Business Challenge
California State agencies face increasing challenges in maintaining operational resilience amidst technological reliance and evolving threats. To comply with the stringent standards outlined in the Statewide Information Management Manual (SIMM) by the California Department of Technology (CDT), agencies must submit detailed documentation annually, which closely aligns with requirements set by the California Office of Emergency Services (CalOES).One California State agency enlisted Radian Solutions to design and implement a Disaster Recovery (DR) and Business Continuity Plan (BCP) program. The goal was to enhance the agency's preparedness, response capabilities, and recovery efficiency while ensuring compliance with SIMM standards and minimizing operational disruptions.
Proposed Solution
Radian Solutions adopted a phased approach to develop a robust and sustainable DR/BCP program:Phase I: Foundation and SharePoint Development
- Current State Analysis: Reviewed the agency’s organizational structure, existing BCP, and Technical Recovery Plan (TRP) to identify opportunities for improvement.
- SharePoint Site Development: Leveraged the agency’s Office 365 SharePoint environment to build a centralized, accessible, and secure platform. Key features included:
- Communication Tools: Employee and facility check-ins, announcements, and event discussion forums.
- Leadership Resources: All-hazard event checklists and emergency procedure libraries.
- Program Management Tools: Risk assessment tools, business impact analysis (BIA) summaries, event tracking, and change management tools.
- Access Control and Resiliency: Hosted the platform outside the Sacramento region to ensure accessibility during emergencies.
Phase II: Team-Specific Customization
- Conducted team workshops to integrate existing documents, collect risk assessments, and identify critical business processes.
- Developed tailored sub-sites and playbooks for individual teams, addressing their unique operational needs.
- Delivered training on continuous improvement practices.
- Created summary reports detailing Recovery Time Objectives (RTO), Recovery Point Objectives (RPO), and Maximum Tolerable Periods of Disruption (MTPD) for integration with TRPs.
- Provided an executive summary with a gap analysis and budget recommendations.
Phase III: Annual Compliance and Exercises
- Disaster Recovery Exercises:
- Conducted technology drills to validate RTOs and RPOs, refine procedures, and identify improvement areas.
- Facilitated tabletop exercises to simulate real-world scenarios, document lessons learned, and improve readiness.
- Regulatory Submissions:
- Assisted in preparing annual CDT and CalOES documentation, applying updated templates and addressing feedback from prior submissions.
Phase IV: Continuous Improvement
- Improve & Automate Data Collection Process: Identify opportunities to further enhance, automate, and simplify the data collection process. This includes providing additional training to projects on updating their BCP documents, fine-tuning communication strategies, automating the data collection process, and automating the BCP documents update process where possible.
- Update & Add New BCP Data and Documents: Build upon the BCP SharePoint Site created during the previous phases with enhanced site design and management based on exercises, staff, CDT, and CalOES feedback.
- Radian team worked with relevant divisions to create new policies as needed, fulfilling requirements from CalOES and CDT and the most current best practices.
- Improved SharePoint site design based on feedback from exercises and regulatory reviews.
- Mature Self-Services Features: Radian Solutions focused on enhancing the maturity of self-services features, making the BCP process more efficient, automated, and aligned with the evolving needs of the BCP program. Additionally, Radian team also offered training sessions to guide State staff on managing their data updates and data submission tasks.
- Knowledge Transfer and Training: Provide guidance to State staff on Disaster Recovery best practices, conduct knowledge transfer sessions with BCP program participants and staff, and document residual tasks for future BCP process improvement and SharePoint site improvements.
- Set up a repeat process of exercise, review, updates, improvements, and regulatory compliance submission.
Benefits and Impact
The implementation and maturation of the DR/BCP program delivered the following benefits:- Empowerment: Enabled teams to independently manage and update BCP documents, increasing accountability.
- Efficiency: Streamlined the update process, saving time and resources.
- Accuracy: Reduced errors by ensuring data updates were made by knowledgeable personnel.
- Time Savings: Automated repetitive tasks, allowing staff to focus on strategic initiatives.
- Consistency: Maintained uniformity across all BCP documents.
- Real-Time Updates: Ensured BCP documents were current and accurate at all times.
These features and enhancements create a more efficient, effective, and user-friendly BCP process. They enable team members to take ownership of their BCP data, streamline routine tasks to save time and minimize errors, and simplify compliance with annual regulatory requirements. Ultimately, these improvements strengthen the organization’s resilience and readiness to handle potential disruptions.
This case study effectively demonstrates Radian Solutions' expertise in creating tailored, scalable DR/BCP programs that address the unique needs of California State agencies