Business Continuity and Disaster Recovery Planning Flashcards
What does the acronym BCP stand for?
BCP (Business Continuity Planning)
What does the acronym DRP stand for?
DCP (Disaster Recovery Planning)
In terms of Business Continuity and Disaster Recovery Planning, what is the the last line of defense when all other controls have failed?
BCP/DRP is the last line of defense when all other controls have failed; the final control that may prevent drastic events like injury or loss of life or failure of an organizations.
In terms of Business Continuity and Disaster Recovery Planning,
characterize the difference between BCP and DRP.
BCP is an umbrella plan which includes multiple specific plans; most importantly the Disaster recovery Plan (DRP)
DRP is IT centric.
In terms of Business Continuity and Disaster Recovery Planning,
What is the definition of BCP?
BCP: Business Continuity Planning: ensuring the business will continue to operate before, throughout and after a disaster; a long term strategic business oriented plan; long term plan to ensure the continuity of the business.
In terms of Business Continuity and Disaster Recovery Planning,
What is the definition of DRP?
Disaster Recovery Plan (DRP): A short term plan to recover from a disruptive event.
In terms of Business Continuity and Disaster Recovery Planning,
What is the definition of COOP?
Continuity of Operations Plan (COOP): A plan to maintain operations during a disaster.
In terms of Business Continuity and Disaster Recovery Planning,
What is the definition of Disaster?
Disaster: Any disruptive event that interrupts normal systems operations.
In terms of Business Continuity and Disaster Recovery Planning,
What is the definition of the Mean Time Between Failures?
Mean Time Between Failures (MTBF): Quantifies how long a new or repaired system will run on average before failing
In terms of Business Continuity and Disaster Recovery Planning,
What dos the acronym MTBF stand for?
Mean Time Between Failures (MTBF): Quantifies how long a new or repaired system will run on average before failing
In terms of Business Continuity and Disaster Recovery Planning,
What dos the acronym MTTR stand for?
Mean Time To Repair (MTTR): Describes how long it will take to recover a failed system.
In terms of Business Continuity and Disaster Recovery Planning,
What is the definition of Mean Time To Repair?
Mean Time To Repair (MTTR): Describes how long it will take to recover a failed system.
In terms of Disaster Types
What is the likelihood of a Natural Diasaster?
Low likelihood but depends on where you are.
In terms of Disaster Types
Technical disastgers (Cyber warfare, espionage, crime, hactivism) are a subset of whct kind of Disaster?
Human Disaster
In terms of Disaster Types
What is the most common kind of Disaster?
Human Unintentional is the most common disaster.
In terms of Disaster Types
What is the most easily avoided kind of Disaster?
Human Unintentional is the most common disaster.
In terms of Disaster Types
What type of disaster are Personnel Shortages?
Human Disaster.
In terms of Disaster Types
What are the trhee kinds of Personnel Shortages?
1: Pandemic & Disease
2: Strikes
3: Availability
In terms of Disaster Types
Is weather a natural disaster or an environmental disaster?
natural disaster
In terms of Disaster Types
What is an environmental disaster?
Environmental pertains to information systems: Power outages or hardware and/or software failures.
In terms of Disaster Types
What is the most common disaster in a datacenter?
Power is the most common that will affect a datacenter.
In terms of the Disaster Recovery Process
What is the most most important issue?
Personnel safety is the most important issue
What is are the five steps to the Disaster Recovery Process
1: Response
2: Recovery Team Activation
3: Tactical Communication
4: Damage Assessment
5: Critical Asset recovery (Reconstitution)
In terms of the Disaster Recovery Process
What is is th epurpose of the Response Phase?
Initial Damage Assessment; Speed is key
Are people safe?
Is it a disaster?
Do we need to engage the alternate processing center?
In terms of the Disaster Recovery Process
What are three considerations to Tactical Communication?
1: Quick and frequent updates about the situation
2: May have to be done out of band
3: May have to communicate to the public
What are the six steps when Developing the BCP/ DRP
1: Project Initiation
2: Project Scope
3: Business Impact Analysis
4: Preventive Controls Identification
5: Recovery Strategy
6: Plan Design and Development
In terms of Developing the BCP/ DRP
What are the seven steps to Project Initiation?
1: Develop the contingency planning policy statement: provides authority to develop plan
2: Conduct Business Impact Analysis (BIA): ID critical IT systems
3: ID Preventative controls:
4: Develop recovery strategies
5: Develop IT Contingency plan
6: Plan testing, exercises and training
7: Plan maintenance
In terms of Developing the BCP/ DRP
What are the five steps to Project Scope?
1: Define exactly which assets to protect
2: Define which emergency events the plan will address
3: Get C-Level approval
4: Determine objectives and deliverables in if-then format (If hurricane – enact Plan H)
5: Assess Critical State by creating a Critical State IT Asset list
In terms of Developing the BCP/ DRP
During Project Scope, What are three considerations when getting C-Level approval?
1: Support for initiating the plan
2: Final Approval
3: Demonstrate due care and due diligence or be held liable under law
In terms of Developing the BCP/ DRP
During Project Scope, when assessing the Critical State, does the PM us a qualitative approach or a a quantitative approach ?
The PM uses a qualitative approach when documenting assets; during the BIA later, he will use a the quantitative method.
In terms of Developing the BCP/ DRP
What is a Business Impact Analysis?
A formal method for determining how a disruption to the IT systems will impact the organization with respect to the mission.
It is an analysis to identify and prioritize critical IT systems and components.
It aims to quantify the consequence of a disruption
In terms of Developing the BCP/ DRP
What is the primary goal of a Business Impact Analysis?
Determine the Maximum Tolerable Downtime (MTD) for a specific asset
In terms of Developing the BCP/ DRP
What does the Maximum Tolerable Downtime (MTD) mean
MTD is the total time a system can be inoperable before an organization is severely impacted.
It is the max time it takes the reconstitution phase.
In terms of Developing the BCP/ DRP
What does the acronym (MTD) stand for
Maximum Tolerable Downtime (MTD)
In terms of Developing the BCP/ DRP
What are the two metrics that comprise the Maximum Tolerable Downtime (MTD) ?
1: Recovery Time Objective (RTO)
2: Work recovery Time (WRT)
In terms of Developing the BCP/ DRP
What are the three alternative names to Maximum Tolerable Downtime (MTD) ?
1: Maximum Allowable Downtime (MAD)
2: Maximum Tolerable Outage (MTO)
3: Maximum Acceptable Outage (MAO)
In terms of Developing the BCP/ DRP and determining the Maximum Tolerable Downtime (MTD)
What does the Recovery Time Objective (RTO) mean?
Recovery Time objective (RTO) is the maximum desired length of time allowed between a disaster and the resumption of normal operations.
The RTO defines the point in time after a disaster at which the consequences of the interruption become unacceptable.
MTD = RTO + WRT
In terms of Developing the BCP/ DRP and determining the Maximum Tolerable Downtime (MTD)
What does the acronym (RTO) stand for?
Recovery Time objective (RTO)
In terms of Developing the BCP/ DRP and determining the Maximum Tolerable Downtime (MTD)
What does the acronym (WRT) stand for?
Work Recovery Time (WRT)
In terms of Developing the BCP/ DRP and determining the Maximum Tolerable Downtime (MTD)
What does Work Recovery Time (WRT) mean?
The time it takes to get business processes up and running after the systems have been restored.
MTD = RTO + WRT
In terms of Developing the BCP/ DRP and determining the Maximum Tolerable Downtime (MTD)
What is the general rule MTD time and revoery cost?
As a general rule, the shorter the MTD, the more expensive the recovery solution.
In terms of conducting the Business Impact Analysis
What is the Reconstitution Phase?
Reconstitution Phase is the process of moving an organization from disaster recovery to business operations.
In terms of conducting the Business Impact Analysis
What is a significant side benefit?
Side benefit: If there are inefficiencies in the business process, the BIA will identify them.
In terms of Developing the BCP/ DRP
What does the acronym BIA stand for?
Business Impact Analysis
In terms of Business Impact Analysis
What are the six common metrics used
1: Recovery Point Objective (RPO)
2: Recovery Time Objective (RTO):
3: Work Recovery Time (WRT):
4: Mean Time Between Failures (MTBF)
5: Mean Time To Repair (MTTR):
6: Minimum Operating requirements (MOR):
In terms of Business Impact Analysis
What is the Recovery Point Objective (RPO)?
The amount of data loss or system inaccessibility (measured in time) that an organization can withstand.
Defined by specific actions like the point in time when users are allowed to deliver payroll checks again.
In terms of Business Impact Analysis
What does the acronym (RPO) stand for?
Recovery Point Objective
In terms of Business Impact Analysis
What is the Mean Time Between Failures (MTBF)?
Mean Time Between Failures (MTBF): Quantifies how long a new or repaired system will run before failing.
In terms of Business Impact Analysis
What is Mean Time To Repair (MTTR)?
Mean Time To Repair (MTTR): Quantifies how long it will take to recover a failed system. It is a best estimate.
In terms of Business Impact Analysis
What are the Minimum Operating Requirements (MOR)?
Minimum Operating requirements (MOR): Describes the minimum environmental and connectivity requirements in order to operate computer equipment.
In terms of Business Impact Analysis
What does the acronym (MOR) stand for?
Minimum Operating requirements (MOR): Describes the minimum environmental and connectivity requirements in order to operate computer equipment.
In terms of Business Impact Analysis
Name the two processes that make up the BIA?
The BIA is comprised of two processes:
1: Identify Critical assets
2: Conduct a comprehensive risk assessment.
In terms of Business Impact Analysis during the Recovery Strategy
Name the five kinds of alternate sites listed in order for cost to implement and degree of availability
1: No Plan
2: Cold Site: A datacenter with raised floor, and utilities. No equipment or data.
3: Warm Site: A datacenter with raised floor, utilities, fully configured computers but no data.
4: Hot Site: A datacenter with raised floor, utilities, fully configured computers and data. The idea is to switch over in a small amount of time.
5: Redundant Site: An exact production duplicate.