Chapter 3 (Domain 1 & 7) Flashcards
Business Continuity Planning
Business Continuity Planning (BCP)
Assessing the risks to organizational processes and creating policies, plans, and procedures to minimize the impact those risks might have on the organization if they were to occur.
Four steps of the BCP
1) Project scope and planning
2) Business impact analysis
3) Continuity planning
4) Approval and implementation
BCP: Project scope and planning
4 steps
1) Organizational Review - Identify all departments and individuals who have a stake in the BCP Process
2) BCP Team Selection - Representatives from each department, IT SME, Cybersecurity, Physical Security, Attorneys, Human Resources, Public Relations, Senior Management.
3) Resource Requirements - Resources for BCP Development, BCP Testing Training and Maintenance, And BCP Implementation.
4) Legal and Regulatory Requirements
BCP: Business Impact Analysis
5 tasks
1) Identifying Priorities
2) Risk Identification
3) Likelihood Assessment
4) Impact Analysis
5) Resource Prioritization
BCP: Continuity Planning
Two Primary Subtasks
1) Strategy Development
2) Provisions and Processes
BCP: Plan Approval and Implementation
The plan should be endorsed by the top executive in your business.
List the necessary member of the business continuity planning team.
Representatives from each department IT SME Cybersecurity Physical Security Attorneys Human Resources Public Relations Senior Management
BCP documentation benifits
- Ensures BCP personnel have a written continuity document to reference in the even of an emergency.
- Provides a historical record of the BCP process that will be useful to future personnel seeking both understanding and reasoning behind implementation and procedures.
- Forces the team members to commit their thoughts to paper-a process that often facilitates the identification of flaws in the plan.
Statement of Importance
This document commonly takes the form of a letter to the organization’s employees, stating the reason that the organization devoted significant resources to the BCP.
Statement of Priorities
Listing the functions considered critical to continued business operations in a prioritized order.
Statement of Organizational Responsibility
Echoes the sentiment that “business continuity is everyone’s responsibility!”
Statement of Urgency and Timing
Expresses the criticality of implementing the BCP and outlines the implementations timetable decided on by the BCP team.
Vital Records Program
States where critical business records will be stored and the procedures for making and storing backup copies of those records.