The Disaster Recovery Institute International (DRII) associates eight tasks with the
contingency planning process [11]. They are as follows:
• Business impact analysis, to analyze the impact of outage on critical business
function operations.
• Risk assessment, to assess the risks to the current infrastructure and the incorporation
of safeguards to reduce the likelihood and impact of disasters.
• Recovery strategy identification, to develop a variety of disaster scenarios and
identify recovery strategies.
• Recovery strategy selection, to select the appropriate recovery strategies based on the
perceived threats and the time needed to recover.
• Contingency plan development, to document the processes, equipment, and facilities
required to restore the IT assets.
• User training, to develop training programs to enable all affected users to perform
their tasks.
• Plan verification, for accuracy and adequacy.
• Plan maintenance, for continuous upkeep of the plan as needs change.
Processes for IT Security Governance Planning
IT security governance planning includes prioritization as its major function. This helps in
utilizing the limited resources of the organization. Determining priorities among the potential
conflicting interests is the main focus of these processes. This task includes budget setting,