?post=5277"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/staging.advisera.com\/20000academy\/wp-json\/wp\/v2\/tags?post=5277"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}