283
A
Sample Recovery Checklist
A.1 Recovery Checklist (Incident Response Team)
Note: Generally, this checklist is in sequential order, but actions can be
done in parallel.
Action BCP Reference
EVENT OCCURRENCE
Incident Detection Page/Section
Incident Reporting Page/Section
Emergency Response Page/Section
Initial Notification Contact Page/Section
Primary contact:________________________
Secondary contact:______________________
IRT Member Recall (use the roster below)
Incident Response Team Recall Roster
Name Title Home Office Mobile
284 A.1 Recovery Checklist (Incident Response Team)
Assembly (in the event of building evacuation) Page/Section
Pick assembly point and provide instructions
Account for all personnel
Conduct a Preliminary Assessment Page/Section
Determine:
Status of emergency response
Incident analysis
Injuries and fatalities
Areas affected
Security
Building access
Status of the following:
Facilities
Power
Utilities
HVAC
Environmental conditions
Data center
Voice communications
Data communication
Designate Command Center Page/Section
(at least 2 possibilities are recommended)
On-premise (if the building is habitable)
Off-premise (if access to the main offices is denied)
Conduct Situation Briefing (as appropriate) Page/Section
Assess Damage Page/Section
Form team
Damage assessment team briefing
Assess damage
Document damage with video recorder, camera, and forms
Analyze damage and impact
Identify salvageable equipment
Conduct Damage Assessment Brief/Debriefing Page/Section
A.1 Recovery Checklist (Incident Response Team) 285
Appendix A
Provide instructions (policy/procedure) for dealing with the press/
media
Develop a Consolidated Action Plan Page/Section
Review planned recovery strategy
Review operational status
Assess business impact
Develop recovery recommendation
Review maximum acceptable outage duration
Review recovery timeline(s) and assumptions
Finalize recovery recommendation
Review disaster declaration criteria
Formulate a disaster declaration recommendation
Brief executive management
Obtain disaster declaration approval
Obtain/develop corporate media statement
Disaster Decision
If Declaration = No
Recover in place, using locally available resources
If Declaration = Yes
Implement Disaster Recovery Plan and Consolidated Action
Plan
Direct systems and operations team leader to notify hot site
Mobilize Recovery Teams Page/Section
Direct team leaders to call, assemble, and brief functional recov-
ery team members
Activate Support Personnel (as appropriate) Page/Section
Human Resources [name]
Finance and Purchasing [name]
Legal [name]
Office Services (Mailroom, Shipping/Receiving)
Records Management
Distribution
Travel
286 A.1 Recovery Checklist (Incident Response Team)
Travel Page/Section
Check travel (airline) schedules
Make travel arrangement/reservations
Deploy teams to alternate facilities (as appropriate)
Teams: Implement Functional Recovery Plans Page/Section
Coordinate Recovery Actions Page/Section
Status reports
Periodic briefings (as required)
Initiate Salvage and Site Restoration (as appropriate) Page/Section
Return Home/Transition Planning Page/Section
Conduct a Post-Incident Review Page/Section
Review all activity logs
Debrief team personnel
Document “lessons learned
Prepare an After-Action Report
Update Disaster Recovery Plans Page/Section
Recovery Checklist (Systems and Operations)
Note: Generally, this checklist is in sequential order, but actions can be
done in parallel.
Action BCP Reference
EVENT OCCURRENCE
Incident Detection Page/Section
Incident Reporting Page/Section
Emergency Response Page/Section
Assemble on-duty personnel at the designated assembly area (as
appropriate)
Account for on-duty personnel (as appropriate)
A.1 Recovery Checklist (Incident Response Team) 287
Appendix A
Provide Instructions to Assembled Personnel (as appropriate)Page/
Section
Provide support to the incident management team (as required)
Team Leader
Report to Designated Location (Command Center) Page/Section
Participate in IRT Briefing Page/Section
Alert Hot Site (as appropriate) Page/Section
Alert Offsite Storage Facility Maintaining
Backup Tapes Page/Section
___ / ___ - _____
Participate in Damage Assessment Page/Section
(mobilize selected team members, as required)
Attend Damage Assessment Briefing Page/Section
Participate in the Consolidated Action
Plan Development Page/Section
Disaster Decision Page/Section
If Declaration = NO
Execute standard operational corrections (onsite)
If Declaration = YES
Make disaster declaration to hot site
Review recovery configuration (equipment/facility) with hot site
Confirm equipment availability
Instruct hot site to load appropriate operating system
Mobilize Subordinate Functional Recovery
Team Leaders Page/Section
Systems and operations
Applications
Network/communications
Voice communications

Get Business Continuity and Disaster Recovery for InfoSec Managers now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.