(270) 506-5140 CONTACT US
Business Continuity / Disaster Recovery

Differences Between a Vendor's Disaster Recovery and Business Continuity Plans

Jul 10, 2019 by Ben Koons

The assumption that disaster recover plans and business continuity plans are the same thing is a common misconception. While they are closely intertwined, they’re not the same.

A business continuity plan (BCP) is an organization’s plan(s) that is developed to ensure key operations, products and services will be delivered at a predetermined or acceptable level of availability should a business disrupting event occur. A disaster recovery plan (DRP) is a subset of business continuity and outlines the organization’s anticipated, immediate response and procedures that they’ll follow if they experience a business disrupting event in order to resume normal operations.

Key Differences Between Vendor’s Disaster Recovery and Business Continuity Plans

Here are six additional key differences:

  1. Strategic Objectives vs. Calculated Plans - BCPs are strategic objectives. DRPs are calculated plans.

  1. Business Resiliency vs. Resuming Operations - BCPs attempt to avoid business interruptions by proactively implementing plans and controls designed to increase the business’s resiliency to potential disaster scenarios outlined in the BCP. DRPs guide disaster recovery personnel in reacting and responding to events that transcend the BCP and in recovering the organization’s people, facilities and systems to normal operations.

  1. BCP Focus - BCPs focus on the following:
    • Risk assessment
    • Preventive controls
    • Succession planning
    • Planning with public entities such as emergency services, local or state disaster relief agencies
    • Communications with identified key vendors, clients, employees and the media

  1. DRP Focus - DRPs focus on the following:
    • Gathering of disaster recovery personnel at the command center
    • Deciding if the incident is a disaster
    • Salvage operations, recovery operations, communications, restoration to normal operations

  1. BCP Components - Your vendor’s BCP should include the following 13 components:
    • Business impact analysis
    • Personnel loss planning
    • Relocations plans
    • Remote access availability
    • Facility loss contingencies
    • Pandemic contingencies
    • Breach/disruption notification procedures
    • Testing procedures
    • Copies of the plan are held off-site in secure locations and available
    • Plan is reviewed, tested and updated regularly
    • Senior management and board approval
    • SLAs and contractual obligations
    • Failover and backup locations

  1. DRP Components - Your vendor’s DRP should include the following six components:
    • Dedicated team and individuals
    • Testing and updates
    • Notification process
    • Backup procedures
    • Procedures for personnel and system recovery to normal operations
    • Senior management/board approval and involvement

As you can see, BCPs and DRPs are closely related but serve distinct purposes. Both are critical to ensuring that a business safeguards its personnel and its ability to meet contractual obligations to customers.

Dive deeper into business continuity planning with your vendors. Download the infographic. 

Vendor Business Continuity for Third Parties

Ben Koons

Written by Ben Koons

Ben has paired a Bachelor’s degree with technical degrees in Information Systems Management and Network Administration and Engineering. His experience as a Systems Administrator for a call center servicing financial clients and Network Engineer at a state university has given him extensive knowledge of server and network security, as well as data center architecture and controls. In addition to his education and experience, Ben has several relevant certifications, including Associate Business Continuity Professional (ABCP) and Cisco Certified Network Administrator (CCNA).

Follow Ben Koons

Subscribe to the Venminder Blog