5.4 - Summarize risk management processes and concepts. Flashcards
RTO (Business impact analysis)
- Recovery time objective
– Get up and running quickly
– Get back to a particular service level
RPO (Business impact analysis)
- Recovery point objective
– How much data loss is acceptable?
– Bring the system back online; how far back
does data go?
MTTR (Business impact analysis)
- Mean time to repair
– Time required to fix the issue
MTBF (Business impact analysis)
- Mean time between failures
– Predict the time between outages
Chapple 553
Weiss 609-610
Gibson 334
- Functional recovery plans (Business impact analysis)
- Single point of failure (Business impact analysis)
- Disaster recovery plan (DRP) (Business impact analysis)
- Mission essential functions (Business impact analysis)
- Identification of critical systems (Business impact analysis)
- Site risk assessment (Business impact analysis)
- Environmental (disasters)
- Person-made (disasters)
- Internal vs. external (disasters)
- Likelihood of occurrence
– Annualized Rate of Occurrence (ARO)
– How likely is it that a hurricane will hit?
In Montana? In Florida?
- Impact
AV
Asset value
SLE
Single-loss expectancy
– What is the monetary loss if a single event occurs?
– Laptop stolen (asset value or AV) = $1,000
Weiss 605
Gibson 280-281
- Annualized loss expectancy (ALE)
– ARO x SLE
– Seven laptops stolen a year (ARO) x
$1,000 (SLE) = $7,000
- Annualized rate of occurrence (ARO)
– How likely is it that a hurricane will hit?
In Montana? In Florida?