Acronis is exposed to potential risks that could disrupt or destroy critical business functions and/or the production and delivery of Company goods and services. Our strategy for continuing business in the event of an incident is to ensure the safety and security of all employees; and to continue critical business functions, production, …show more content…
and delivery of products and services.
1. Scope
The purpose of the BC/DR policy is to ensure that all Acronis business activities can be kept at normal or near-normal performance following an incident that has the potential to disrupt or destroy the Company.
The scope of this policy are Acronis offices, Data Centers (DCs), including subcontractors, product environments, and Acronis Staff.
2. Responsibilities
Role title
Role description
ISD
Provides guidance in choosing mitigation controls basing on best practices in Information Security and Business Continuity Management
Acronis Staff
All Acronis employees and complementary workers on behalf of Acronis must comply with this procedure
DCO
Data Center Operations (DCO) are responsible for verifying DR plans for Data Centers and ensure they’re present in contracts with third-parties
Development teams
Teams (including QA), which are responsible for DR planning in product development lifecycle
Internal Auditor
Performs regular audits to ensure compliance with this policy
3.
Policy
4.1 Key goals
The main goals of Acronis Business Continuity Program are:
• Maintain a strategy for reacting to, and recovering from, adverse situations;
• Maintain a program of activity, which ensures the company has the ability to react appropriately to, and recover from, adverse situations in line with the business continuity objective;
• Maintain appropriate response plans underpinned by a clear escalation process;
• Train employees and exercise response and recovery plans;
• Maintain a level of resilience to operational failure in line with the risk faced, the level of negative impact which could result from failure and senior management’s level of acceptable risk;
• Maintain employee awareness of the company’s expectations of them during an emergency or business continuity threatening situation;
• Take account of changing business needs and ensure that the response plans and business continuity strategy are revised where necessary;
• Remain aligned with best practice in business continuity management.
4.2 Business Continuity …show more content…
strategy
To ensure, that all possible scenarios are taken into account, Acronis establishes separate BC/DR processes for the following general areas:
Data Centers
Data Centers are the key element of all Acronis cloud solutions.
Acronis understands, that DCs require specific regulations of BC/DR, that differ from all other types of assets. These include redundancy, prevention and protection from human-made and natural disasters. For outsourcing, Acronis must ensure that BC/DR processes satisfy necessary requirements either by a specific certification earned by DC, or necessary statements in SLA.
Offices
Offices are the heart of Acronis business. Acronis must ensure, that whatever happens, designed measures for hardening business processes and office infrastructure will help to achieve the following:
• There will be a logical recovery of the business;
• Impacts will be kept within acceptable levels as defined by the business department representatives;
• Business will continue as usual, as far as possible.
Application
Environments
Acronis must take care of hardening the environments, so that Acronis products will be redundant as well. This is a cooperative work with development teams, which helps to:
• Avoid negative impact on production environments;
• Minimize restore time in case of product failures;
• Enhance development processes through the full lifecycle to increase productivity and redundancy of the product
itself.
Acronis Staff
Acronis’s biggest value is its people. Besides designing mesures to keep Acronis Staff safe, Acronis’s duty is to teach to use them by performing regular trainings.
To minimize business delay because of absence or loss of key team members, segregation og duties is required.
4.3 Business Impact Analysis