DEPARTMENT OF THIRD PARTY REVIEW
WILLIAM G. HOLLAND Iles Park Plaza |
INTRODUCTION
|
ILLINOIS DEPARTMENT OF CENTRAL MANAGEMENT
SERVICES
BUREAU OF COMMUNICATION AND COMPUTER SERVICES
STATISTICS |
1997 |
||||||||||||||||||||||||
Mainframes |
|
||||||||||||||||||||||||
Services/Workload |
|
||||||||||||||||||||||||
State Agencu Users |
|
||||||||||||||||||||||||
CCF Employees |
|
||||||||||||||||||||||||
Historical Growth Trend* |
* In the month of January for each year listed |
Information provided by the Department
AGENCY DIRECTOR AND BUREAU MANAGER |
During Audit period:
Director: Michael Schwartz -- Bureau Manager: William
Vetter |
Statewide Critical Application List
Comprehensive test of DRP has not been conducted
Department concurs with recommendation |
FINDINGS,
CONCLUSIONS, AND DISASTER CONTINGENCY PLAN WEAKNESSES The Department has a written disaster contingency plan, the CMS/BCCS/CCF Disaster Recovery Plan (DRP), dated August 1996. The DRP is currently being updated and is expected to be distributed during July 1997. Although the Department has made great progress in addressing the disaster recovery needs of the State's Central Computer Facility, the plan and operational provisions still need to be enhanced. The primary backup site is the Harris facility in Springfield; a secondary backup facility is located in Chicago. The primary site was upgraded during the audit period and has significantly more processing and data storage capacity. The Department worked with user agencies and developed a prioritized Statewide Critical Application Priority List. The Department asked agencies to place their applications in one of five categories. The Department concluded that Category 1 (Human Safety) applications would constitute the critical applications that would be recovered in the event of a disaster. There were only 4 agencies who reported Category 1 critical applications; 11 such applications were identified. The Department plans to perform individual and consolidated tests of Category 1 applications to evaluate the primary backup site. The Department plans to perform the tests in the first half of Fiscal Year 1998 and intends to restore only the applications in Category 1. A comprehensive test of the DRP has never been conducted. A comprehensive test helps verify that the plan is viable, determines that the processing and storage capacity at the alternative site is appropriate, and educates staff on disaster recovery procedures. The State is placing great reliance on the Department's ability to deliver data processing services in the event of a disaster. The development of a comprehensive and tested Disaster Recovery Plan reduces the risks and helps ensure that all critical computer processing needs are adequately addressed. A comprehensive and thoroughly tested disaster recovery plan and adequate backup facilities are essential components of recovery efforts. (revised Finding first reported in 1986) Recommendation
Department Response In a disaster, the first applications to be recovered will be Category 1, but recovery will continue through Category 2 and further through all applications, as resources will allow. It is estimated that at least Categories 1-3 will be recovered, while additional resources are identified to reposition the State after a disaster, to handle all processing. AUDITORS' OPINION Procedures were generally sufficient to provide reasonable, but not absolute, assurance that relevant general and application control objectives were achieved.
WGH:WJS:ag |