Disaster Recovery and Business Continuity Plan
Procedures for maintaining essential operations and restoring services after disruption.
1. Scope
This plan covers the public website, authentication, GrowthZone integrations, conference services, NKN, Foundation experiences, forms, editorial workflows, databases, media, DNS, hosting, email dependencies, and administrative access.
2. Service Priorities
- Security containment and integrity of credentials and data
- Public safety, official notices, and essential contact information
- Authentication, membership, conference, donation, and registration functions
- Editorial, intelligence, committee, and noncritical experience services
3. Recovery Targets
Each critical service must have an approved recovery time objective and recovery point objective based on operational impact. Targets must be documented in the service inventory and tested at least annually.
4. Backup Requirements
- Automated backups of database, uploads, plugins, themes, and critical configuration
- At least one logically separate or offsite recovery copy
- Documented retention and encryption controls
- Routine restoration tests, not backup-success messages alone
5. Activation
The technical owner may activate recovery procedures when availability, integrity, confidentiality, or essential operations are materially threatened. Leadership and affected owners must be notified according to incident severity.
6. Recovery Procedure
- Contain the incident and preserve evidence.
- Confirm the last known good recovery point.
- Restore infrastructure, data, configuration, and integrations in priority order.
- Validate security, authentication, transactions, content, and external connections.
- Communicate service status and known limitations.
- Monitor closely after restoration.
7. Manual Continuity
Essential contact lists, conference notices, member support, and leadership communications require documented manual alternatives when normal systems are unavailable.
8. Testing
Conduct tabletop exercises, credential-access checks, backup restoration tests, vendor-contact validation, and at least one annual recovery simulation. Record findings and corrective actions.
9. Post-Incident Review
After a major disruption, document cause, timeline, decisions, impact, recovery performance, communications, lessons learned, and assigned preventive actions.

