Cards 41-80 Flashcards
- Two reasons to collect physical security program metrics:.
-provide assurance of program effectiveness
and
-facilitate improvements
- Commonly provides management with a snapshot of the effectiveness and efficiency of a physical security program?
A metrics summary chart
- The purpose of a business impact analysis (BIA)?
ID and evaluate the potential impact of a disruptive event to operations.
The purpose of a business continuity management system (BCMS)….?
Enable a company to address Disruptive events by identifying, developing and implementing …C….O….P, P and P…..capabilities, objectives, policies, processes and programs within legal bounds.
- What two things are the foundation for setting up business continuity objectives, targets, programs and plans?
The business impact analysis and the risk assessment.
- Name 3 inter-related management response steps that require pre-emptive planning and implementation in case of a disruptive or crisis event?
Emergency response;
Continuity planning; and
Recovery planning
- What is the basis for setting recovery time objectives?
-The results of the business impact analysis
- What is a disruptive event?
An event that is planned or not planned that interrupts activities, operations or functions.
- What is a threat?
-The potential cause of an unwanted incident which may harm…
Individuals;
Assets;
A system
An organization
The environment or
The community
- What is a loss event profile?
-a list of the kind of threats affecting the assets to be safeguarded.
- What is a hazard?
A source of potential danger or adverse condition. They are generally associated with nature.
- Threats or loss risk events fall into three categories:
-Crimes
-non-criminal man-made incidents or Natural disasters
- events caused by an org’s relationship with other orgs
- Examples of non-criminal threats?
Natural threats - hurricane, tornado, storm;
Man-made threats and disasters…..like a plane crash….labor strike or power failure
- Six examples of peripheral systems and interfaces?
Life safety systems and policies and procedures;
Building controls and IT Infrastructure;
Liaison relationships and outsourced services;
- What is a consequential event?
-An event that occurs b/c of a relationship between events or between two organizations. The company suffers a loss b/c of that event or relationship.
- How is the probability of a threat occurring decided?
-by considering the likelihood that a loss risk event may occur in the future.