Ch3 Flashcards

1
Q

What are phases of BCP

A
  • project scope and planning
  • business impact assessment
  • continuity planning
  • approval and implementation
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the overall goal of BCP

A

ensuring business operations continue uninterrupted during emergencies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Business Organization Analysis

A
  • performed by the individuals spearheading the BCP effort to identify what departments have stake in the BCP
  • should be reviewed first thing…again by BCP Team once members are chosen
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

BCP - project scope and planning

A

■ analysis of the business’s organization
■ creation of a BCP team
■ assessment of the resources available
■ analysis of the legal and regulatory

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

BIA - Business Impact Analysis

A
  • identifies resources critical to an organization
  • threats posed to those resources (risk analysis)
  • likelihood that each threat will actually occur
  • impact those occurrences will have on the business
  • includes Quantitative & Qualitative analysis
  • MTD and RTO (Recovery Time Objective) are analyzed at this point
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Name of report by independent auditing firm that conducts an assessment of controls

A

a service organization control (SOC) report.
Keep in mind that there are three different versions of the SOC report. The simplest of these, a SOC-1 report, covers only internal controls over financial reporting. If you want to verify the security, privacy, and availability controls, you’ll want to review either an SOC-2 or SOC-3 report. The American Institute of Certifed Public Accountants (AICPA) sets and maintains the standards surrounding these reports to maintain consistency between
auditors from different accounting firms

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Continuity Planning

A
  • focuses on developing and implementing a continuity strategy to minimize the impact realized risks might have on protected assets.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Strategy Development

A
  • bridges the gap between BIA and continuity planning by analyzing the prioritized list of risks developed during the BIA and determining which risks will be addressed by the BCP
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

four responses to risk

A

accept
reduce (mitigate)
assign (transfer)
reject

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Provisions and Processes Phase

A
  • meat of the BCP
  • BCP Team design specific procedures and mechanisms that will mitigate the risks deemed unacceptable during the strategy development stage.
  • people, buildings/facilities, and infrastructure are protected
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Approval and Implementation phase

A
  • Requires Senior management approval
  • plan implementation
  • training and education
  • BCP Documentation
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

what are the necessary members of the BCP Team

A
IT
Operational dept
Support dept
Legal
HR
Senior Management
Security personnel
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Steps of Business Impact Assessment

A
  • Identify priorities
  • Identify Risk
  • Likelihood assessment
  • impact assessment
  • resource prioritization
How well did you know this?
1
Not at all
2
3
4
5
Perfectly