Setting up Disaster Recovery (DR) and Business Continuity Plans (BCP) Centres for IT/ITESSEZs - Guidelines
DISASTER recovery (DR) may be seen as the process, policies and procedures related to preparing for recovery or continuation of technology infrastructure critical to a business organization after a natural or human-induced disaster occurs. Disaster recovery may be seen as a subset of business continuity. While business continuity involves planning for keeping all aspects of a business functioning in the midst of disruptive events, disaster recovery focuses on the IT or technology systems that support business functions.
DR/BCP are essential for businesses today and more especially for IT/ITES businesses. Businesses with no DR/BCP systems i.e. no saved information, no documentation, no backup hardware, and no contingency plan are unable to put into place any recovery time objectives (RTO) which is the duration of time and a service level within which a business process must be restored after a disaster (or disruption) and also are not in a position to assure "recovery point objective" (RPO), which is the maximum tolerable period in which data might be lost from an IT service due to a major incident, to its clients. Such businesses are unable to attract business as all business clients seek assurances on credible RTOs and RPOs, which are written into their business contracts.
Setting up DRC/BCP Centres by SEZ Units :
1. The DRC/BCP location will be approved by the DC, SEZ on an application made by the SEZ unit. Such approval will allow the SEZ unit to relocate its operations, data and employees to the DRC/BCP location upon the occurrence of a disaster. If the DR/BCP location is within another SEZ/EOU, the DC of such SEZ/EOU may also be consulted prior to issue of approval.
2. DR/BCP operations by the unit as well as the list of calamities/events, which are covered under ‘disaster', must be stated and thereafter approved by the DC.
3. A DR/BCP location will be provided with adequate infrastructure including telecommunication links, administrative support systems, data back up and retrieval systems as well as seating/workstations for personnel.
4. On the occurrence of events pre-defined under the category of 'disaster', the unit will not need to seek prior approval of DCs to put into operation the DR/BCP strategy. However, within 48 hours of the DR/BCP being put into operation the unit must intimate the DC, SEZ
5. On the occurrence of a disaster, it will be necessary for the IT SEZs to carry out real time BCP/DRP operations including shifting of data, operations and employees to be shifted and relocated to the DRC/BCP site on a temporary basis, till restoration of operations at the original location. The validity of the relocation will be initially for a period of 90 days and may be extended by DC office and any further extension will be granted based on application to DC office.
6. As this activity is envisaged as a purely internal exercise to be carried out across branches of the same SEZ entity to ensure that business continuity therefore there will be no commercial activity involved and accordingly, no commercial invoice will be raised in such movement of data, operations and employees.
7. Once the DR/BCP has been approved by the DC, SEZ in which the unit is located as well as the DC where the unit is situated may both ensure a seamless transfer of data, operations and personnel as per the terms of the approval. For this purpose, necessary approvals/permissions for carrying out business at the new location, in terms of the DR/BCP approval, may be made available immediately.