Disaster recovery as part of business continuity planning

Disaster recovery consists of designing a system for the recovery or continuation of critical business processes and systems, data protection and data recovery in eventuality of natural or human caused disaster, it centers on the IT or technology systems supporting critical functions of any organization.

Disaster recovery planning is essential for an IT system and its core procedures. It is a documented process or set of procedures to recover and protect an organization or system in the event of a disaster. It can also be called a part of larger process known as business continuity planning and includes planning for resumption of applications, data, hardware, electronic communications (such as networking) and other IT infrastructure.

A business continuity plan (BCP) includes planning for non-IT related aspects such as key personnel, facilities, crisis communication and reputation protection, and should refer to the disaster recovery plan (DRP) for IT related infrastructure recovery / continuity.

There are several methods of data protection in an IT driven system such as backups made to tape and sent off-site at regular intervals; backups made to disk on-site and automatically copied to off-site disk, or made directly to off-site disk; replication of data to an off-site location, which overcomes the need to restore the data (only the systems then need to be restored or synchronized), often making use of Storage Area Network (SAN).

Other methods offer private cloud solutions, which replicate the management data (VMs, Templates and disks) into the storage domains which are part of the private cloud setup. These management data are configured as an xml representation called OVF (Open Virtualization Format), and can be restored from the Data Base once a disaster occurs.

Hybrid cloud solutions replicate both on-site and to off-site data centers. These solutions provide the ability to instantly fail-over to local on-site hardware, but in the event of a physical disaster, servers can be brought up in the cloud data centers as well. Examples include Quorom, Cloud from Persistent Systems or Ever Safe.

The use of high availability systems keep both the data and system replicated off-site, enabling continuous access to systems and data, even after a disaster (often associated with Cloud storage) is also in vogue. In many cases, an organization may elect to use an outsourced disaster recovery provider to provide a stand-by site and systems rather than using their own remote facilities, increasingly via Cloud Computing.

Data recovery is a procedure of salvaging inaccessible data from corrupted or damaged storage, removable media or files, when the data they store cannot be accessed in normal way. The data is commonly salvaged from storage media such as internal or external hard disc drives, USB flash drives, magnetic tapes, CDs, DVDs or other electronic devices. Techniques for recovery of data envisage hardware/software repairs or remote data recovery.

Pakistan Customs possesses Disaster Recovery System with capability to replicate vital Customs data in order to ensure its safe storage and security. The primary site of storage of Customs data i.e Data Center is located at  Custom House, Karachi, where Storage Area Network (SAN) , Hi-tech Servers, air conditioning and air purification systems are installed, which ensure that trade transactions are carried out without any disturbance.

The current system for storage and security works on real time basis so that data of a transaction is stored at secure places without any loss in eventuality of any IT disaster. Two types of data replication methodologies are being implemented at the Data Center as (i) SAN-TO-SAN Replication:  This is a service where a centralized repository of stored data is duplicated to another repository on real time basis. This is a three way replication from Data Center Karachi to  Regional Tax Office, Karachi and Data Centre, Federal Board of Revenue,  Islamabad  on block level and on real time basis.

(ii) Structured Query Language (SQL) base Replication: SQL is a special-purpose programming language designed for managing data held in a relational database management system (RDBMS), or for stream processing in a relational data stream management system (RDSMS). This is not a block level replication and solely used to replicate data to multiple destinations but requires a machine to be present at each location.

The various options are being analyzed by FBR for upgrading and modernizing current Disaster Recovery System of Customs operations for further increasing its efficiency and safety.

One option is to relocate primary Data Centre to a nearby Customs Station in order to improve safety and security of data and infrastructure in event of any disaster.  Other options include Cloud Computing Technology as it would be more safe and efficient using a network of remote servers hosted on the internet to store, manage, and process data, rather than a local server; and would provide  storage solutions to FBR and users  with various capabilities to store and process data and information on real time basis.

By Abid Hussain Hakro

Deputy Director

Directorate of Reform & Automation (Pakistan Customs)