To comply with the IS-12 policy, each essential application and service must:
- Have an IT Recovery plan for applications and services
- Test the Recovery plan and data backup plan annually
OIT will adhere to IS-12 for the essential applications and services it supports, and each supporting unit will be responsible for its own. For details, see a list of essential IT applications and services (login and authorization required).
IT Application and Services (IT Resources) in Scope
The Units and Essential Functions Information page lists the unit information with essential functions and its unit contact information.
Timeline
Before July 2024, we collaborated with 39 units to gather and evaluate Applications and services within the scope. All units should have already been contacted. If not, please contact us.
Between July 2024 and June 2025, we are working with units to ensure compliance with essential applications and services. Our goal is to ensure that all units have started the IS-12 journey: have an IT recovery plan in place and test it at least once by June 2025.
Compliance with IS-12
First, you need to work with the Business Continuity Office to determine if your unit has essential functions. If it does, follow these steps to comply with our IS-12 program:
- Identify IT applications and services that support your essential functions.
- The Unit IT Recovery Lead (UITRL) will update the IS-12 Workbook with identified IT applications and services. The IS-12 workbook helps with compliance and testing requirements and can be stored on SharePoint.
- If a vendor or supplier supports your applications and services, send them the Supplier/Vendor IS-12 Compliance Attestation form for completion and return.
- Determine if the IT applications and services comply with IS-12:
- For vendor-supported applications, the IS-12 team will help evaluate compliance.
- For unit-managed IT applications and services, create an IT Recovery plan and test the plan. Completing the workbook gets you halfway to compliance; testing the recovery plan completes it.
- If applications and services do not comply with IS-12, file an exception with the IS-12 Program to inform them of how and when compliance will be achieved.
- Each Unit reviews the overall state of IS-12 compliance each year.
This is a high-level overview of the IS-12 Program.