IT Disaster Recovery & Business Continuity Plan
Attachments: ../../Untitled%203a74-6ad9/CSI_IT_Disaster_Recovery_Business_Continuity_Plan_English.docx, ../../Untitled%203a74-6ad9/CSI_IT_Disaster_Recovery_Business_Continuity_Plan_English.pdf, ../../Untitled%203a74-6ad9/CSI_IT_Disaster_Recovery_Business_Continuity_Plan_Gujarati.docx, ../../Untitled%203a74-6ad9/CSI_IT_Disaster_Recovery_Business_Continuity_Plan_Gujarati.pdf, ../../Untitled%203a74-6ad9/CSI_IT_Disaster_Recovery_Business_Continuity_Plan_Hindi.docx, ../../Untitled%203a74-6ad9/CSI_IT_Disaster_Recovery_Business_Continuity_Plan_Hindi.pdf Created: July 25, 2026 12:07 AM Document ID: DOC-2 Document Type: Plan Domain: IT Infrastructure Hierarchy: Playbook Languages: English, Gujarati, Hindi Last Updated: July 25, 2026 12:44 AM Migration Status: Migrated Owner: Cyber Space Infocom Remarks: Reviewed and approved as the CSI controlled working master on 2026-07-26. Recheck time-sensitive technical, pricing and legal details before external issue. Review Date: August 1, 2026 Review Priority: P2 High Source Archive: CSI DOCS.tar(1).gz Source Files: CSI_IT_Disaster_Recovery_Business_Continuity_Plan_English.docx | CSI_IT_Disaster_Recovery_Business_Continuity_Plan_English.pdf | CSI_IT_Disaster_Recovery_Business_Continuity_Plan_Gujarati.docx | CSI_IT_Disaster_Recovery_Business_Continuity_Plan_Gujarati.pdf | CSI_IT_Disaster_Recovery_Business_Continuity_Plan_Hindi.docx | CSI_IT_Disaster_Recovery_Business_Continuity_Plan_Hindi.pdf Source Formats: DOCX, PDF Status: Under Review Version: v1.0
This page contains the readable working content migrated from the CSI source archive. Review and approve it before external or contractual use.
- English
| | CYBER SPACE INFOCOM IT Infrastructure • AI • Cyber Security | +91 90547 79647 |
| --- | --- |
IT DISASTER RECOVERY & BUSINESS CONTINUITY PLAN
Business Impact • Recovery Priorities • RPO/RTO • Alternate Operations • Testing
Operational template • Complete owners, recovery targets, suppliers, credentials and alternate procedures before approval. A backup is not a recovery plan until restoration and business operation have been tested.
1. Plan Ownership and Emergency Contacts
| Role / Contact | Primary | Alternate / Details |
| --- | --- | --- |
| Plan Owner | | |
| Executive Sponsor | | |
| Disaster Recovery Lead | | |
| Business Continuity Lead | | |
| CSI Recovery Contact | | |
| Facilities / Safety | | |
| ISP / Telecom | | |
| Cloud / Data Centre | | |
| Server / Software Vendor | | |
| Backup Provider | | |
| Cyber Insurer | | |
| Alternate Site Contact | | |
1. Purpose, Scope and Disaster Declaration
- Covers loss or severe degradation of approved premises, people, power, internet, server, network, storage, cloud, application, data or critical supplier.
- Executive Sponsor or named alternate declares a disaster when normal incident handling cannot meet the required business recovery objective.
- Life safety and lawful instructions take priority. Recovery staff must not enter unsafe premises or restore compromised systems without security clearance.
- This plan coordinates with the Incident Response Plan; cyber incidents require containment and clean-recovery validation before service restoration.
| Declaration Control | Approved Detail |
| --- | --- |
| Disaster declaration authority | |
| Plan activation channel | |
| Primary assembly / bridge | |
| Alternate work/site | |
| Maximum tolerable outage | |
1. Business Impact and Recovery Priority
| Priority | Impact | Target Window | Response |
| --- | --- | --- | --- |
| Priority 1 / Critical | Business stops or legal/safety impact | 0–4 hours | Immediate recovery team |
| Priority 2 / Essential | Major operations impaired | 4–24 hours | Recover after P1 dependencies |
| Priority 3 / Important | Workaround available briefly | 1–3 days | Scheduled recovery |
| Priority 4 / Deferrable | Limited short-term impact | 3+ days | Recover after core services |
1. Critical System Recovery Register
| No. | Business Service / System | Priority | RPO | RTO | Owner | Dependencies | Recovery Method |
| --- | --- | --- | --- | --- | --- | --- | --- |
| 1 | | ☐ P1 ☐ P2 ☐ P3 ☐ P4 | | | | | |
| 2 | | ☐ P1 ☐ P2 ☐ P3 ☐ P4 | | | | | |
| 3 | | ☐ P1 ☐ P2 ☐ P3 ☐ P4 | | | | | |
| 4 | | ☐ P1 ☐ P2 ☐ P3 ☐ P4 | | | | | |
| 5 | | ☐ P1 ☐ P2 ☐ P3 ☐ P4 | | | | | |
| 6 | | ☐ P1 ☐ P2 ☐ P3 ☐ P4 | | | | | |
| 7 | | ☐ P1 ☐ P2 ☐ P3 ☐ P4 | | | | | |
| 8 | | ☐ P1 ☐ P2 ☐ P3 ☐ P4 | | | | | |
| 9 | | ☐ P1 ☐ P2 ☐ P3 ☐ P4 | | | | | |
| 10 | | ☐ P1 ☐ P2 ☐ P3 ☐ P4 | | | | | |
1. Dependency and Resource Register
| Dependency | Requirement | Owner / Evidence |
| --- | --- | --- |
| People / skills | Named primary and alternate recovery staff | |
| Premises | Primary site, alternate site, safe access | |
| Power / UPS | Runtime, generator, fuel and shutdown | |
| Internet / WAN | Primary, secondary, failover and contacts | |
| Identity / DNS / time | AD/Entra, MFA, DNS, NTP and break-glass | |
| Hardware / spares | Server, firewall, switches, laptops, storage | |
| Software / licences | Install media, keys, vendor portal and support | |
| Data / backups | Repositories, encryption keys, retention | |
| Suppliers | ISP, cloud, OEM, logistics and escalation | |
1. Disaster Scenarios and Initial Actions
| Scenario | Immediate Actions |
| --- | --- |
| Power / premises unavailable | Ensure safety; controlled shutdown; activate alternate work/site; assess duration |
| ISP / WAN outage | Confirm carrier; fail over secondary link; prioritise critical traffic |
| Server / storage failure | Preserve evidence/config; invoke warranty/spare; restore according to priority |
| Ransomware / cyber compromise | Activate incident response; isolate; protect backups; rebuild clean |
| Cloud / SaaS outage | Check vendor status; activate manual/export workaround; monitor recovery |
| Data corruption / deletion | Stop writes if necessary; identify recovery point; restore to alternate path and validate |
| Loss of staff / supplier | Activate alternates; secure access; invoke documented vendor escalation |
1. Recovery Strategy
- Use preventive controls: UPS, redundant links, supported hardware, spares, monitoring, patching, capacity and tested backups.
- Maintain one recovery method for every P1/P2 service: failover, rebuild, restore, alternate SaaS, spare equipment or documented manual process.
- Keep recovery documentation, contacts, configuration, licences and essential credentials available offline and securely.
- Define minimum business service—not only server startup—for each recovery target.
- Do not rely on a single site, account, administrator, ISP, storage system or untested cloud sync.
1. Activation and Recovery Sequence
| Step | Required Action |
| --- | --- |
| 1. Declare | Confirm event, safety, severity, authority and plan activation |
| 2. Stabilise | Stop further damage; coordinate incident response; protect people/data/backups |
| 3. Assess | Scope outage, dependencies, recovery options, estimated time and business impact |
| 4. Prioritise | Approve recovery order and acceptable data gap/workaround |
| 5. Recover foundation | Power, connectivity, identity, DNS/time, security and storage |
| 6. Recover services | Restore P1 then P2/P3 systems with dependencies |
| 7. Validate | Technical checks plus business-owner data/function approval |
| 8. Communicate | Status, limitations, user instructions and next update |
| 9. Normalise | Return, reconcile manual data, monitor and close |
| 10. Improve | Review evidence, cost, gaps and corrective actions |
1. Server, Network, Cloud and User Recovery
- Servers/VMs: clean hardware/hypervisor, trusted build, patched OS, identity/DNS, applications, data and monitoring in dependency order.
- Network: restore firewall/router/switch/AP from approved configurations; verify WAN, VLAN, VPN, DNS and security logging.
- Cloud/SaaS: use vendor escalation and status; verify identity, MFA, configuration, data and integration before users return.
- Endpoints: issue clean spare/rebuilt devices to priority staff; avoid reconnecting unverified systems.
- Printing/telephony/CCTV/IoT: recover according to business priority and security segmentation.
1. Alternate Work and Manual Procedures
- Define alternate workplace, remote-work authority, minimum laptops, secure internet/VPN and contact method.
- Maintain manual forms/process for critical orders, payments, approvals, customer contact and service records.
- Record every manual transaction with owner/time so it can be reconciled after system recovery.
- Do not use personal email, unapproved cloud storage or uncontrolled messaging for sensitive business data.
- Specify maximum duration of each workaround and trigger for escalation or site relocation.
1. Backup, Restore and Data Validation
- Verify latest successful jobs, off-site/isolated copy, encryption keys and repository health.
- Select recovery point based on incident time, integrity and approved RPO—not merely the newest copy.
- Restore into isolated/alternate location first where compromise or corruption is possible.
- Validate file/database/application integrity and obtain data-owner approval.
- Document missing transactions and reconcile manual/alternate records after return.
- Keep evidence of quarterly partial/full restore tests and annual DR exercise.
1. Communications and Supplier Coordination
| Communication / Supplier Item | Approved Detail |
| --- | --- |
| Employee status channel | |
| Client/vendor status channel | |
| Executive update frequency | |
| ISP/cloud/OEM escalation | |
| Media/public spokesperson | |
1. Return to Normal Operations
- Confirm incident cause is controlled, facilities safe and primary infrastructure stable.
- Approve cutback window, rollback plan, data synchronisation and user communication.
- Back up the recovered/alternate environment before migration.
- Reconcile transactions, changes and files created during manual or alternate operation.
- Monitor performance, security, backups and integrations during heightened observation.
- Business owners sign service and data validation; close only after open risks have owners.
1. Testing, Training and Maintenance
| Test / Review | Frequency | Success Evidence |
| --- | --- | --- |
| Contact-tree test | Quarterly | All contacts reached through approved alternate channel |
| Backup restore test | Quarterly | Selected P1 data/application restored and validated |
| Tabletop exercise | At least annually | Scenario, decisions, communications and gaps recorded |
| Technical DR exercise | Annually / risk based | P1 services meet approved RPO/RTO or gaps tracked |
| Plan review | After major change/incident and at least annually | Contacts, dependencies, vendors and procedures updated |
1. Gaps, Actions and Investment Plan
| No. | Priority | Gap / Required Action | Owner | Budget / QTN | Due | Status |
| --- | --- | --- | --- | --- | --- | --- |
| 1 | ☐ Critical ☐ High ☐ Medium ☐ Low | | | ₹ / QTN- | **/**/__ | ☐ Open ☐ Closed |
| 2 | ☐ Critical ☐ High ☐ Medium ☐ Low | | | ₹ / QTN- | **/**/__ | ☐ Open ☐ Closed |
| 3 | ☐ Critical ☐ High ☐ Medium ☐ Low | | | ₹ / QTN- | **/**/__ | ☐ Open ☐ Closed |
| 4 | ☐ Critical ☐ High ☐ Medium ☐ Low | | | ₹ / QTN- | **/**/__ | ☐ Open ☐ Closed |
| 5 | ☐ Critical ☐ High ☐ Medium ☐ Low | | | ₹ / QTN- | **/**/__ | ☐ Open ☐ Closed |
| 6 | ☐ Critical ☐ High ☐ Medium ☐ Low | | | ₹ / QTN- | **/**/__ | ☐ Open ☐ Closed |
| 7 | ☐ Critical ☐ High ☐ Medium ☐ Low | | | ₹ / QTN- | **/**/__ | ☐ Open ☐ Closed |
| 8 | ☐ Critical ☐ High ☐ Medium ☐ Low | | | ₹ / QTN- | **/**/__ | ☐ Open ☐ Closed |
1. Approval and Sign-off
Approval confirms recovery priorities, targets, authority and resource commitments. Actual recovery depends on incident conditions, people, suppliers, credentials, infrastructure and validated backups.
| Approval Item | Name / Signature / Date |
| --- | --- |
| Client / Company | __ |
| Executive Sponsor | __ |
| DR Lead | __ |
| Business Continuity Lead | __ |
| Cyber Space Infocom Representative | __ |
| Signature & Stamp | __ |
| Effective Date | __ |
Appendix A — Recovery Activity Log
| Time / TZ | Event / Decision / Recovery Action | Owner | Evidence | Next Step |
| --- | --- | --- | --- | --- |
| **/**/__ **:** | | __ | __ | |
| **/**/__ **:** | | __ | __ | |
| **/**/__ **:** | | __ | __ | |
| **/**/__ **:** | | __ | __ | |
| **/**/__ **:** | | __ | __ | |
| **/**/__ **:** | | __ | __ | |
| **/**/__ **:** | | __ | __ | |
| **/**/__ **:** | | __ | __ | |
| **/**/__ **:** | | __ | __ | |
| **/**/__ **:** | | __ | __ | |
| **/**/__ **:** | | __ | __ | |
| **/**/__ **:** | | __ | __ | |
Appendix B — Official References
| Official Reference | URL |
| --- | --- |
| NIST SP 800-34 Rev. 1 | [https://csrc.nist.gov/pubs/sp/800/34/r1/upd1/final](https://csrc.nist.gov/pubs/sp/800/34/r1/upd1/final) |
| NIST SP 800-34 PDF | [https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-34r1.pdf](https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-34r1.pdf) |
| CISA StopRansomware Guide | [https://www.cisa.gov/stopransomware/ransomware-guide](https://www.cisa.gov/stopransomware/ransomware-guide) |
| CISA tabletop exercise packages | [https://www.cisa.gov/resources-tools/services/cisa-tabletop-exercise-packages](https://www.cisa.gov/resources-tools/services/cisa-tabletop-exercise-packages) |
-
ગુજરાતી
| | CYBER SPACE INFOCOM IT Infrastructure • AI • Cyber Security | +91 90547 79647 | | --- | --- |
IT DISASTER RECOVERY અને BUSINESS CONTINUITY PLAN
Business Impact • Recovery Priorities • RPO/RTO • Alternate Operations • Testing
Operational template • Approval પહેલાં owners, recovery targets, suppliers, credentials અને alternate procedures भरो. Backup ત્યાં સુધી recovery plan નથી જ્યાં સુધી restore અને business operation test ન થાય.
- Plan Ownership and Emergency Contacts
Role / Contact Primary Alternate / Details Plan Owner Executive Sponsor Disaster Recovery Lead Business Continuity Lead CSI Recovery Contact Facilities / Safety ISP / Telecom Cloud / Data Centre Server / Software Vendor Backup Provider Cyber Insurer Alternate Site Contact 1. Purpose, Scope and Disaster Declaration - Covers loss or severe degradation of approved premises, people, power, internet, server, network, storage, cloud, application, data or critical supplier. - Executive Sponsor or named alternate declares a disaster when normal incident handling cannot meet the required business recovery objective. - Life safety and lawful instructions take priority. Recovery staff must not enter unsafe premises or restore compromised systems without security clearance. - This plan coordinates with the Incident Response Plan; cyber incidents require containment and clean-recovery validation before service restoration. Declaration Control Approved Detail Disaster declaration authority Plan activation channel Primary assembly / bridge Alternate work/site Maximum tolerable outage 1. Business Impact and Recovery Priority Priority Impact Target Window Response Priority 1 / Critical Business stops or legal/safety impact 0–4 hours Immediate recovery team Priority 2 / Essential Major operations impaired 4–24 hours Recover after P1 dependencies Priority 3 / Important Workaround available briefly 1–3 days Scheduled recovery Priority 4 / Deferrable Limited short-term impact 3+ days Recover after core services 1. Critical System Recovery Register No. Business Service / System Priority RPO RTO Owner Dependencies Recovery Method 1 ☐ P1 ☐ P2 ☐ P3 ☐ P4 2 ☐ P1 ☐ P2 ☐ P3 ☐ P4 3 ☐ P1 ☐ P2 ☐ P3 ☐ P4 4 ☐ P1 ☐ P2 ☐ P3 ☐ P4 5 ☐ P1 ☐ P2 ☐ P3 ☐ P4 6 ☐ P1 ☐ P2 ☐ P3 ☐ P4 7 ☐ P1 ☐ P2 ☐ P3 ☐ P4 8 ☐ P1 ☐ P2 ☐ P3 ☐ P4 9 ☐ P1 ☐ P2 ☐ P3 ☐ P4 10 ☐ P1 ☐ P2 ☐ P3 ☐ P4 1. Dependency and Resource Register Dependency Requirement Owner / Evidence People / skills Named primary and alternate recovery staff Premises Primary site, alternate site, safe access Power / UPS Runtime, generator, fuel and shutdown Internet / WAN Primary, secondary, failover and contacts Identity / DNS / time AD/Entra, MFA, DNS, NTP and break-glass Hardware / spares Server, firewall, switches, laptops, storage Software / licences Install media, keys, vendor portal and support Data / backups Repositories, encryption keys, retention Suppliers ISP, cloud, OEM, logistics and escalation 1. Disaster Scenarios and Initial Actions Scenario Immediate Actions Power / premises unavailable Ensure safety; controlled shutdown; activate alternate work/site; assess duration ISP / WAN outage Confirm carrier; fail over secondary link; prioritise critical traffic Server / storage failure Preserve evidence/config; invoke warranty/spare; restore according to priority Ransomware / cyber compromise Activate incident response; isolate; protect backups; rebuild clean Cloud / SaaS outage Check vendor status; activate manual/export workaround; monitor recovery Data corruption / deletion Stop writes if necessary; identify recovery point; restore to alternate path and validate Loss of staff / supplier Activate alternates; secure access; invoke documented vendor escalation 1. Recovery Strategy - Use preventive controls: UPS, redundant links, supported hardware, spares, monitoring, patching, capacity and tested backups. - Maintain one recovery method for every P1/P2 service: failover, rebuild, restore, alternate SaaS, spare equipment or documented manual process. - Keep recovery documentation, contacts, configuration, licences and essential credentials available offline and securely. - Define minimum business service—not only server startup—for each recovery target. - Do not rely on a single site, account, administrator, ISP, storage system or untested cloud sync. 1. Activation and Recovery Sequence Step Required Action 1. Declare Confirm event, safety, severity, authority and plan activation 2. Stabilise Stop further damage; coordinate incident response; protect people/data/backups 3. Assess Scope outage, dependencies, recovery options, estimated time and business impact 4. Prioritise Approve recovery order and acceptable data gap/workaround 5. Recover foundation Power, connectivity, identity, DNS/time, security and storage 6. Recover services Restore P1 then P2/P3 systems with dependencies 7. Validate Technical checks plus business-owner data/function approval 8. Communicate Status, limitations, user instructions and next update 9. Normalise Return, reconcile manual data, monitor and close 10. Improve Review evidence, cost, gaps and corrective actions 1. Server, Network, Cloud and User Recovery - Servers/VMs: clean hardware/hypervisor, trusted build, patched OS, identity/DNS, applications, data and monitoring in dependency order. - Network: restore firewall/router/switch/AP from approved configurations; verify WAN, VLAN, VPN, DNS and security logging. - Cloud/SaaS: use vendor escalation and status; verify identity, MFA, configuration, data and integration before users return. - Endpoints: issue clean spare/rebuilt devices to priority staff; avoid reconnecting unverified systems. - Printing/telephony/CCTV/IoT: recover according to business priority and security segmentation. 1. Alternate Work and Manual Procedures - Define alternate workplace, remote-work authority, minimum laptops, secure internet/VPN and contact method. - Maintain manual forms/process for critical orders, payments, approvals, customer contact and service records. - Record every manual transaction with owner/time so it can be reconciled after system recovery. - Do not use personal email, unapproved cloud storage or uncontrolled messaging for sensitive business data. - Specify maximum duration of each workaround and trigger for escalation or site relocation. 1. Backup, Restore and Data Validation - Verify latest successful jobs, off-site/isolated copy, encryption keys and repository health. - Select recovery point based on incident time, integrity and approved RPO—not merely the newest copy. - Restore into isolated/alternate location first where compromise or corruption is possible. - Validate file/database/application integrity and obtain data-owner approval. - Document missing transactions and reconcile manual/alternate records after return. - Keep evidence of quarterly partial/full restore tests and annual DR exercise. 1. Communications and Supplier Coordination Communication / Supplier Item Approved Detail Employee status channel Client/vendor status channel Executive update frequency ISP/cloud/OEM escalation Media/public spokesperson 1. Return to Normal Operations - Confirm incident cause is controlled, facilities safe and primary infrastructure stable. - Approve cutback window, rollback plan, data synchronisation and user communication. - Back up the recovered/alternate environment before migration. - Reconcile transactions, changes and files created during manual or alternate operation. - Monitor performance, security, backups and integrations during heightened observation. - Business owners sign service and data validation; close only after open risks have owners. 1. Testing, Training and Maintenance Test / Review Frequency Success Evidence Contact-tree test Quarterly All contacts reached through approved alternate channel Backup restore test Quarterly Selected P1 data/application restored and validated Tabletop exercise At least annually Scenario, decisions, communications and gaps recorded Technical DR exercise Annually / risk based P1 services meet approved RPO/RTO or gaps tracked Plan review After major change/incident and at least annually Contacts, dependencies, vendors and procedures updated 1. Gaps, Actions and Investment Plan No. Priority Gap / Required Action Owner Budget / QTN Due Status 1 ☐ Critical ☐ High ☐ Medium ☐ Low ₹ / QTN- //__ ☐ Open ☐ Closed 2 ☐ Critical ☐ High ☐ Medium ☐ Low ₹ / QTN- //__ ☐ Open ☐ Closed 3 ☐ Critical ☐ High ☐ Medium ☐ Low ₹ / QTN- //__ ☐ Open ☐ Closed 4 ☐ Critical ☐ High ☐ Medium ☐ Low ₹ / QTN- //__ ☐ Open ☐ Closed 5 ☐ Critical ☐ High ☐ Medium ☐ Low ₹ / QTN- //__ ☐ Open ☐ Closed 6 ☐ Critical ☐ High ☐ Medium ☐ Low ₹ / QTN- //__ ☐ Open ☐ Closed 7 ☐ Critical ☐ High ☐ Medium ☐ Low ₹ / QTN- //__ ☐ Open ☐ Closed 8 ☐ Critical ☐ High ☐ Medium ☐ Low ₹ / QTN- //__ ☐ Open ☐ Closed 1. Approval and Sign-off Approval confirms recovery priorities, targets, authority and resource commitments. Actual recovery depends on incident conditions, people, suppliers, credentials, infrastructure and validated backups.
Approval Item Name / Signature / Date Client / Company __ Executive Sponsor __ DR Lead __ Business Continuity Lead __ Cyber Space Infocom Representative __ Signature & Stamp __ Effective Date __ Appendix A — Recovery Activity Log
Time / TZ Event / Decision / Recovery Action Owner Evidence Next Step //__ : __ __ //__ : __ __ //__ : __ __ //__ : __ __ //__ : __ __ //__ : __ __ //__ : __ __ //__ : __ __ //__ : __ __ //__ : __ __ //__ : __ __ //__ : __ __ Appendix B — Official References
Official Reference URL NIST SP 800-34 Rev. 1 https://csrc.nist.gov/pubs/sp/800/34/r1/upd1/final NIST SP 800-34 PDF https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-34r1.pdf CISA StopRansomware Guide https://www.cisa.gov/stopransomware/ransomware-guide CISA tabletop exercise packages https://www.cisa.gov/resources-tools/services/cisa-tabletop-exercise-packages - हिन्दी | | CYBER SPACE INFOCOM IT Infrastructure • AI • Cyber Security | +91 90547 79647 | | --- | --- |
IT DISASTER RECOVERY और BUSINESS CONTINUITY PLAN
Business Impact • Recovery Priorities • RPO/RTO • Alternate Operations • Testing
Operational template • Approval से पहले owners, recovery targets, suppliers, credentials और alternate procedures भरें। Backup तब तक recovery plan नहीं है जब तक restore और business operation test न हो।
- Plan Ownership and Emergency Contacts
Role / Contact Primary Alternate / Details Plan Owner Executive Sponsor Disaster Recovery Lead Business Continuity Lead CSI Recovery Contact Facilities / Safety ISP / Telecom Cloud / Data Centre Server / Software Vendor Backup Provider Cyber Insurer Alternate Site Contact 1. Purpose, Scope and Disaster Declaration - Covers loss or severe degradation of approved premises, people, power, internet, server, network, storage, cloud, application, data or critical supplier. - Executive Sponsor or named alternate declares a disaster when normal incident handling cannot meet the required business recovery objective. - Life safety and lawful instructions take priority. Recovery staff must not enter unsafe premises or restore compromised systems without security clearance. - This plan coordinates with the Incident Response Plan; cyber incidents require containment and clean-recovery validation before service restoration. Declaration Control Approved Detail Disaster declaration authority Plan activation channel Primary assembly / bridge Alternate work/site Maximum tolerable outage 1. Business Impact and Recovery Priority Priority Impact Target Window Response Priority 1 / Critical Business stops or legal/safety impact 0–4 hours Immediate recovery team Priority 2 / Essential Major operations impaired 4–24 hours Recover after P1 dependencies Priority 3 / Important Workaround available briefly 1–3 days Scheduled recovery Priority 4 / Deferrable Limited short-term impact 3+ days Recover after core services 1. Critical System Recovery Register No. Business Service / System Priority RPO RTO Owner Dependencies Recovery Method 1 ☐ P1 ☐ P2 ☐ P3 ☐ P4 2 ☐ P1 ☐ P2 ☐ P3 ☐ P4 3 ☐ P1 ☐ P2 ☐ P3 ☐ P4 4 ☐ P1 ☐ P2 ☐ P3 ☐ P4 5 ☐ P1 ☐ P2 ☐ P3 ☐ P4 6 ☐ P1 ☐ P2 ☐ P3 ☐ P4 7 ☐ P1 ☐ P2 ☐ P3 ☐ P4 8 ☐ P1 ☐ P2 ☐ P3 ☐ P4 9 ☐ P1 ☐ P2 ☐ P3 ☐ P4 10 ☐ P1 ☐ P2 ☐ P3 ☐ P4 1. Dependency and Resource Register Dependency Requirement Owner / Evidence People / skills Named primary and alternate recovery staff Premises Primary site, alternate site, safe access Power / UPS Runtime, generator, fuel and shutdown Internet / WAN Primary, secondary, failover and contacts Identity / DNS / time AD/Entra, MFA, DNS, NTP and break-glass Hardware / spares Server, firewall, switches, laptops, storage Software / licences Install media, keys, vendor portal and support Data / backups Repositories, encryption keys, retention Suppliers ISP, cloud, OEM, logistics and escalation 1. Disaster Scenarios and Initial Actions Scenario Immediate Actions Power / premises unavailable Ensure safety; controlled shutdown; activate alternate work/site; assess duration ISP / WAN outage Confirm carrier; fail over secondary link; prioritise critical traffic Server / storage failure Preserve evidence/config; invoke warranty/spare; restore according to priority Ransomware / cyber compromise Activate incident response; isolate; protect backups; rebuild clean Cloud / SaaS outage Check vendor status; activate manual/export workaround; monitor recovery Data corruption / deletion Stop writes if necessary; identify recovery point; restore to alternate path and validate Loss of staff / supplier Activate alternates; secure access; invoke documented vendor escalation 1. Recovery Strategy - Use preventive controls: UPS, redundant links, supported hardware, spares, monitoring, patching, capacity and tested backups. - Maintain one recovery method for every P1/P2 service: failover, rebuild, restore, alternate SaaS, spare equipment or documented manual process. - Keep recovery documentation, contacts, configuration, licences and essential credentials available offline and securely. - Define minimum business service—not only server startup—for each recovery target. - Do not rely on a single site, account, administrator, ISP, storage system or untested cloud sync. 1. Activation and Recovery Sequence Step Required Action 1. Declare Confirm event, safety, severity, authority and plan activation 2. Stabilise Stop further damage; coordinate incident response; protect people/data/backups 3. Assess Scope outage, dependencies, recovery options, estimated time and business impact 4. Prioritise Approve recovery order and acceptable data gap/workaround 5. Recover foundation Power, connectivity, identity, DNS/time, security and storage 6. Recover services Restore P1 then P2/P3 systems with dependencies 7. Validate Technical checks plus business-owner data/function approval 8. Communicate Status, limitations, user instructions and next update 9. Normalise Return, reconcile manual data, monitor and close 10. Improve Review evidence, cost, gaps and corrective actions 1. Server, Network, Cloud and User Recovery - Servers/VMs: clean hardware/hypervisor, trusted build, patched OS, identity/DNS, applications, data and monitoring in dependency order. - Network: restore firewall/router/switch/AP from approved configurations; verify WAN, VLAN, VPN, DNS and security logging. - Cloud/SaaS: use vendor escalation and status; verify identity, MFA, configuration, data and integration before users return. - Endpoints: issue clean spare/rebuilt devices to priority staff; avoid reconnecting unverified systems. - Printing/telephony/CCTV/IoT: recover according to business priority and security segmentation. 1. Alternate Work and Manual Procedures - Define alternate workplace, remote-work authority, minimum laptops, secure internet/VPN and contact method. - Maintain manual forms/process for critical orders, payments, approvals, customer contact and service records. - Record every manual transaction with owner/time so it can be reconciled after system recovery. - Do not use personal email, unapproved cloud storage or uncontrolled messaging for sensitive business data. - Specify maximum duration of each workaround and trigger for escalation or site relocation. 1. Backup, Restore and Data Validation - Verify latest successful jobs, off-site/isolated copy, encryption keys and repository health. - Select recovery point based on incident time, integrity and approved RPO—not merely the newest copy. - Restore into isolated/alternate location first where compromise or corruption is possible. - Validate file/database/application integrity and obtain data-owner approval. - Document missing transactions and reconcile manual/alternate records after return. - Keep evidence of quarterly partial/full restore tests and annual DR exercise. 1. Communications and Supplier Coordination Communication / Supplier Item Approved Detail Employee status channel Client/vendor status channel Executive update frequency ISP/cloud/OEM escalation Media/public spokesperson 1. Return to Normal Operations - Confirm incident cause is controlled, facilities safe and primary infrastructure stable. - Approve cutback window, rollback plan, data synchronisation and user communication. - Back up the recovered/alternate environment before migration. - Reconcile transactions, changes and files created during manual or alternate operation. - Monitor performance, security, backups and integrations during heightened observation. - Business owners sign service and data validation; close only after open risks have owners. 1. Testing, Training and Maintenance Test / Review Frequency Success Evidence Contact-tree test Quarterly All contacts reached through approved alternate channel Backup restore test Quarterly Selected P1 data/application restored and validated Tabletop exercise At least annually Scenario, decisions, communications and gaps recorded Technical DR exercise Annually / risk based P1 services meet approved RPO/RTO or gaps tracked Plan review After major change/incident and at least annually Contacts, dependencies, vendors and procedures updated 1. Gaps, Actions and Investment Plan No. Priority Gap / Required Action Owner Budget / QTN Due Status 1 ☐ Critical ☐ High ☐ Medium ☐ Low ₹ / QTN- //__ ☐ Open ☐ Closed 2 ☐ Critical ☐ High ☐ Medium ☐ Low ₹ / QTN- //__ ☐ Open ☐ Closed 3 ☐ Critical ☐ High ☐ Medium ☐ Low ₹ / QTN- //__ ☐ Open ☐ Closed 4 ☐ Critical ☐ High ☐ Medium ☐ Low ₹ / QTN- //__ ☐ Open ☐ Closed 5 ☐ Critical ☐ High ☐ Medium ☐ Low ₹ / QTN- //__ ☐ Open ☐ Closed 6 ☐ Critical ☐ High ☐ Medium ☐ Low ₹ / QTN- //__ ☐ Open ☐ Closed 7 ☐ Critical ☐ High ☐ Medium ☐ Low ₹ / QTN- //__ ☐ Open ☐ Closed 8 ☐ Critical ☐ High ☐ Medium ☐ Low ₹ / QTN- //__ ☐ Open ☐ Closed 1. Approval and Sign-off Approval confirms recovery priorities, targets, authority and resource commitments. Actual recovery depends on incident conditions, people, suppliers, credentials, infrastructure and validated backups.
Approval Item Name / Signature / Date Client / Company __ Executive Sponsor __ DR Lead __ Business Continuity Lead __ Cyber Space Infocom Representative __ Signature & Stamp __ Effective Date __ Appendix A — Recovery Activity Log
Time / TZ Event / Decision / Recovery Action Owner Evidence Next Step //__ : __ __ //__ : __ __ //__ : __ __ //__ : __ __ //__ : __ __ //__ : __ __ //__ : __ __ //__ : __ __ //__ : __ __ //__ : __ __ //__ : __ __ //__ : __ __ Appendix B — Official References
Official Reference URL NIST SP 800-34 Rev. 1 https://csrc.nist.gov/pubs/sp/800/34/r1/upd1/final NIST SP 800-34 PDF https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-34r1.pdf CISA StopRansomware Guide https://www.cisa.gov/stopransomware/ransomware-guide CISA tabletop exercise packages https://www.cisa.gov/resources-tools/services/cisa-tabletop-exercise-packages