Chapter 3 Flashcards
Business Continuity Planning (BCP)
used to maintain the continuous operation of a business in the event of an emergency
Difference between BCP and DRP
BC is strategic and high level - focused on business processes and operations. DR are more tactical and describe technical activities like recovery sites, backups, and fault tolerance.
4 steps of business continuity
- Project scope and planning
- Business impact analysis
- Continuity planning
- Approval and implementation
top priority of BCP and DRP
PEOPLE - don’t let them die
Which step of BCP does this belong to?
Perform a structured review of the business’s organization from a crisis planning POV
- Project Scope and Planning
Which step of BCP does this belong to?
Create a BCP team with the approval of senior management.
- Project scope and planning
Which step of BCP does this belong to?
Assess the resources available to participate in BC activities
- Project scope and planning
Which step of BCP does this belong to?
Analyze the legal and regulatory landscape that governs an organization’s respond to a catastrophic event.
- project scope and planning
Which step of BCP does this describe?
Analyze the business organization to identify all departments and individuals who have a stake in the BCP process
- Organizational Review
What are four key departments to identify during the Organizational Review?
- Operational departmets - core services
- Critical support - maintain systems for operations
- physical security teams - usually first responders
- senior executives
Why would a BCP team made of only the IT and security departments be a critical flaw?
other departments may not know about the plan until it is too late
plan may not take into account aspects critical to business ops
critical roles filled by snr management in bcp
setting priorities, providing staff and financial resources, settling disputes
Resource requirements should be assessed for three phases. Which are they?
- BCP development - time and staff effort
- BCP testing, training, and maintenance
- BCP implementation - when disaster strikes
Which step of BCP does this describe?
Identify business processes and tasks that are critical to an organization’s viability and threats to those resources
- Business Impact Analysis
Quantitative Impact Assessment
use numbers and formulas to reach a decision - often expressed in dollar value
Qualitative Impact Analysis
uses non-numerical factors that are categorized (high, med, low)
critical business functions
activities that if disrupted would jeopardize the organization’s ability to achieve its goal