Implement and Optimize an Effective Security Management Metrics Program
Security investments, requiring time and money, are often made without adequate supporting information as to the relative benefit of one investment vs. another.
Many organizations and subject matter experts recognize the difficulty of establishing and maintaining an effective metrics program. This results in an inability to acquire management/leadership support for changes or additions needed for the security technology, policy, and process environment.
In a resource-constrained environment, availability of additional resources for investment will be limited without solid evidence. Metrics allow the organization to understand its current state and highlight unnecessary risks and opportunities to reduce those risks.
Keep your systems dormant until disaster strikes. Prepare as much of your environment as possible without tapping into compute resources. Enjoy the low at-rest costs, and leverage the reliability of the cloud in your failover.
Avoid failure on the failback! Bringing up your systems in the cloud is a great temporary solution, but an expensive long-term strategy. Make sure you have a plan to get back on premises.
Leverage cloud DR as a start for cloud migration. Cloud DR provides a gateway for broader infrastructure lift and shift to cloud IaaS, but this should only be the first phase of a longer-term roadmap that ends in multi-service hybrid cloud.
Impact and Result
Calculate the cost of your DR solution with a cloud vendor. Test your systems often to build out more accurate budgets and to define failover and failback action plans to increase confidence in your capabilities.
Define “good enough” performance by consulting with the business and setting correct expectations for the recovery state.
Dig deeper into the various flavors of cloud-based DR beyond backup and restore, including pilot light, warm standby, and multi-site recovery. Each of these has unique benefits and challenges when done in the cloud.