Business Continuity and Disaster Recovery Planning Flashcards
What is the purpose of a BIA
To determine how time sensitive different business functions are so you can determine how best to prioritize recovery operations.
When analyzing the software you company uses to perform certain functions, what should you consider?
Whether employees can continue to use the software from a different network location
Whether the software is necessary for performing key business functions.
What should you take into account when considering the amount of work that might be lost in a disaster
The amount of work that can tolerably be lost without harming the organization
How quickly work in progress will need to be restored to workstations at an alternate site.
What 2 types of plans are required for an IT organization
BCP - business continuity plan
DRP - disaster recovery plan
What does a BCP do?
designed to mitigate the impact of a disaster by ensuring that critical business operations continue.
What does a DRP do?
outlines how to restore the normal operational state of an enterprise within the minimum possible time.
3 steps involved in developing a BCP
assessing the impact of a potential disaster in terms of operational disturbance and data loss
formulating appropriate plans to ensure the continuous availability of critical systems
planning and implementing regular BCP training, testing, and maintenance
First phase of BCP - Project Initiation
gain support from senior management
defining project scope
defining a timeline for the project
developing a company policy for implementing the plan
Which requirements must the BCPs of the US financial institutions meet?
They should be reassessed annually
the should focus on maintaining and continuing business functions rather than just on technology recovery.
What should the planning team document during the creation of a BCP or DRP?
contact details for critical staff
ways in which the business will be impacted by possible disasters
potential alternative sites for running critical systems and operations
mission critical data or records
3 ways to respond to risk
accept
transfer
mitigate
3 primary goals of a BIA
prioritize systems in terms of their criticality
estimate maximum acceptable down times
determine resource requirements
Which are key considerations when analyzing impact on business applications?
how a new location might impact employees’ ability to use an application
the relationship between applications and business functions, even those that aren’t time sensitive.
What are key considerations when analyzing the impact of incidents on work in progress?
how quickly data must be recovered in the aftermath of a disaster
the percentage of employees current work that can be lost at a given time.
cold site
empty spaces containing no technical equipment
Which phrase best defines a business continuity/disaster recovery plan?
A. a set of plans for preventing a disaster
B. an approved set of preparations and sufficient procedures for responding to a disaster.
C. A set of preparations and procedures for responding to a disaster without management approval
D. The adequate preparations and procedures for the continuation of all organization functions.
D. The adequate preparations and procedures for the continuation of all organization functions.
Regardless of the industry, which element of legal and regulatory requirements are all industries subject to? A. Sarbanes-Oxley B. HIPAA C. Due care D. BS25999
C. Due care
Which of the following statements best describes the extent to which an organization should address business continuity or disaster recovery planing?
A. Continuity planning is a significant organization issue and should include all parts or functions of the company.
B. Continuity planning is a significant technology issue and the recovery of technology should be its primary focus.
C. Continuity planning is required only where there is complexity in voice and data communications.
D. Continuity planning is a significant management issue and should include the primary functions specified by management.
A. Continuity planning is a significant organization issue and should include all parts or functions of the company.
Business impact analysis is performed to best identify
A. The impacts of a threat to the organization operations
B. The exposures to loss to the organization
C. The impacts of a risk on the organization
D. The cost efficient way to eliminate threats
B. The exposures to loss to the organization
During the risk analysis phase of the planning, which of the following actions could best manage threats or mitigate the effects of an event?
A. Modifying the exercise scenario?
B. developing recovery procedures
C. increasing reliance on key individuals
D. Implementing procedural controls.
D. Implementing procedural controls.
The best reason to implement additional controls of safeguards is to A. deter or remove the risk B. identify and eliminate the threat C. reduce the impact of the threat D. identify the risk and the threat
C. reduce the impact of the threat
Which of the following statements best describes business impact analysis?
A. Risk analysis and business impact analysis are two different terms describing the same project effort
B. A business impact analysis calculates the probability of disruptions to the organization.
C. A business impact analysis is critical to development of a business continuity plan.
D. A business impact analysis establishes the effect of disruptions on the organization.
D. A business impact analysis establishes the effect of disruptions on the organization.
The term disaster recovery refers to the recovery of A. organization operations B. technology environment C. manufacturing environment D. personnel environments
B. technology environment