Chapter 15: Business Continuity Planning Flashcards

1
Q

What is Business Continuity Planning?

A

Assessing the risks to organizational processes and creating policies, plans, and procedurs to minimize the imapact those rigks might have on the orgamization if they were to occur.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What happens if business continuity is broken?

A

Business processes have stopoed and the organization is in disaster mode, thus, disaster recovery planning takes over.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the four main steps of BCP as defined by ISC2?

A

Project scope and planning,
business impact assessment
continuity planning
approval and implementaiton

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What does project scope and planning require?

A

structured analysis of the buisiness’s orgamization from a crisis planning point of view
Creation of a BCP team with senior management approval
Assessment of the resource savailablet o participate in BC ativities
Analysis of the legal and regularory landscape that governs response to a catastrophic event

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What areas should be considered in business orgamization analysis?

A

Operational departments that are responsiuble for core services the business provides to clients
Critical support services such as IT, plaint maintenance, and other groups responsible for upkeep of operational departmetns
Senior execs and other key inidividuals essential for the ongoing viability of the orgamization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Who should be on the BCP team?

A

Representatives from each of the organization’s deparatments responsible for the core services
Representatives from the key support departments identified by org. analysis
IT representatives with technical experience in areas covered by the BCP
Security representatives with knowledge of the BCP process
Representatives from senior management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is a risk in selecting the BCP team?

A

Depending on the event, members of the BCP team may not be available in the event of a disaster.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What do you have to consider in selecting an effective BCP team?

A

Balance representing different points of view with explosive personality differences.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is one important reason to include senior management representatives in the BCP process?

A

It can be required by laws or regulations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the marjor resource likely to be needed by the BCP plan during plan creation?

A

Time of the BCP team members.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Why is it essential to include legal counsel in the BCP process?

A

Laws and regulations can place requirements on BCP.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the difference between quantititative decision making and qualitiative?

A

Quant uses numbers and formulas, qual uses nonnumerical factors such as emotions, investor/customer confidence, workforce stability, and other concers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How do you set priorities in BCP?

A

Assign an asset value (AV), maximum tolerable downtime (MTD) or maximum tolerable outage (MTO), recovery time objective (RTO). The goal of BCP is to insure that the RTO isless than MTO.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are natural threats?

A

Violent storms/hurricanes/tornadoes/blizzards
Earthquakes
mudslides/avalanches
volcanoes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are man made threats?

A
terrorist acts/wars/civil unreast
theft/vandalism
fires/explosuions
prolonged power outages
building collapse
transportaion failures
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is ARO?

A

Annualized Rate of Occurrence. The number of times a business expects a particular disaster to occur per year.

17
Q

What is Exposure Factor (EF)?

A

The percentage an asset is reduced in value in the event a loss happens.

18
Q

What is SLE?

A

Single Loss Expectancy. The monetary loss expected each time a loss event occurs for an asset.

19
Q

What nonmonetary impacts can interruptions have on a business?

A

Loss of goodwill among clients
Loss of employees to other jobs after a prolonged downtime
Social/ethical responsibilites to the communities
Negative publicity

20
Q

What are the subtasks in continuity development?

A
Strategy development
provisions and procsses
plan approval
plan implementation
training and education
21
Q

What are the four possible responses to a risk?

A

reduce, assign, accept, reject

22
Q

What is the most important activity in BCP?

A

Ensuring that the people within the orgamization are safe before, during, and after an emergency.

23
Q

What are the two areas that a BCP should address for each critical facility?

A

Hardening provisions and alternate sites.

24
Q

What are the two main methods of providing infrastructure protetion?

A

Physically hardening systems and alternative systems.

25
Q

What is essential to the success of the overall BCP effort?

A

Senior management approval and buy-in.

26
Q

Who should receive training on the plan?

A

Everyone who will be directly or indirectly involved in the plan should receive training on the overall plan and their specific responsibilities.

27
Q

What should the Risk Acceptance/Mitigation portion of a BCP cover?

A

For risks deemed acceptable, it should outline why and list potential future events that should trigger reconsideration.

For risks deemed unacceptable, it should outline risk amanagement provisions and proceesses that reduce the risk.

28
Q

What should emergency response guidelines include?

A

Immediate response procedures (security and safety, fire supporession, notification of emergency response agencies)
Who to notive (execs, BCP members, etc)
Secondary response procedures to take whilew aiting for the BCP team to assemble.

29
Q

How should a BCP be maintained?

A

As a living document. Older versions should be physically destroyed and replaced so there can be no confusion as to which version to use.