1 / 32

The Bank of Korea: Business Continuity Planning

The Bank of Korea: Business Continuity Planning. Table of Contents. Ⅰ . Background. Ⅱ . Backup Center. Ⅲ . Business Continuity Planning. Ⅰ . Background. Information System Architecture Information System Configuration. Accounting System. Information System Architecture. Information

maynardb
Download Presentation

The Bank of Korea: Business Continuity Planning

An Image/Link below is provided (as is) to download presentation Download Policy: Content on the Website is provided to you AS IS for your information and personal use and may not be sold / licensed / shared on other websites without getting consent from its author. Content is provided to you AS IS for your information and personal use only. Download presentation by click this link. While downloading, if for some reason you are not able to download a presentation, the publisher may have deleted the file from their server. During download, if you can't get a presentation, the file might be deleted by the publisher.

E N D

Presentation Transcript


  1. The Bank of Korea: Business Continuity Planning

  2. Table of Contents Ⅰ. Background Ⅱ. Backup Center Ⅲ. Business Continuity Planning

  3. Ⅰ. Background • Information System Architecture • Information System Configuration

  4. Accounting System Information System Architecture Information System Network

  5. Accounting System Accounting System • Deposit & Loan • National Treasury • Securities • International Finance Information System Architecture Information System Network

  6. Information System • Provision of Information Relevant to Monetary Policy • ▶ Diverse Statistical • Reports • Provision of Management Information on Enterprise Information Portal Information System Information System Architecture Accounting System Network

  7. Network • BOKNET • BOK-Wire • Foreign Exchange Network • SWIFT Network Information System Architecture Accounting System Information System

  8. Info SystemServers Foreign ExchangeSystem Servers SWIFT FROMs Tape Mainframe #1 Mainframe #2 Disk Printer Leased Line Leased Line Information System Configuration: Main Center BOK-Wire Servers F/W Switch G/W G/W Switch F/W F/W F/W F/W Router BOK(DR) BOKACCT (Center) Router BOKNET (Informational Network) MOFE 20Mbps * 2 2Mbps*2 Router DJBranch DGBranch 2Mbps*2 KT Dacom Hanaro F/W 2Mbps*2 2Mbps*2 64Kbps 128Kbps KT/Dacom 128Kbps KJBranch BSBranch Clearing House (SWIFT) Commercial Banks FinancialInstitutions Commercial Banks ForeignBanks Modem Internet (xDSL)

  9. II. Backup Center • History • Major Facilities • BOKNET

  10. Feb. 2001 Project Plan Developed in Cooperation with System Integrator Nov. 2001 Opening of Backup Center Jan. 2003 Installation of SWIFT Server for Disaster Recovery Dec. 2004 Upgrade of BOK-Wire Server & CLS System Implementation Aug. 2005 Installation of Advanced Foreign Reserve Management System April 2006 Upgrade of Mainframe System Dec. 2006 Conversion of Network Protocol from X.25 to TCP/IP Aug. 2007 Upgrade of Disk Storage System and Adoption of MSPP Technology History

  11. Major Facilities

  12. Emergency Suburbs of Seoul and Gangwon Branch Office HeadOffice Main Center(Disaster) DaejeonBackupCenter Daegu Busan Gwangju BOKNET Normal Suburbs of Seoul and Gangwon Branch Office E1*2 HeadOffice 4Mbps*2 Main Center E1*2 E1*2 E1*2 20Mbps*2 E1*2 Daejeon Daegu E1*2 E1*2 E1*2 E1*2 E1*2 E1*2 E1*2 Busan Gwangju Wire Wire atDisaster Additional Wire Main Wire Detour Wire

  13. III. Business Continuity Planning • Outline • Disaster Countermeasure Procedure • Trouble Countermeasure Procedure • Trouble Report System • Inter-organization Activity for Disaster • Miscellaneous Issues

  14. Outline Business Continuity Management (2006, Bank of International Settlements) • A whole-of-business approach that includes policies, standards, and procedures for ensuring that specified operations can be maintained or recovered in a timely fashion • Purpose: minimization of the operational, financial, legal, reputational and other material consequences arising from a disruption Business Continuity Plan (2006, Bank of International Settlements) • Component of Business Continuity Management • Comprehensive written plan of action that sets out the procedures and systems necessary to continue or restore the operation of an organization in the event of disruption

  15. Outline Emergency • Disaster: Totally Inoperable IT System • Trouble: IT System in Abnormal Operation Classification of Trouble • A: Significant and Broad ExternalImpact • B: External Impact not as Significant as “A,” but quite Significant • C: Limited ExternalImpact & Significant Internal Impact • D: No External Impact & Limited Internal Impact Classification: A • Total or Critical Trouble with Payment and Settlement System • Total or Critical Trouble with Integrated Communication Network, BOK-Wire, and CLS (Continuous linked settlement) System Network • Critical Trouble with Accounting System

  16. Outline Classification: B • Partial Trouble with Payment and Settlement System • Partial Trouble with Integrated Communication Network and BOK-Wire • Total or Critical Trouble with Foreign Exchange Information System and BOK Home Page Classification: C • Total or Critical Trouble with Internal System such as Integrated Document Management System, MIS, and Economic Statistics System • Trouble with Non-critical Functionalities of Payment and Settlement System • Minor Trouble with Foreign Exchange Information System Classification: D • Trouble with Electronic Library and Business Analysis System of Financial Institution • Minor Trouble with MIS and Integrated Document Management System

  17. 1. Convocation of IT Disaster Countermeasure Committee • ▶ Deputy Governor (Chairman), Director General of IT Department • 2. Report to Governor & Monetary Policy Committee • 3. Transformation of IT Department into Emergency Organization & Highest • Priority assigned to Payment and Settlement Systemincluding BOK-Wire • 4. Switch over to (Daejeon) Backup Center followed by Emergency Operation • & Recovery according to Disaster Recovery Manual in case that Disaster • Recovery at Main Center is judged to be impossible • 5. Switch over to Manual Transaction Processing according to Instruction • Manual in case of totally inoperable (Daejeon) Backup Center • 6. Switch over the (Gangnam) Main Center upon the completion of Main • Center Recovery Disaster Countermeasure Procedure: (Gangnam) Main Center

  18. Disaster Countermeasure Procedure: Walkout □ If the normal system operation by regular IT personnel becomes impossible due to strike, system protection measure including termination of the system access by IT personnel on strike will be implemented. □ The system operation authority will be delegated to substitute IT personnel if necessary. □ Replace regular IT personnel by substitute IT personnel consisting of system maintenance personnel, IT personnel at end user department and retired IT personnel.

  19. Trouble Countermeasure Procedure 1. Recognition & Registration of Trouble: ▶ Trouble Report from End User, Financial Institutions, IT Department ▶ Trouble Status recorded into Trouble Record Book 2. Convocation of IT Disaster Countermeasure Committee & formation of Crisis Management Organization 3. Emergency Measure & Report/Notice ▶Exercise of Emergency Measure in cooperation with Maintenance Company ▶Status Report to Executives, Monetary Policy Committee, Audit Department, relevant Institutions and Media

  20. Trouble Countermeasure Procedure 4. Troubleshooting & Recordkeeping ▶Implementation of Emergency Recovery ▶ Emergency Operation/Recovery at Backup Center if applicable 5. Trouble Termination & Report ▶ Recording of the details of disaster recovery followed by report to executives, user department, participating institutions, relevant institutions, and media upon the trouble termination ▶ Switch over to Main Center from Backup Center if applicable

  21. Trouble Report System BOK-Wire & Accounting System

  22. Trouble Report System Foreign Exchange Information System

  23. Trouble Report System Integrated Document Management System & MIS

  24. Inter-organization Activity for Disaster □ IT Department providing the support centered around IT Issues ▶User department in charge of an interaction with external institutionsincluding government agencies and media ▶Report to the governor regarding the contact with external institutions

  25. Miscellaneous Issues: IT Department □ Disaster Recovery Training for Mainframe System ▶(Monthly) Operation Training ▪ Confirmation of Normal Operation ▶(Quarterly) System Training ▪ Confirmation of Normal Operation ▪ Confirmation of the Data Accuracy ▪ Revision of Disaster/Recovery Manual if applicable ▶(Biyearly) System Training ▪ Participation of Financial Institutions & Government Agencies ▪ Confirmation of Normal Operation ▪ Switch over to Main Center from Backup Center upon the Training Termination □ Disaster Recovery Training for Server System

  26. Miscellaneous Issues: IT Department □ Subsystem Operation/Recovery Manual for Disaster & Subsystem Operation/Recovery Manual for Trouble & Trouble Report System ▶BOK-Wire System ▶Accounting System ▶ Mainframe System ▶ Server System ▶Telecommunication System ▶ Foreign Exchange Information System ▶ BOKIS: BOK Homepage ▶ Economic Statistics System ▶ Integrated Document Management System ▶ Management Information System ▶ (Real-time) Electronic National Treasury Transfer System ▶CLS (Continuous Linked Settlement) System

  27. Miscellaneous Issues: IT Department □ Key Issues: Subsystem Operation/Recovery Manual for Disaster ▶Priority of IT Resources Recovery ▶Cooperation with relevant Departments/Teams □ Key Issues: Subsystem Operation/Recovery Manual for Trouble ▶Trouble Countermeasure Procedure ▪ Identification of Cause ▪ Retention of Trouble Record ▪ Procurement Procedure of Relevant Equipment □ Key Issues: Trouble Report System ▶Roles & Organization of Task Force Team ▶ Emergency Contact Information

  28. Miscellaneous Issues: BOK-Wire BCP

  29. Miscellaneous Issues: BOK-Wire BCP □ Crisis Management Organization ▶Emergency Countermeasure Committee ▪ Deputy Governor (Chairman), Director General of Payment Systems & Treasury Service Department, Director General of IT Department and etc. ▶Emergency Countermeasure Working-level Committee ▪ Payment Systems Management Team Head (Chairman) □ Tasks with Highest Priority □ Detailed Strategies ▶Manpower ▶Communication: Internal, External, Media ▶Telecommunication (for Emergency Center) ▶Facilities: Retention of Emergency Center

  30. Miscellaneous Issues: BOK-Wire BCP Reporting System

  31. Miscellaneous Issues: Future Plan □ Intensification of Disaster Recovery Training (under review) ▶ Present: BOK Backup Center connected to Main Center of Participating Financial Institutions ▶Future: Connection of BOK Backup Center to Backup Center of Participating Financial Institutions □ Diversification of Disaster Recovery Training Scenarios (under review) □ Reinforcement of Backup Center (under review) ▶ Reinforcement of IT Personnel at Backup Center ▶ Site Rotation

  32. Thank you !

More Related