gearing up resiliency for your critical systems, anand bindumadhavan, swift
TRANSCRIPT
Taking Resiliency to the next level
Singapore
22 May 2014
Agenda
2
Resiliency
Lifeline
Resiliency Workshop - Singapore
Sometimes this happens…
3
VPNVPN
PRIMARY host
?
Nothing working
VPNVPN
CONTINGENCY host
• Alliance Entry/Access
• Alliance Gateway?• Alliance Entry/Access
• Alliance Gateway
?
Resiliency Workshop - Singapore
Resiliency
• “To minimise the impact of a technical failure on your business, you should be prepared for any disaster that might arise.”
• Failover procedures • Application data to restore• HSM Resilience• PKI resilience
– Certificate renewal– SO access to secondary SNL
• Failover routes
4
Prepare
Test
Learn
VPN
Messaging application
Communication interface
Hardware Security Module (HSM)
SWIFTNet connectivity
Resiliency Workshop - Singapore
5
Typical infrastructure
5
Prime/Backup site
PRIMARY host
• Alliance Access 7.0.70
• Alliance Gateway 7.0.21
VPNVPN
-Bronze -Silver
or
VPNVPN
Contingency site
DR host
• Alliance Access 7.0.50
• Alliance Gateway 7.0.20
-Bronze-Silver
or
Copy Backups
• Alliance Access 7.0.70
• Alliance Gateway 7.0.21
Keep your Backup or Contingency systems on the
same patch level and license
Implement Backups on Alliance Gateway and
SWIFTNet Link
Multiple ISP
RAHA license on Alliance Gateway can provide transparent failovers
Backup tokens or HSM cluster
How to recover lost messages on DR
procedure?
Is the DR site working?Connectivity?Certificates?Applications?
In case of system failure, the back office and users need to switch to the
contingency SAA
Resiliency Workshop - Singapore
6
Extra resiliency locally
6
Prime/Backup site
PRIMARY host
• Alliance Entry/Access
• Alliance Gateway
BACKUP host
• Alliance Entry/Access
• Alliance Gateway
VPNVPN
-Bronze (ISP, ISP)-Silver (LL, ISP)
VPNVPN
Contingency site
DR host
• Alliance Entry/Access
• Alliance Gateway
-Bronze-Silver
or or
Resiliency Workshop - Singapore
7
Extra resilience for emergencies
7
Prime/Backup site
PRIMARY host
• Alliance Entry/Access
• Alliance Gateway
VPNVPN
-Bronze (ISP, ISP)-Silver (LL, ISP)
VPNVPN
Contingency site
DR host
• Alliance Entry/Access
• Alliance Gateway
-Bronze-Silver
or orLifeline service
Resiliency Workshop - Singapore
Agenda
8
Business continuity
Connectivity
Resiliency
Lifeline
Resiliency Workshop - Singapore
Introducing Alliance Lifeline
Resiliency Workshop - Singapore 9
Alliance Lifeline keeps you connected to SWIFT no
matter what happens
What is Alliance Lifeline?
10Resiliency Workshop - Singapore
InternetOptional:
Alliance Connect
Alliance Lifeline
HSMInterface MV-SIPN
Connect to SWIFT via
Alliance Lifeline
Browsers
@
AutoClient
Primary / backup / DR infrastructureat customer site
Alliance Lifeline light ‘footprint’ at customer site
Application
When your main SWIFT connection becomes
unavailable
Alliance Lifeline – Light footprint
Resiliency Workshop - Singapore 11
1
2
3
Standard broadband Internet connection
*Option to connect using VPN
Standard Internet Explorer browser
Standard Windows PC / laptop
4 SWIFT security tokens (USB)
Alliance Lifeline – Stay connected to SWIFT no matter what happens
• The Alliance Lifeline user interface (GUI) is always available
– Access to O2M, RMA management
• The SWIFT connection is in stand-by mode:
Lifeline – Standard – FIN, RMA and Browse
Configured with one LT, ready to be activated for emission and reception
Lifeline – Premium – “Complex” FIN, SWIFTNet and Browse
Configured ready to send (1 new dedicated LT)
ready to be activated in reception (support of multiple LTs and delivery
sub-sets)
Pre-definition of activation scenarios
12Resiliency Workshop - Singapore
Alliance Lifeline – Key features
Resiliency Workshop - Singapore 13
Cost-effective ‘cold standby’ connection to SWIFT (based on Alliance Access)
Secure Internet connection from any location; option to connect over SWIFT VPN
Global 24/7/365 connection activation on request – GUI always available
Easy-to-use browser-based screens; light footprint
Deployed from SWIFT Operating Centre for maximum availability and resilience
Basic message reconciliation – copy of messages exchanged over Lifeline during outage, report of last sent messages before outage available upon request
Alliance Lifeline could be right for you if …
• Inability to exchange SWIFT messages could have severe financial or reputational consequences for your business
• You want an insurance in case your connection to SWIFT becomes unavailable
• You need an alternative connection in order to comply with regulatory requirements
• You like the flexibility of having a subscription-based emergency connection without the need for additional upfront investment
• You’re a remote office and you want a backup solution in case you cannot connect to SWIFT via your head office
Resiliency Workshop - Singapore 14
Alliance Lifeline – Service offering
Resiliency Workshop - Singapore 15
Analysis & Design
ImplementationActivation
Testing
End-to-end Project Manager
Activation / Deactivation
Change Management
Testing
Operation & MaintenanceSet-up Services
Customer Support
• Requirements assessment and solution design
• Customisation to your specific needs• Remote installation• Initial RMA records import• Activation testing • Activation tutorial• End-to-end project management
• Activation/deactivation on request • Message reconciliation assistance• Activation testing (twice per year)• Additional configuration changes*
* Additional charges will apply
Alliance Lifeline Pricing
Resiliency Workshop - Singapore 16
No surprises,all inclusive
One-time setup fee
All-inclusive annual subscription fee
Sent messages and files are charged at standard SWIFT
prices
Daily usage fee when service is activated2 days per year free of charge to allow testing
17
How efficient and resilient are you?
• SWIFT consulting can help you in assessing your current infrastructure and identifying area for improvements– Infrastructure review– Health checks– DR architecture assessment and procedure– Operational procedures and incident management
Resiliency Workshop - Singapore