Core Infrastructure Assets with initial Impact assessment, i

advertisement
Core Infrastructure Assets with Initial Impact
Assessment, i.e., Possible effects of loss or malfunction
of Asset (V3)
Fibre Optic
Cable Plant
Core Fibre
Ring
Fibre Spurs
Loss or
Malfunction
Cable Fault
Likely
Impact
Nil
Likely
Probability
Unlikely
Cable fault
Unacceptable
Unlikely
Building PDS
Cable fault
High
Unlikely
Warranty
against defect
Leased Circuits Circuit fault
including dark
fibre
Installation and Staff shortage
maintenance
Unacceptable
Unlikely
Maintenance
contracts
Medium
Unlikely
Staff cover
Routers and
Edge devices
Core Router
Loss or
Malfunction
Hardware
failure.
Power failure
Likely
Impact
Unacceptable
Likely
Probability
Likely
Edge Router
Hardware
failure.
Power Failure
High
Likely
Current
Control
Redundancy,
Maintenance
spares,
Maintenance
contract. UPS
Redundancy
Maintenance
spares
Maintenance
contract
Edge devices
switches/hubs
Hardware
failure
Power Failure
Medium
Likely
Maintenance
spares
Recommended
Control
Redundancy,
Maintenance
spares,
Maintenance
contract. UPS
Redundancy
Maintenance
spares
Maintenance
contract, UPS.
Dual Routers
and Dual Paths
Maintenance
spares. UPS
Core Services
Loss or
Malfunction
No routing
service – not
hardware
related
Loss of
Likely
Impact
Unacceptable
Likely
Probability
Unlikely
Unacceptable
Unlikely
Current
Control
High end
Routers and
competent
support staff
Dual
Recommended
Control
High end
Routers and
competent
support staff
Dual
Routing
Service
SuperJANET
Current
Control
Diversely
routed Ring
None
Recommended
Control
Diversely
routed Ring
Alternative
path/circuit
Alternative path
for critical
services
Alternative
circuits where
cost effective
Staff cover
access
SuperJANET
connectivity
Resilient
hardware,
service spares
and
maintenance
contracts
Multiple
platforms,
staff cover
connections
from diverse
locations
Resilient
hardware, UPS.
Service spares
and
maintenance
contracts
Multiple
platforms, staff
cover
Remote Site
interconnect
Failure of
network
services to
remote site
Unacceptable
Unlikely
Network
Management
Failure of
management
systems or
staff shortages
Staff
shortages
Staff
shortages, no
funding
Systems
exposed, no
containment
Medium
Unlikely
High
Unlikely
Staff cover
Staff cover
High
Likely
Staff cover
Staff cover,
secure funding
Unacceptable
Certain
Network
Monitoring
IDS.
System
compromises.
Poor
practices,
Poor security
awareness
No remote
access. No
secure
flexible
access
Unacceptable
Certain
High
Unlikely
DNS
Failure or
degradation in
DNS service
Unacceptable
Unlikely
DHCP/Bootp
Failure or
Medium
degradation of
DHCP/Bootp
Network
Maintenance
Network
Development
Network
security
Information
security
Universal
Access
connections
from JWN
Unlikely
Network
Monitoring
IDS, Network
segmentation
(Funding)
Security team. Security team,
Security
Polices,
Network
segmentation
Robust
remote access
options and
Flexible
access
provision.
Competent
staff
Robust DNS
service based
on multiple
servers.
Robust
service with
competent
Robust remote
access options
and Flexible
access provision
(Expansion
requires
Funding).
Competent staff
Robust DNS
service based
on multiple
servers. Second
SuperJANET
access location
Robust service
with competent
staff. University
Mail servers
and relays
service
Failure or
Unacceptable
degradation of
e-mail
services
Unlikely
staff
Robust
service based
on multiple
servers with
competent
staff
Central E-Mail
Spam and virus
detection
service
Failure of
scanning and
detection
software
High
Unlikely
Robust
service based
on multiple
servers with
competent
staff
WWW Caches
Failure of
proxy service,
Hardware or
software
Unacceptable
Likely
Robust
service based
on multiple
servers and
competent
staff
WWW server
Failure of
hardware or
software
High/Unaccep Likely
table
Single server
competent
staff
Filestore
services
Failure to
access server
or network
filestore
Unacceptable
Likely
Robust
service with
competent
staff but with
single points
of failure
Backup/
Restore service
Failure of
hardware or
software or
Unacceptable
Likely
Backup
regimes are
problematic
security policies
Robust service
based on
multiple servers
with competent
staff. University
security
policies. Need
to address
Exchange
service
Robust service
based on
multiple servers
with competent
staff. University
security
policies.
Robust service
based on
multiple servers
and competent
staff. University
security
policies.
Clustered or
load balanced
solution with
competent staff.
University
security
policies.
Robust service
with server
consolidation
(clustering or
mirroring) SAN
attached
Filestore and
competent staff.
University
security
policies.
Implement high
end SAN/LAN
based backup
limited
backup
window
wrt to volume
of data,
backup
capacity and
backup
window
Multiple print
servers and
printers
Print Services
Failure of
print service
or individual
printers
Medium
Likely
Directory
services
Failure of
hardware or
software
Unacceptable
Unlikely
Robust
services based
on multi
master
replication
Directory
Integration
Failure of
High
meta directory
hardware/
Software,
procedures or
quality of data
Failure of
Unacceptable
SSD backend
infrastructure
Unlikely
Failure of
CSCE
backend
infrastructure
Unlikely
Robust
service based
on multiple
servers and
competent
staff
Robust
service based
on multiple
servers,
directory
service,
network
services, file/
print services
and security
services. Does
have many
single points
of potential
failure thou
Robust
service based
on multiple
servers,
directory
service,
network
Desktop
services for
staff
Desktop
services for
students
Unacceptable
Unlikely
solution
supported by
competent staff
More robust
service with
modern
hardware
(Funding)
Robust services
based on multi
master
replication.
University
security
policies.
Robust service
based on
multiple servers
and competent
staff
Robust service
based on
multiple
servers,
directory
service,
network
services, file/
print services
and security
services.
Eliminate single
points of failure
(Funding)
Robust service
based on
multiple
servers,
directory
service,
network
VLE
Failure of
MOODLE
hardware or
backend
infrastructure
Medium
Unlikely
Video
conferencing
Failure of
video
conferencing/
Video
Teaching
service,
hardware
Unacceptable/
high
Likely
E-science
Access GRID
conferencing
Failure of
hardware/
Software or
multicast
backend
routing
service
Medium
Likely
A/V streaming
service
Failure of
hardware/
Software or
backend
infrastructure
Medium
Likely
Training
services
Staff resources
Staff
shortages
Staff
shortages for
existing
workload. To
Low
Unlikely
High
Likely
services, file/
print services
and security
services. Does
have many
single points
of potential
failure thou
Robust
service based
on multiple
servers.
Would be
prone to
backend
single points
of failure
Service based
on ageing
ATM
technology;
kept going by
expert staff
Robust
service based
on multiple
locations with
competent
staff
monitoring
Multicast
service
Service based
on single
server
managed by
competent
staff
Staff cover
Staff cover
Staff training
services, file/
print services
and security
services.
Eliminate single
points of failure
(Funding)
Robust service
based on
multiple
servers.
Eliminate
backend single
points of failure
(Funding)
Upgrade service
to modern IP
based VC
codecs, with
onsite spares
and
maintenance
contract
Robust service
based on
multiple
locations with
competent staff
monitoring
Multicast
service
Provide Robust
service based
on multiple
servers with
replicated
filestore
Staff cover
Staff cover
Staff training
Knowledge
transfer.
much
dependence
on single
sources of
expertise
Better
documentation
and procedures
Critical
Locations
James Watt
North Building
Loss or
Malfunction
Flood, Fire,
Power or air
conditioning
Likely
Impact
Unacceptable
Likely
Probability
Unlikely
Current
Control
Staff
awareness.
UPS and
standby
Generator
MIS
Flood, Fire,
Power or air
conditioning
Unacceptable
Unlikely
Staff
awareness.
UPS
Library
Flood, Fire,
Power or air
conditioning
Unacceptable
Likely
Staff
awareness.
Some
resilience for
Network
services
Funding
Loss or
Malfunction
Poor retention
and
motivation
Likely
Impact
High
Likely
Probability
Likely
Current
Control
Interesting
work; long
hours
Reduced
budgets
lowering
maintenance
High
Likely
Try and keep
critical
service
elements on
Staff
Maintenance
Recommended
Control
Staff awareness.
UPS and
standby
Generator.
Disaster
recovery site
(Funding)
Staff awareness.
UPS. Disaster
recovery site
(Funding).
Additional
Impact
assessment
covering
specific services
Staff awareness.
Improve
resilience of
network
services.
Additional
Impact
assessment
covering
specific services
Recommended
Control
Staff training
and
achievement
recognition
(Funding)
Ensure critical
service
elements are
covered by
IT strategy
provisions
and increasing
risks
Inability to
High
implement
key elements
of IT strategy
Likely
appropriate
maintenance
contracts
Prioritise IT
strategic
developments
appropriate
maintenance
contracts
Confirm
funding for IT
strategy priority
developments
Download