Ch3 Flashcards
What are phases of BCP
- project scope and planning
- business impact assessment
- continuity planning
- approval and implementation
What is the overall goal of BCP
ensuring business operations continue uninterrupted during emergencies
Business Organization Analysis
- performed by the individuals spearheading the BCP effort to identify what departments have stake in the BCP
- should be reviewed first thing…again by BCP Team once members are chosen
BCP - project scope and planning
■ analysis of the business’s organization
■ creation of a BCP team
■ assessment of the resources available
■ analysis of the legal and regulatory
BIA - Business Impact Analysis
- identifies resources critical to an organization
- threats posed to those resources (risk analysis)
- likelihood that each threat will actually occur
- impact those occurrences will have on the business
- includes Quantitative & Qualitative analysis
- MTD and RTO (Recovery Time Objective) are analyzed at this point
Name of report by independent auditing firm that conducts an assessment of controls
a service organization control (SOC) report.
Keep in mind that there are three different versions of the SOC report. The simplest of these, a SOC-1 report, covers only internal controls over financial reporting. If you want to verify the security, privacy, and availability controls, you’ll want to review either an SOC-2 or SOC-3 report. The American Institute of Certifed Public Accountants (AICPA) sets and maintains the standards surrounding these reports to maintain consistency between
auditors from different accounting firms
Continuity Planning
- focuses on developing and implementing a continuity strategy to minimize the impact realized risks might have on protected assets.
Strategy Development
- bridges the gap between BIA and continuity planning by analyzing the prioritized list of risks developed during the BIA and determining which risks will be addressed by the BCP
four responses to risk
accept
reduce (mitigate)
assign (transfer)
reject
Provisions and Processes Phase
- meat of the BCP
- BCP Team design specific procedures and mechanisms that will mitigate the risks deemed unacceptable during the strategy development stage.
- people, buildings/facilities, and infrastructure are protected
Approval and Implementation phase
- Requires Senior management approval
- plan implementation
- training and education
- BCP Documentation
what are the necessary members of the BCP Team
IT Operational dept Support dept Legal HR Senior Management Security personnel
Steps of Business Impact Assessment
- Identify priorities
- Identify Risk
- Likelihood assessment
- impact assessment
- resource prioritization