Senin, 13 Agustus 2012

Data Center IDC Down

Pada malam tanggal 12 Agustus 2012 telah terjadi kebakaran di Data Center IDC yang berlokasi di Duren Tiga. Kebakaran tersebut disebabkan adanya kerusakan pada UPS. Banyak website seperti : Detik, Garuda Indonesia, MyTrans, Indowebster, Maxindo, OkeZone, Liputan 6, dll. 

Dari berita yang saya dapatkan, saya menjadi berfikir bahwa perusahaan besar seperti Garuda Indonesia mengapa tidak mempunyai Backup untuk websitenya yang diletakkan pada DRC (Disaster Recovery Center). Kemudian juga sekelas Indowebster mengapa tidak langsung mengalihkan website dan forum mereka ketempat lain ? Padahal setahu saya mereka menyediakan jasa penyimpanan data2 loh dan perasaan saya ada Data Center mereka yang berlokasi di Pantai Indah Kapuk deh.

Kebakaran di IDC sangat menjadi pelajaran berharga bagi perusahaan besar di Indonesia. Dengan adanya hal tersebut, mereka seharusnya berfikir bahwa pentingnya Disaster Recovery Center (DRC) serta Disaster Recovery Plan (DRP). Jika mereka sudah aware dengan hal tersebut, maka perusahaan besar tersebut harus melihat dampak yang akan terjadi apabila mereka tidak mempunyai DRC. Kemudian perusahaan tersebut harus mempunyai Business Impact Analysis, serta SLA yang diberikan oleh pihak penyedia jasa Data Center.

Saya ragu apakah organisasi atau perusahaan yang mengalami down pada sistem mereka belum menerapakan standarisasi Business Continuity Plan (BCP). Sungguh sangat disayangkan jika mereka belum aware tentang kelangsungan layanan mereka yang diberikan kepada publik.

Dengan terjadinya disaster tersebut, saya mengkhawatirkan jika perusahaan atau organisasi tersebut akan terkena dampak "Risiko Reputasi" karena nanti pihak publik akan ragu dengan layanan yang diberikan oleh perusahaan tersebut karena menganggap mereka lalai karena tidak memikirkan kualitas layanan kepada publik. Pihak publik sih tidak mau tahu kerusakan terjadi disisi mananya, yang mereka lihat adalah si perusahaan tersebut bukan third party dari perusahaan tersebut.

Untuk mengatasi risiko tersebut, sebaiknya disegerakan pihak perusahaan melakukan klarifikasi kepada publik terkait kejadian disaster tersebut. Bentuk klarifikasi bisa melalui media masa (Koran, Radio, TV, dll). Jadi intinya klarifikasi tersebut jangan saling menyalahkan pihak siapapun, tapi perusahaan mencoba mengambil hikmah dari kejadian tersebut dan berjanji akan lebih aware tentang hal-hal seperti itu. Kemudian juga bisa memberikan statement bahwa perusahaan akan mempunyai backup untuk layanan tersebut apabila layanan primary-nya terjadi down dan diberikan SLA untuk layanan tersebut.

Memang Risiko Reputasi itu tidak bisa dinilai berapa total kerugiannya. Berbeda dengan risiko lainnya yang dapat dinilai total kerugiannya. Saran saya yang terakhir adalah pihak penyedia jasa dan perusahaan, sebaiknya mengambil sertifikasi yang salah satu poin dari sertifikasi tersebut adalah tentang BCP. Setahu saya standarisasi ISO ada yang mengatur tentang BCP, diantaranya :
- ISO 27001
- ISO 27031
- ISO 22399
- ISO 24762
- dll.


Semoga diambil hikmah dari kejadian tersebut dan dari tulisan ini saya berharap dapat bermanfaat bagi para pembaca blog saya.

Senin, 30 Juli 2012

ISO 20000:2011

This part of ISO/IEC 20000 is a service management system (SMS) standard. It Specifies requirement for the service provider to plan, establish, implement, operate, monitor, review, maintain and improve an SMS. The requirements include the design, transition, delivery and improvement of service to fulfill service requirements. This part of ISO/IEC 20000 can be used by:
  1. An organization seeking services from providers and requiring assurance that their service requirement will be fulfilled.
  2. An organization that requires a consistent approach by all its service provider, including those in a supply chain.
  3. An service provider that intends to demonstrate its capability for the design, transition, delivery and improvement of service to fulfill service requirements.
  4. A service provider to monitor, measure and review its service management processes and service.
  5. A service provoder to improve the design, transition and delivery of service through effective implementation and operation of an SMS.
  6. An assessor or auditor as the criteria for a comformity assessment of a service provider’s SMS to the requirements in this part of ISO/IEC 20000.

Figure 2 illustrates an SMS, including the service management processes. The service management processes and realitionships between the processes can be implemented in different ways by different service providers. The nature of the relationship between a service provider and the customers wil be influence how the service management processes are implemented.


ISO/IEC 17021:2011

Certification of management systems (named in this International Standard “certification”) is a third-party conformity assessment activity (see ISO/IEC 17000:2004, 5.5). Bodies performing this activity are therefore third-party conformity assessment bodies (named in this International Standard “certification body/bodies”).

5.1.1 Legal responsibility
The certification body shall be a legal entity, or a defined part of a legal entity, such that it can be held legally responsible for all its certification activities. A governmental certification body is deemed to be a legal entity on the basis of its governmental status.

5.1.2 Certification agreement
The certification body shall have a legally enforceable agreement for the provision of certification activities to its client. In addition, where there are multiple offices of a certification body or multiple sites of a client, the certification body shall ensure there is a legally enforceable agreement between the certification body granting certification and issuing a certificate, and all the sites covered by the scope of the certification.

5.1.3 Responsibility for certification decisions
The certification body shall be responsible for, and shall retain authority for, its decisions relating to
certification, including the granting, maintaining, renewing, extending, reducing, suspending and withdrawing of certification.

5.2 Management of impartiality
5.2.1 The certification body shall have top management commitment to impartiality in management system certification activities. The certification body shall have a publicly accessible statement that it understands the importance of impartiality in carrying out its management system certification activities, manages conflict of interest and ensures the objectivity of its management system certification activities.

5.2.2 The certification body shall identify, analyse and document the possibilities for conflict of interests arising from provision of certification including any conflicts arising from its relationships. Having relationships does not necessarily present a certification body with a conflict of interest. However, if any relationship creates a threat to impartiality, the certification body shall document and be able to demonstrate how it eliminates or minimizes such threats. This information shall be made available to the committee specified in 6.2. The demonstration shall cover all potential sources of conflict of interests that are identified, whether they arise from within the certification body or from the activities of other persons, bodies or organizations.

DOWNLOAD