Chapter 3 Business Continuity Planning Flashcards
What is the process of maintaining business operations with reduced or restricted infrastructure capabilities or resources.
Business Continuity Planning
What is the difference between BCP and DRP
Business Continuity Planning - strategic focused to continue business operations/processes.
Disaster Recovery Plan - tactical plan to transition to recovery site, backups, and implement fault tolerant systems.
4 steps of the BCP process
Business Continuity Plan:
Project Scope and Planning
Business Impact Analysis
Continuity Planning
Approval and Implementation
What is entailed by the organizational review
Business analysis of the organization to id all departments and individuals who have a stake in the BCP process.
- Senior executives/key individuals
- Critical support services
- Critical Security teams
- Operational departments that are responsible for the core services the business provides to its clients
What is the limitation to giving the IT/security department sole responsibility over the BCP
No other operational or support departments are providing input and will not know how to implement the continuity processes when disaster strikes.
Name examples of people you would want on the BCP team
- Core services Dept Org Reps
- Functional area representation
- Physical security and facility management
- Attorneys
- human resources
- public relations
- Senior Management representatives
What are the three BCP phases after the Organizational Review is Complete
- Development
- Testing, Training, and Maintenance
- Implementation
What is one metric that you can point to in order to demonstrate the cost of a loss?
ALE - Annualized Loss Expectancy
Involves the use of numbers and formulas to reach a decision. This type of data often expresses options in terms of the dollar value to the business.
Quantitative Impact Assessment
Takes non-numerical factors, such as reputation, investor/customer confidence, workforce stability, and other concerns, into account. This type of data often results in categories of prioritization (such as high, medium, and low).
Qualitative Impact Assessment
What is the first step in the BIA from a quantitative perspective? Qualitative perspective?
Quantitative - Asset Valuation
Qualitative - ID Business priorities
After you have conducted an asset valuation in the Business Impact Analysis (BIA), what is the next step in determining how much time the business function can tolerate a disruption before suffering irreparable harm?
Develop the maximum tolerable downtime (MTD)
Amount of time in which you can feasibly recover the function in the event of a disruption.
Recovery Time Objective (RTO)
What is the point in time before an incident where the org should be able to recover data from a critical business process?
Recovery Point Objective (RPO)
What is the RPO of a function that is backed up every 20 minutes.
Recovery point objective - 20 minutes