Business Continuity Planning (BCP) Flashcards

1
Q

activation

A

to start business continuity processes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

alert

A

Notification that a potential disaster situation exists or has occurred

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

alternate site

A

location to perform the business function

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Backup

A

A copy of files and programs made to facilitate recovery if necessary.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Business Continuity Plan

A

documentation of a predetermined set of instructions or procedures that describe how an organization’s mission/business processes will be sustained during and after a significant disruption.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

business continuity program

A

ongoing process supported and funded by executive staff to ensure business continuity requirements are assessed, resources are allocated and, recovery and continuity strategies and procedures are completed and tested

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

business continuity steering committee

A

group of decision makers, business owners, technology experts and continuity professionals, tasked with making strategic recovery and continuity planning decisions for the organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Business Impact Analysis

A

detailed review of information system’s requirements, functions, and interdependencies used to characterize system contingency requirements and priorities in the event of a significant disruption.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

business interruption

A

Any event, whether anticipated or unanticipated which stops the normal course of business operations at an organization location.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

business interruption insurance

A

contract to pay for disaster related expenses that may be incurred until operations are fully recovered.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

business recovery team

A

group of individuals responsible for maintaining the procedures and coordinating return of business functions and processes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

business recovery timeline

A

chronological sequence of recovery activities, or critical path, that must be followed to resume an acceptable level of operations following a business interruption. may range from minutes to weeks, depending upon requirements and methodology.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

business unit recovery

A

component which deals specifically with the relocation of a key function or department in the event of a disaster.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

call tree

A

internal list of contact information used for the communication of incident information, designed in a distributed manor so that no one person is responsible for contacting everyone.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

checklist test

A

(desk check) a test that answers the questions: Does the organization have the documentation it needs? Can it be located?

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

cold site

A

recovery alternative, a building only with sufficient power, and HVAC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Continuity of Operations Plan

A

A predetermined set of instructions or procedures that describe how an organization’s mission essential functions will be sustained within 12 hours and for up to 30 days as a result of a disaster event before returning to normal operations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

coordinator

A

person responsible for overall recovery of an organization or unit(s).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

crisis

A

A critical event, which may dramatically impact an organization’s profitability, reputation, or ability to operate.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

critical functions

A

Business activities or information that could not be interrupted or unavailable for several business days without significantly jeopardizing operation of the organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

critical infrastructure

A

Systems whose incapacity or destruction would have a debilitating impact on the economic security of an organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

critical records

A

documents that, if lost, would cause considerable inconvenience and/or require replacement or recreation at considerable expense.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

data backup strategies

A

processes determined by an organization to be necessary to meet its recovery and restoration objectives. these will determine the timeframes, technologies, media and offsite storage of the backups, and will ensure that recovery point and time objectives can be met.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

data backups

A

confidential system, application, program and/or production files on media that can be stored both on and/or offsite.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

data recovery

A

restoration of computer files from backup media to restore programs and production data to the state that existed at the time of the last safe backup.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

database replication

A

partial or full duplication of data from source to one or more destinations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

declaration

A

formal announcement by pre-authorized personnel that a disaster or severe outage is predicted or has occurred and that triggers pre-arranged mitigating actions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

desk check test

A

test that answers the questions: Does the organization have the documentation and people it needs. Do they understand the documentation?

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

disaster

A

an event which stops business from continuing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

Disaster Recovery Plan

A

A written plan for recovering one or more information systems at an alternate facility in response to a major hardware or software failure or destruction of facilities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

disaster recovery teams

A

A structured group of teams ready to take control of the recovery operations if a disaster should occur.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

disk mirroring

A

Disk mirroring is the duplication of data on separate disks in real time to ensure its continuous availability, currency and accuracy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

Disruption

A

An unplanned event that causes an information system to be inoperable for a length of time (e.g., minor or extended power outage, extended unavailable network, or equipment or facility damage or destruction).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

distributed processing

A

a back up type, where the organization has excess capacity in another location.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

Drills - Test

A

practice of activity typically targeted to a specific response. The purpose is to have the participants follow the designated response activities specified in their plans to become more proficient in executing the response activity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

electronic vaulting

A

transmission of backup data to an offsite facility; it eliminates the need for tape shipment and therefore significantly shortens the time required to move the data offsite.

37
Q

emergency

A

sudden, unexpected event requiring immediate action due to potential threat to health and safety, the environment, or property.

38
Q

Emergency Operations Center

A

location where coordination and execution of BCP or DRP is directed

39
Q

emergency procedures

A

plan of action to commence immediately to prevent the loss of life and minimize injury and property damage.

40
Q

executive succession

A

planning for the delegation of authority required when decisions must be made without the normal chain of command

41
Q

exercise

A

activity that is performed for the purpose of training and conditioning team members, and improving their performance.

42
Q

file shadowing

A

asynchronous duplication of the production database on separate media to ensure data availability, currency and accuracy.

43
Q

forward recovery

A

process of recovering a database to the point of failure by applying active journal or log data to the current backup files of the database.

44
Q

Full Interruption Test

A

live, very high risk test.

45
Q

hot site

A

recovery alternative, everything needed for the business function, except people and last backup

46
Q

Impact

A

magnitude of harm that can be expected to result from consequences of unauthorized disclosure of information, unauthorized modification of information, unauthorized destruction of information, or loss of information or information system availability.

47
Q

Impact Level

A

classify the intensity of a potential impact that may occur if the information system is jeopardized.

48
Q

incident manager

A

highest level of authority at EOC with knowledge of the business process and the resources available

49
Q

incident response

A

reaction of an organization to a significant event that may impact the organization, its people, or its ability to function productively.

50
Q

Incident Response Plan

A

documentation of a predetermined set of instructions or procedures to detect, respond to, and limit consequences of a malicious cyber attacks against an organization’s information system(s).

51
Q

Information System Contingency Plan

A

management policy and procedures designed to maintain or restore business operations, including computer operations, possibly at an alternate location, in the event of emergencies, system failures, or disasters.

52
Q

integrated test

A

test conducted on multiple components of a plan, in conjunction with each other, typically under simulated operating conditions

53
Q

journaling

A

process of logging single changes or updates to a database since the last full backup.

54
Q

Live Walk-Through Test

A

an exercise where the plan is executed as if a real disaster has taken place at a specific point in the facility and is typically conducted with multiple BC/DR teams. (simulation test)

55
Q

Maximum Tolerable Downtime

A

amount of time mission/business process can be disrupted without causing significant harm to the organization’s mission.

56
Q

mirrored site

A

recovery alternative, complete duplication of services including personnel

57
Q

mission-critical application

A

essential to the organization’s ability to perform necessary business functions.

58
Q

mobile site

A

recovery alternative, short-term, high cost movable processing location

59
Q

near site

A

backup of data located where staff can gain access readily and a localized disaster will not cause harm

60
Q

off site

A

backup of data located where staff can not gain access readily and a regional disaster will not cause harm

61
Q

off-site storage

A

Alternate location where duplicated vital records and documentation may be stored for use during disaster recovery.

62
Q

on-site

A

backup of data located where staff can gain access immediately

63
Q

operational impact analysis

A

determines the significance of the loss of an operational or technological resource. The loss of a system, network or other critical resource may affect a number of business processes.

64
Q

operational test

A

test conducted on one or more components of a plan under actual operating conditions.

65
Q

Parallel Test

A

operational test is held at the same time with the actual processing of critical systems to ensure that the systems will run correctly at the alternative site.

66
Q

reciprocal agreement

A

between two organizations (or two internal business groups) with basically the same equipment/same environment that allows each one to recover at each other’s site.

67
Q

recovery period

A

time period between a disaster and a return to normal functions, during which the disaster recovery plan is employed.

68
Q

Recovery Point Objective

A

determinant of the amount of data that may need to be recreated after the systems or functions have been recovered.
stipulates the amount of data an organization can lose when a disaster occurs

69
Q

Recovery Time Objective

A

target time which respects tolerance for loss of certain business function, basis of strategy
stipulates the amount of time an organization needs to recover from a disaster

70
Q

remote journaling

A

database backup type which records at the transaction level

71
Q

replication

A

backup type which creates a complete copy

72
Q

Resilience

A

ability to quickly adapt and recover from any known or unknown changes to the environment through holistic implementation of risk management, contingency, and continuity planning.

73
Q

restoration

A

planning with a goal of returning to the normal business function

74
Q

resumption

A

process of planning for and/or implementing the restarting of defined business operations following a disaster, usually beginning with the most critical or time-sensitive functions first.

75
Q

risk assessment / analysis

A

assessing the critical functions necessary for an organization to continue business operations, defining the controls in place to reduce organization exposure and evaluating the cost for such controls; involves an evaluation of the probabilities of a particular negative event.

76
Q

risk mitigation

A

Implementation of measures to limit specific threats to the continuity of business operations, and/or respond to any occurrence of such threats in a timely and appropriate manner.

77
Q

service bureau

A

recovery alternative which outsources a business function at a cost

78
Q

shadowing

A

backup type, for databases at a point in time

79
Q

simulation

A

scenario based test that answers the question: Can the organization replicate the business process?

80
Q

standalone test

A

test conducted on a specific component of a plan, in isolation from other components, typically under simulated operating conditions.

81
Q

structured walkthrough

A

One method of testing a specific component of a plan. Typically, a team member makes a detailed presentation of the component to other team members (and possibly non-members) for their critique and evaluation.

82
Q

System Development Life Cycle

A

The scope of activities associated with initiation, development and acquisition, implementation, operation and maintenance, and ultimately its disposal

83
Q

system downtime

A

planned or unplanned interruption in system availability

84
Q

Tabletop Walk-Through Test

A

A is a test that exercises all or part of the BC/DR plan as specified in the scope of the test plan.

85
Q

test plan

A

document designed to periodically exercise specific action tasks and procedures to ensure viability in a real disaster.

86
Q

triage

A

to evaluate the current situation and make basic decisions as to what to do

87
Q

Walk-Through Test

A

first test conducted to familiarize the team leader and members with the plan. It addresses all components of the BC/ DR plan.

88
Q

warm site

A

recovery alternative which includes cold site and some equipment and infrastructure is available