Cards 41-80 Flashcards
- Two reasons to collect physical security program metrics:
-provide assurance of p____ e____; and
-f________ imp________.
Program effectiveness
Facilitate improvements
- Commonly provides management with a snapshot of the effectiveness and efficiency of a physical security program?
-A m_______ S______ chart
A metrics summary chart
- The purpose of a business impact analysis (BIA)?
ID and ev______ the potential impact of a dis______ ev_____ to operations.
Evaluate;
Disruptive event
The purpose of a business continuity management system (BCMS)….?
-enable a company to address potentially d_____ ev______ by identifying, developing and implementing P___, ob ___, cap____, p_____ and Pro_____ w/in legal bounds.
Disruptive events;
Policies;
Objectives;
Capabilities;
Processes & programs…
- What two things are the foundation for setting up business continuity o__, t___, pr___ and pl___?
-The B___I____a____ and the R__A___
Objectives, targets, programs and plans;
The business impact analysis and the risk assessment.
- Name 3 inter-related management response steps that require pre-emptive planning and implementation in case of a disruptive or crisis event?
-e____r____;
-c_____ and
-r______
Emergency response;
Continuity planning; and
Recovery planning
- What is the basis for setting recovery time objectives?
-The results of the b___IM____A___
Business impact analysis
- What is a disruptive event?
An event that is planned or not planned that interrupts a___o____ or f______
Activities;
Operations; or
Functions
- What is a threat?
-The p___ c____ of an unwanted incident which may harm
I____
A____
A sys____
An org____
The e_____ or
The c_____
Potential cause
Individuals;
Assets;
A system
An organization
The environment or
The community
50.What is a loss event profile?
-a list of the k____ of th______ affecting the a______to be safeguarded.
Kind of threats
Assets
- What is a hazard?
A source of p____d____ or ad___ c____. They are generally associated with n_______
Potential danger
Adverse condition
Nature
- Threats or loss risk events fall into three categories:
-C______
-non-criminal man-made in__ or N___ d____
- events caused by an org’s r_____ with other orgs
Crimes;
Incidents or natural disasters
Relationship
- Examples of non-criminal threats?
-N___threats - h__, t___, s___
-M___ M___ threats/disasters - plane crash, l____ s_____, power failure
Natural threats - hurricane, tornado, storm;
Man-made….labor strike
- Examples of peripheral systems and interfaces?
-L____ S_____ systems;
-B_____ controls;
-IT i________
- L_____r______
-O______ S______ and
-P_____ and pr______
Life safety;
Building controls;
Infrastructure;
Liaison relationships
Outsourced services;
Policies & procedures
- What is a consequential event?
-An event that occurs b/c a relationship between e____ or between two o_____. The company suffers a loss b/c of that event or relationship.
Events
Organizations
- How is the probability of a threat occurring decided?
-by considering the likelihood that a l____ r_____ e_____ may occur in the future.
Loss risk event