Disaster Recovery.com

Network disaster recovery plan template

By Paul Kirvan

Editor's note: This article was expanded and updated in November 2017.

Most organizations depend on voice and data communications, and also have LANs and WANs. With such a critical and strategic investment in networking, how do you protect those valuable investments from unplanned disruptions due to carrier problems or equipment malfunctions? And how do you know your network infrastructure is secure and protected from unauthorized access, viruses or attacks by hackers? Critical network infrastructures and associated assets must be protected with disaster recovery plans.

In this article and its associated network disaster recovery plan template, we'll examine the issues that should be addressed when preparing and deploying a network disaster recovery plan for voice and data communications.

Network disaster recovery planning is not always a priority

When it comes to network infrastructures, disaster recovery planning often isn't a huge priority. Network security, by contrast, is usually a high priority because a porous perimeter spells doom for most organizations. Preventing unauthorized access by hackers and other criminal types and halting the introduction of viruses and denial-of-service attacks are usually high priorities that get management attention.

On the voice side, growing acceptance of voice over IP (VoIP) technology has increased the importance of robust network security initiatives. As VoIP is simply another application using existing network resources, it has vulnerabilities that must be addressed the same as other network-based systems.

Older PBS systems typically used separate network facilities and did not overlap with data networks. However, as it became more cost-effective to share voice and data traffic over digital T-1 lines, the risks to voice communications systems increased.

Why networking requires its own specific DR plan

Network disaster recovery planning is critical for enterprise LANs, no matter how large the organization or potential disaster. And you require a network-specific DR plan for the same reasons network security has become such a high priority. With voice, data, internet access and other network services often sharing the same network resources, it is essential to not only protect network access lines and the interface devices -- routers and switches -- that support these services, but to be able to get those network resources back up and running in the event of an interruption.

A resilient network environment is also indispensable for providing business continuity. This enables you to access services, local or remote physical or virtual servers, and storage, irrespective of location: a central data center, colocation facility, managed service provider or the cloud. Business continuation is particularly crucial for branch or remote offices that require remote access information in the public cloud or at company headquarters.

Getting started with network disaster recovery planning

Before you get started creating your network disaster recovery plan, read these important caveats:

  1. Take the disaster recovery planning process seriously. If you want to protect your network infrastructures and related assets from unplanned events that could disrupt network operations, you need a plan. It doesn't have to be hundreds of pages long; a one-page plan with the right information can be more valuable than a voluminous document that nobody can use.
  2. Use business continuity standards as a starting point. Almost two dozen BC/DR standards are available worldwide.
  3. Keep it simple. Depending on how your voice/data/internet/wireless networks are configured, your plans will need to reflect that same level of structure and complexity.
  4. Limit content to actual disaster response actions. Assuming you are creating a plan to respond to specific network-related incidents, include only the information needed for the response and subsequent recovery.
  5. Keep the plan up to date and test often. Once the plan is complete, exercise the plan at least twice annually -- more often if your network configuration changes frequently -- to ensure that documented procedures make sense in the sequence indicated.
  6. Be flexible. A single disaster recovery template may not be applicable to all networks, especially if your organization has many corporate locations served by the network and multiple data centers. You may want to consider more complex templates, specialized network DR software or consultants experienced in network disaster recovery.

Network disaster recovery plan components

Next, we'll examine the structure and content of the network disaster recovery plan template, indicating key issues to address and activities to perform.

Why a recovery site is necessary

As with all things DR related, a recovery site is an important component of any network DR plan; it is where you can recover and restore your IT infrastructure and operations when your primary data center becomes unavailable. There are two types of recovery sites: external and internal.

Network DR plan templateClick on the above image
to download our free
Network disaster recovery
plan template.

An internal site normally consists of a second data center owned and operated by another organization that the company can depend on to recover and resume operations should disaster befall its primary data center. Organizations with aggressive recovery time objectives and large information requirements tend to go with an internal DR recovery site.

There are three types of external recovery sites: hot, warm and cold. Hot sites are fully staffed, functional and ready to go in the event of a disaster. Warm sites have some or all of the necessary hardware, software, network services and personnel, but not the data. A cold site, which can be used to complement hot and warm sites, is an option for when a disaster lasts for an extended period. It has the infrastructure to support data and IT systems, but doesn't include the specific technologies necessary to run business operations until an organization installs that equipment and activates its DR plan.

Common mistakes of network disaster recovery planning

Redundancy and diversity are the fundamental components when planning a resilient and survivable data and communication network. With that in mind, businesses often make a few common internal and external mistakes when preparing a network DR plan.

Externally, companies often don't take the time to closely examine the network infrastructure of their primary and alternate carriers outside of their building when assessing the redundancy and resilience of voice and data networks. Where does service enter, and is there just a single entry point? Is service delivered using overhead wires or underground? If the former, where are the poles located, and are they in the path of oncoming transportation? If the latter, what type of conduit does the carrier use to carry service to the building: Is the cable simply buried or is it safely tucked away in a hardened conduit? What level of transport diversity to and from the building does the local telephone company provide? If a path is blocked, will voice and data service continue over another route?

Internally, make sure you design your network infrastructure with diversity and redundancy in mind. That way, there will be no single points of failure that can take the network down. Are your network connectivity devices configured in a redundant arrangement, and are there extra switches, routers and other network devices available? Do you use more than one internet service provider (ISP) or have an alternate ISP ready to go should service from your primary ISP go down? What level of diversity -- or physically separate connections -- does your primary ISP provide to deliver service?

How to audit/maintain/update a plan

Auditing and testing a network DR plan helps to make sure it stays up to date and continues to meet the needs of your organization. It ensures the plan you have in place addresses your network technology issues, people and processes, and has the pertinent controls to work as expected when confronted with an actual emergency.

The results of an audit can detect areas of the plan that are incomplete, lack proper procedures and suitable documentation, are untested, and aren't up to date. As with an overarching DR audit, one that focuses on a networking DR plan should address:

The process of developing a network disaster recovery plan should be a relatively easy process. Plan complexity may increase, however, if you have a very complex network with multiple technologies and a complex topology. The keys to success include defining step-by-step response and recovery procedures, validating these activities through tests and keeping the plan up to date.

22 Nov 2017

All Rights Reserved, Copyright 2008 - 2024, TechTarget | Read our Privacy Statement