Business Continuity and Disaster Recovery Standard
Revision History
| Version No. | Date | Description | Author |
|---|---|---|---|
| 1.0 | 10/20/2023 | Initial Release | ISS GRC |
| 2.0 | 03/14/2024 | Updated from Business Continuity and Disaster Recovery Policy | ISS GRC |
| 3.0 | 01/22/2026 | Reviewed against NIST 37r2 Risk Management Framework | OISA GRC |
1. Introduction
Business Continuity and Disaster Recovery is designed to minimize disruptions to regular business functions to ensure that organizations are well-equipped to handle unplanned incidents while protecting IT systems and critical data during interruptions. In the event of a disaster, effective Business Continuity and Disaster Recovery planning provides the ability to swiftly return to normal operations, minimize downtime, protect personnel, and maintain critical operations. This standard provides the guidance to meet the fundamental requirements for Business Continuity and Disaster Recovery which is crucial for maintaining the confidentiality, integrity, and availability of data, aligning WSU System with the National Institute of Standards and Technology’s (NIST) core principles for robust cybersecurity practices.
2. Purpose
Information security standards are created to set processes for areas to facilitate data protection. They also align business goals and strategies with appropriate methods for technically and operationally protecting data. As Information Owners determine their requirements for protecting data, standards define the processes and procedures WSU areas will follow to meet policy requirements.
3. Scope
The control baselines selected for systems are to be commensurate with the potential adverse impact on WSU operations, WSU assets, individuals, other organizations, or the Nation if there is a loss of confidentiality, integrity, or availability. FIPS 199 requires organizations to categorize systems as low impact, moderate-impact, or high-impact for the stated security objectives of confidentiality, integrity, and availability. This standard applies to all Institutional business units, workforce members, and institutional information systems that create, store, use, share, and/or transmit Institutional Data.
4. External Requirements/Drivers
The following Business Continuity and Disaster Recovery standards are derived from the National Institute of Standards and Technology (NIST) Special Publication 800-53r5 Control Framework.
WSU is required to comply with Federal and/or State laws and regulations related to information security, privacy, and data confidentiality. This standard complies with regulations as defined by:
- FERPA
- HIPPA
- GLBA
- Washington State OCIO Policy 141 – Securing Information Technology Assets
5. Effective Dates
January 1st, 2026
6. Instruction
The following Business Continuity and Disaster Recovery Standard statements are applicable all information systems regardless of the Information Owner’s stated Impact (Low, Moderate, or High) in the event Confidentiality, Integrity, or Availability of the information system were to become compromised. See the definition of “Stated Impact”.
7. Standard
Contingency Plan CP-2
Control Standard for Low, Moderate, and High Impact Systems:
- Develop a contingency plan for the system that:
- Identifies essential mission and business functions and associated contingency
requirements. - Provides recovery objectives, restoration priorities, and metrics.
- Addresses contingency roles, responsibilities, assigned individuals with contact
information. - Addresses maintaining essential mission and business functions despite a system
disruption, compromise, or failure. - Addresses eventual, full system restoration without deterioration of the controls
originally planned and implemented. - Addresses the sharing of contingency information.
- Is reviewed and approved by [Assignment: organization-defined personnel or roles].
- Distribute copies of the contingency plan to [Assignment: organization-defined key contingency personnel (identified by name and/or by role) and organizational elements].
- Coordinate contingency planning activities with incident handling activities.
- Review the contingency plan for the system [Assignment: organization-defined frequency].
- Update the contingency plan to address changes to the organization, system, or environment of operation and problems encountered during contingency plan implementation, execution, or testing.
- Communicate contingency plan changes to [Assignment: organization-defined key contingency personnel (identified by name and/or by role) and organizational elements].
- Incorporate lessons learned from contingency plan testing, training, or actual contingency activities into contingency testing and training.
- Protect the contingency plan from unauthorized disclosure and modification.
Control Enhancements for Moderate, and High Impact Systems:
Coordinate with Related Plans CP-2(1)
Coordinate contingency plan development with organizational elements responsible for related plans.
Resume Mission and Business Functions CP-2(3)
Plan for the resumption of [Assignment: all, essential] mission and business functions within [Assignment: organization-defined time period] of contingency plan activation.
Identify Critical Assets CP-2(8)
Identify critical system assets supporting [Assignment: all, essential] mission and business functions.
Control Enhancement for High Impact Systems:
Capacity Planning CP-2(2)
Conduct capacity planning so that necessary capacity for information processing, telecommunications, and environmental support exists during contingency operations.
Continue Mission and Business Functions CP-2(5)
Plan for the continuance of [Assignment: all, essential] mission and business functions with minimal or no loss of operational continuity and sustains that continuity until full system restoration at primary processing and/or storage site.
Contingency Training CP-3
Control Standard for Low, Moderate, and High Impact Systems:
- Provide contingency training to system users consistent with assigned roles and responsibilities:
- Within [Assignment: organization-defined time period] of assuming a contingency role or responsibility.
- When required by system changes.
- [Assignment: organization-defined frequency] thereafter.
- Review and update contingency training content [Assignment: organization-defined frequency] and following [Assignment: organization-defined events].
Control Enhancement for High Impact Systems:
Simulated Event CP-3(1)
Incorporate simulated events into contingency training to facilitate effective response by personnel in crisis situations.
Contingency Plan Testing CP-4
Control Standard for Low, Moderate, and High Impact Systems:
- Test the contingency plan for the system [Assignment: organization-defined frequency] using the following tests to determine the effectiveness of the plan and the readiness to execute the plan: [Assignment: organization-defined tests].
- Review the contingency plan test results; and
- Initiate corrective actions, if needed.
Control Enhancement for Moderate, and High Impact Systems:
- Establish an alternate storage site, including necessary agreements to permit the storage and retrieval of system backup information; and
- Ensure that the alternate storage site provides controls equivalent to that of the primary site.
- Control Enhancements for Moderate, and High Impact Systems:
Separation from Primary Site CP-6(1)
Identify an alternate storage site that is sufficiently separated from the primary storage site to reduce susceptibility to the same threats.
Accessibility CP-6(3)
Identify potential accessibility problems to the alternate storage site in the event of an areawide disruption or disaster and outline explicit mitigation actions.
Control Enhancement for High Impact Systems:
Recovery Time and Recovery Point Objectives CP-6(2)
Configure the alternate storage site to facilitate recovery operations in accordance with recovery time and recovery point objective.
Alternate Processing Site CP-7
Control Standard for Moderate, and High Impact Systems:
- Establish an alternate processing site, including necessary agreements to permit the transfer and resumption of [Assignment: organization-defined system operations] for essential mission and business functions within [Assignment: organization-defined time period consistent with recovery time and recovery point objectives] when the primary processing capabilities are unavailable.
- Make available at the alternate processing site, the equipment and supplies required to transfer and resume operations or put contracts in place to support delivery to the site within the organization-defined time period for transfer and resumption.
- Provide controls at the alternate processing site that are equivalent to those at the primary site.
Control Enhancements for Moderate and High Impact Systems:
Separation from Primary Site CP-7(1)
Identify an alternate processing site that is sufficiently separated from the primary processing site to reduce susceptibility to the same threats.
Accessibility CP-7(2)
Identify potential accessibility problems to alternate processing sites in the event of an areawide disruption or disaster and outlines explicit mitigation actions.
Priority of Service CP-7(3)
Develop alternate processing site agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives).
Control Enhancement for High Impact Systems:
Preparation for Use CP-7(4)
Prepare the alternate processing site so that the site can serve as the operational site supporting essential mission and business functions.
Telecommunications Services CP-8
Control Standard for Moderate, and High Impact Systems:
The organization establishes alternate telecommunications services including necessary agreements to permit the resumption of [Assignment: organization-defined information system operations] for essential missions and business functions within [Assignment: organization-defined time period] when the primary telecommunications capabilities are unavailable at either the primary or alternate processing or storage sites.
Control Enhancements for Moderate, and High Impact Systems:
Priority Of Service Provisions CP-8(1)
The organization:
- Develops primary and alternate telecommunications service agreements that contain priority-of-service provisions in accordance with organizational availability requirements (including recovery time objectives).
- Requests Telecommunications Service Priority for all telecommunications services used for national security emergency preparedness in the event that the primary and/or alternate telecommunications services are provided by a common carrier.
Single Points Of Failure CP-8(2)
The organization obtains alternate telecommunications services to reduce the likelihood of sharing a single point of failure with primary telecommunications services.
Control Enhancement for High Impact Systems:
Separation Of Primary / Alternate Providers CP-8(3)
The organization obtains alternate telecommunications services from providers that are separated from primary service providers to reduce susceptibility to the same threats.
Provider Contingency Plan CP-8(4)
The organization:
- Requires primary and alternate telecommunications service providers to have contingency plans.
- Reviews provider contingency plans to ensure that the plans meet organizational contingency requirements.
- Obtains evidence of contingency testing/training by providers [Assignment: organization-defined frequency].
Control Standard for Low, Moderate, and High Impact Systems:
System Backup CP-9
- Conduct backups of user-level information contained in [Assignment: organization-defined system components] [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives].
- Conduct backups of system-level information contained in the system [Assignment: organization-defined frequency consistent with recovery time objectives].
- Conduct backups of system documentation, including security- and privacy-related documentation [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives].
- Protect the confidentiality, integrity, and availability of backup information.
Control Enhancements for Moderate, and High Impact System:
Testing for Reliability and Integrity CP-9(1)
Test backup information [Assignment: organization-defined frequency] to verify media reliability and information integrity.
Cryptographic Protection CP-9(8)
Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of [Assignment: organization-defined backup information].
Control Enhancement for High Impact System:
Test Restoration Using Sampling CP-9(2)
Use a sample of backup information in the restoration of selected system functions as part of contingency plan testing.
Separate Storage for Critical Information CP-9(3)
Store backup copies of [Assignment: organization-defined critical system software and other security-related information] in a separate facility or in a fire rated container that is not collocated with the operational system.
Transfer to Alternate Storage Site CP-9(5)
Transfer system backup information to the alternate storage site [Assignment: organization-defined time period and transfer rate consistent with the recovery time and recovery point objectives].
Control Standard for Low, Moderate, and High Impact Systems:
System Recovery and Reconstitution CP-10
Provide for the recovery and reconstitution of the system to a known state within [Assignment: organization-defined time period consistent with recovery time and recovery point objectives] after a disruption, compromise, or failure.
Control Enhancements for Moderate, and High Impact System:
Transaction Recovery CP-10(2)
Implement transaction recovery for system that are transaction-based.
Control Enhancements for High Impact Systems:
Restore Within Time Period CP-10(4)
Provide the capability to restore system components within [Assignment: organization-defined restoration time periods] from configuration-controlled and integrity-protected information representing a known, operational state for the components.
8. Administrative
Information Owners (e.g., vice presidents, chancellors, or deans) are responsible for the administration of this standard. The Chief Information Security Officer is responsible for the enforcement of this standard.
9. Review Cycle
This standard shall be reviewed annually.
Appendix A: Acronyms
| Acronym | Definition |
|---|---|
| WSU | Washington State University |
| NIST | National Institute of Standards and Technology |
This content is now available in an accessible HTML format. The original PDF remains available for reference. Business Continuity and Disaster Recovery (PDF)