Showing posts with label data classification. Show all posts
Showing posts with label data classification. Show all posts

Thursday, April 24, 2008

Data Classification - Revisited

In an earlier post (see Simple data classification for Business Continuity) I described a simple means of beginning to classify the value of data for Business Continuity. I’d like to expand on that topic and perhaps approach the subject from a slightly different perspective.

The value of business data

When speaking of the value of business data, the one universal constant is “it depends”. All data is “important” to the business owner – otherwise it wouldn’t have been created in the first place, right?

But looking at the question from the terms of the “business”, the true value to the organization of any particular piece of data lies in how that data is accessed, not in any innate value placed on it by the data’s creator. In fact, the importance of data varies significantly among industries, even by application and perhaps time of day within any particular firm.


Just as the true value of data will vary in nearly every case, the process of assigning a value to the data will be different from enterprise to enterprise. Take for example, the case of a large web based retailer. In this environment, the cost of an hours’ outage might be estimated as:


Estimated Cost of Outage
$'s per hour
FirstSecondThirdFourthFifth
(hard dollars)Loss of SalesXXXXX
(soft dollars)Customer SatisfactionZZ+10%Z+15%Z+20%Z+25%

In this example, the retailer has determined that the cost of lost sales remains constant while the soft dollar loss relating to customer satisfaction (and future customer visits) gradually increases with the duration of the outage.
Although this is a simplistic case, it does illustrate a starting point that can be used and built upon in support of different industries and or clients. Take, for example, an enterprise in the banking or services industry. A chart such as follows might be used to quantify the cost of an outage:
Estimated Cost of Outage
$'s per hour
FirstSecondThirdFourthFifth
(hard dollars)Loss of FeesXXXXX
Loss of FloatYYYYY
(soft dollars)Customer SatisfactionZZ+10%Z+15%Z+20%Z+25%

In either case, once you have the anticipated costs assigned to components of both the “hard” and “soft” dollar categories, the value of the data to the business is represented by the sum of the individual columns
Performing this type of exercise is an important step in gaining management concurrence and understanding of the true business value of the various data components. It is also the basis of generating sustainable Service Level Agreements (SLA) as well as Recovery Time and Recovery Point Objectives (RTO and RPO).

Wednesday, February 27, 2008

Simple data classification for Business Continuity

The majority of today's businesses cannot survive a catastrophic loss of corporate data. In many cases, the data is the corporations’ most important asset – and the amount of data is growing at exponential rates. This dramatic growth in the enterprise storage environment is forcing businesses to continually examine and enhance the availability, security and reliability of their enterprise storage environment.


Quick Terms
Business ContinuityThe ability of an enterprise to continue to function during and after a catastrophic event
HIPAAHealth Insurance Portability and Accountability Act
ResilienceThe ability to provide a minimum acceptable level of service during or following following failures
Sarbanes-OxleyU.S. legislation to protect and preserve financial information


Just as the volume and importance of data for day-to-day business use continues to grow, the requirement to archive data for future use has also grown dramatically. Compliance requirements, like Sarbanes-Oxley, HIPAA, and others have helped to accelerate this growth. Also, new data sources are constantly being developed including the digitization of formerly non-digital (paper) assets, plus the requirement to quickly and accurately retrieve legacy data for business purposes, has contributed to enterprise storage requirements as well.

Businesses recognize that remote data replication, multi-site failover and other techniques along with faster backup and recovery times, are essential to their ability to survive in today’s 24x7 global economy. Several mechanisms are implemented by most businesses to ensure business continuity. These techniques include newer data replication (“mirroring”) processes as well as adaptations to or modifications of some of the more classic Disaster Recovery techniques that have been successfully utilized in the past.

In many cases, the legacy Disaster Recovery methods have served the industry well for many years. These methods continue to be useful, but they are proving to be inadequate as the sole means of providing Business Continuity in today’s world. Business requirements for continuity plans and fault recovery demand greater levels of operational resilience, data protection and business continuance requiring off-site data replication, automatic storage system failover, in addition to shorter backup windows and quicker recovery times.

Luckily, new tools and facilities are constantly being developed to satisfy these requirements.

Before deciding upon which of the newer business continuity facilities might be appropriate in your environment, it is important to try to understand how your data is classified according to business use. While a single solution might seem desirable from a support aspect, it is sometimes not the most cost effective means of satisfying the true business requirements.

Using the broadest terms possible, the recovery requirements of data can be classified as:
  1. Immediate – This data is required to support critical business functions.
  2. As Soon As Possible –This data is required to support normal business functions.
  3. Eventually - This data will probably be used sometime or may need to be available to satisfy legal or archival requirements.

While this list is a vast over-simplification of the complexities involved in data classification, it does illustrate the idea that different data may have different backup and recovery requirements. Once this idea has been accepted, it is possible to target specific data for the appropriate (and most cost effective) backup and recovery methodologies that have been (or can be) implemented in your environment.