2 BC/IR/DR Flashcards
Business Continuity Planning (BCP) =
a set of activities and controls designed to keep a business running in the face of adversity (Availability!)
Business Impact Assessment (BIA) =
a tool that identifies and prioritizes risk (risk assessment)
The BIA output =
a prioritized listing of risks with associated cost - compare control cost with annualized loss expectancy
Single Point of Failure Analysis (SPOFs) (Business continuity tool)
identifies and removes SPOFs (single server - replace with server cluster)
2 key concepts to improve availability
1 High Availability (HA) - redundant systems 2 Fault Tolerance (FT) - helps protect a single system from failing in the first place
Load Balancing =
(related but different concept)
- uses multiple systems in an attempt to spread the burden of providing services across those systems
3 Common Points of Failure that FT addresses:
1 Power Supplies 2 Storage Media
3 Networking
RAID is a
Fault Tolerance technique to protect against a single disk failure, it is not a backup strategy!
RAID types (2)
1 Disk Mirroring (RAID level 1)
2 Disk Striping with Parity (RAID level 5)
Disk Mirroring (RAID level 1) server has
- 2 disks
- data is written to both identically (synchronized)
Disk Striping with Parity (RAID level 5)
- 3 or more disks
- data is written across those disks with parity blocks (additional data) spread across the disks
Incident Response Process (4) (lifecycle)
1 Preparation
2 Detection/Analysis
3 Containment/Eradication/Recovery
4 Post-incident Activity
NIST SP 800-61 (standard process)
Incident Response Plan elements:
1 statement of purpose/scope
2 clear strategies and goals for the incident response effort
3 the organization’s approach to incident response (who is responsible for what?)
4 communication with other groups
5 senior leadership approval
IR Plan should (4)
1 covers both internal and external communications
2 contain notification and escalation procedures
3 limit external communications (PR, alert attackers, etc)
4 alerting law enforcement is usually not required (complex - threat to safety, obligation)
SIEM =
Security Incident and Event Management