---
name: framework-financial-services-shared-bcdr
title: Business continuity and disaster recovery overview
description: Business continuity and disaster recovery (BCDR) is important for all cloud-based applications, and it is all the more critical for the kind of regulated workloads that the IBM Cloud for Financial Services is intended to host. In the event of a disaster, consumers depend on service being restored quickly without loss of data. Using the VPC reference architecture and following the controls of the IBM Cloud Framework for Financial Services help you achieve that goal. When building a BCDR solution in IBM Cloud, you need to consider your workloads that run in virtual servers or Red Hat OpenShift on IBM Cloud and the BCDR characteristics of all of the other IBM Cloud services your solution depends on.
last-updated: 2025-03-02
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/framework-financial-services?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Business continuity and disaster recovery overview
{: #shared-bcdr}

Business continuity and disaster recovery (BCDR) is important for all cloud-based applications, and it is all the more critical for the kind of regulated workloads that the IBM Cloud for Financial Services is intended to host. In the event of a disaster, consumers depend on service being restored quickly without loss of data. Using the VPC reference architecture and following the controls of the IBM Cloud Framework for Financial Services help you achieve that goal. When building a BCDR solution in IBM Cloud, you need to consider your workloads that run in virtual servers or Red Hat OpenShift on IBM Cloud and the BCDR characteristics of all of the other IBM Cloud services your solution depends on.
{: shortdesc}

## Requirements
{: #your-workloads-requirements}

The following sections describe some of the requirements that you must follow for BCDR of your workloads.

### Alternative storage site
{: #your-workloads-requirements-alternate-storage-site}

You must establish and configure an alternative storage site in at least one geographically separate IBM Cloud multizone region. So, if the storage in one region becomes unavailable, you can use storage from another region.



### Information system backup
{: #your-workloads-requirements-information-system-backup}

As the provider, you must:

* Conduct backups of user-level information contained in the information system
* Conduct backups of system-level information contained in the information system
* Conduct backups of information system documentation, including security-related documentation
* Protect the confidentiality, integrity, and availability of backup information at storage locations

The different levels of information are defined as follows:

* User-level information - Consumer/consumer-managed data
* System-level information - Data you manage that is necessary to meet your service's Recovery Point Objective (RPO). For example, system-state information, operating system and application software, licenses, and so on.
* System documentation - External documentation, internal architecture documentation, run books, and so on.

Other requirements:

* Backups must be at least incremental daily and full weekly.
* Backups must be monitored. Failed backups must be investigated and corrective action that is documented as necessary to maintain the service's RPO.
* Backups and backup logs should be accessible only to authorized individuals who need access to do their jobs.
* Transaction-based systems must implement transaction recovery. Transaction-based systems include database management systems and transaction processing systems. Mechanisms supporting transaction recovery include transaction rollback and transaction journaling.

### Information system recovery and reconstitution
{: #your-workloads-requirements-information-system-recovery}

You should enable recovery and reconstitution of the system to a known state after a disruption, compromise, or failure. Contingency plans must include procedures for validating successful recovery and reconstitution.  Recovery and reconstitution activities include resuming operational capabilities at the original location.

## Backup and disaster recovery for the reference architectures
{: #bcdr-for-reference-architectures}

See the following resources depending on which reference architecture you are using:

- [Business continuity and disaster recovery for VPC reference architecture](https://cloud.ibm.com/docs/framework-financial-services?topic=framework-financial-services-vpc-architecture-bcdr&format=markdown)
- [Business continuity and disaster recovery for Satellite reference architecture](https://cloud.ibm.com/docs/framework-financial-services?topic=framework-financial-services-satellite-architecture-bcdr&format=markdown)

## Backup and disaster recovery for IBM Cloud services
{: #ibm-cloud-services}

In addition to backing up your workloads and having the capability to restore service in the face of a disaster, your BCDR strategy needs to consider all of the IBM Cloud services in your deployment. The following table provides references to additional information regarding BCDR for each service in the reference architecture.

The following table provides references for more information about BCDR for each service in the reference architecture.

| Category | VPC reference architecture | Satellite reference architecture | Optional for both |
|----------|-------------------|-------------------|-------------------|
| Core  | - [VPC infrastructure services](https://cloud.ibm.com/docs/vpc?topic=vpc-ha-dr-vpc&format=markdown) [^tabletext] | - [Satellite](https://cloud.ibm.com/docs/satellite?topic=satellite-ha&format=markdown) |  |
| Containers  | - [Red Hat OpenShift on IBM Cloud](https://cloud.ibm.com/docs/openshift?topic=openshift-responsibilities_iks&format=markdown#disaster-recovery) \n - [Container Registry](https://cloud.ibm.com/docs/Registry?topic=Registry-ha-dr&format=markdown) | - [Red Hat OpenShift on IBM Cloud](https://cloud.ibm.com/docs/openshift?topic=openshift-responsibilities_iks&format=markdown#disaster-recovery) [^tabletext-satellite-enabled-openshift] \n - [Container Registry](https://cloud.ibm.com/docs/Registry?topic=Registry-ha-dr&format=markdown) |  |
| Networking  | - [VPC infrastructure services](https://cloud.ibm.com/docs/vpc?topic=vpc-ha-dr-vpc&format=markdown) \n - [Direct Link](https://cloud.ibm.com/docs/dl?topic=dl-ha-dr&format=markdown) \n - [Transit Gateway](https://cloud.ibm.com/docs/transit-gateway?topic=transit-gateway-bc-dr&format=markdown)  |  |  |
| Storage  | - [Block Storage for VPC](https://cloud.ibm.com/docs/vpc?topic=vpc-ha-dr-vpc&format=markdown) \n - [Object Storage](https://cloud.ibm.com/docs/cloud-object-storage?topic=cloud-object-storage-endpoints&format=markdown#endpoints-geo) | - [Object Storage](https://cloud.ibm.com/docs/cloud-object-storage?topic=cloud-object-storage-endpoints&format=markdown#endpoints-geo) |  |
| Security  | - [Hyper Protect Crypto Services](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-ha-dr&format=markdown#cross-region-disaster-recovery)  | - [Hyper Protect Crypto Services](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-ha-dr&format=markdown#cross-region-disaster-recovery)  | - [App ID](https://cloud.ibm.com/docs/appid?topic=appid-ha-dr&format=markdown)  |
| Logging and monitoring  | - [Activity Tracker Event Routing](https://cloud.ibm.com/docs/atracker?topic=atracker-ha_dr&format=markdown) \n - [Compliance Manager](https://cloud.ibm.com/docs/security-compliance?topic=security-compliance-bc-dr&format=markdown) \n - [Flow Logs for VPC](https://cloud.ibm.com/docs/vpc?topic=vpc-ha-dr-vpc&format=markdown)  | - [Activity Tracker Event Routing](https://cloud.ibm.com/docs/atracker?topic=atracker-ha_dr&format=markdown) \n - [Compliance Manager](https://cloud.ibm.com/docs/security-compliance?topic=security-compliance-bc-dr&format=markdown) |  |
| Integration  |  |  | - [Event Streams](https://cloud.ibm.com/docs/EventStreams?topic=EventStreams-disaster_recovery_scenario&format=markdown) |
{: caption="Backup and disaster recovery information for IBM Cloud services in the reference architectures" caption-side="top"}

[^tabletext]: Only required if enabling public internet access to workload VPC for application consumers.

[^tabletext-satellite-enabled-openshift]: {{site.data.content.satellite-enabled-openshift}}

In addition to the Financial Services Validated services in the reference architecture, see the following references for other important information:

* [How IBM Cloud ensures high availability and disaster recovery](https://cloud.ibm.com/docs/overview?topic=overview-zero-downtime&format=markdown)
* [High availability](https://cloud.ibm.com/docs/framework-financial-services?topic=framework-financial-services-shared-high-availability&format=markdown) in the VPC reference architecture
* [Responsibilities for operating services in your deployment](https://cloud.ibm.com/docs/framework-financial-services?topic=framework-financial-services-shared-responsibilities&format=markdown) of the VPC reference architecture

## Related controls in IBM Cloud Framework for Financial Services
{: #related-controls}

{{site.data.content.related-controls-disclaimer}}


| Family              | Control                                           |
|---------------------|---------------------------------------------------|
| Contingency Planning (CP) | [CP-2 Contingency Plan](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-cp-2&format=markdown) \n [CP-6 Alternate Storage Site](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-cp-6&format=markdown) \n [CP-7 Alternate Processing Site](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-cp-7&format=markdown) \n [CP-9 System Backup](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-cp-9&format=markdown) \n [CP-10 System Recovery and Reconstitution](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-cp-10&format=markdown) \n [CP-10 (2) Information System Recovery and Reconstitution &#124; Transaction Recovery](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-cp-10.2&format=markdown)  |
{: caption="Related controls in IBM Cloud Framework for Financial Services [FSv2.0]" caption-side="top"}
{: #related-controls-fsv2.0}
{: tab-title="FSv2.0"}
{: tab-group="RelatedControls-1"}
{: class="simple-tab-table"}


| Family              | Control                                           |
|---------------------|---------------------------------------------------|
| Contingency Planning (CP) | [CP-2 Contingency Plan](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-cp-2&format=markdown) \n [CP-6 Alternate Storage Site](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-cp-6&format=markdown) \n [CP-7 Alternate Processing Site](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-cp-7&format=markdown) \n [CP-9 Information System Backup](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-cp-9&format=markdown) \n [CP-10 Information System Recovery and Reconstitution](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-cp-10&format=markdown) \n [CP-10 (2) System Recovery and Reconstitution &#124; Transaction Recovery](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-cp-10.2&format=markdown)  |
{: caption="Related controls in IBM Cloud Framework for Financial Services [FSv1.1]" caption-side="top"}
{: #related-controls-fsv1.1}
{: tab-title="FSv1.1"}
{: tab-group="RelatedControls-1"}
{: class="simple-tab-table"}


## Next steps
{: #next-steps}

* [Development processes and software integrity](https://cloud.ibm.com/docs/framework-financial-services?topic=framework-financial-services-shared-development-processes&format=markdown)