Chapter 4: Domain Four: Response Management Flashcards

1
Q

Activity

A

Process or set of processes undertaken by an organization (or on its behalf) that produces or supports one or more products or services.

NOTE: Examples of such processes include accounting, call center, information services, manufacturing, distribution, and other services.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Alternate Worksite

A

A work location, other than the primary location, to be used when the primary location is not accessible. (ASIS International Business Continuity Guideline: 2004)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Auditor

A

A person with the competence to conduct an audit.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Business Continuity

A

Ability of an organizatin to operate at predefined levels following a disruptive event.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Business Continuity Management

A

(BCM) a proactive set of planning, preparedness, and related activities that are intended to restore and organization’s critical business functions to predeterminded levels, enabling the organization to operate despite serious disruptive events and recover to an operational state expeditiously.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Business Continuity Plan

A

(BCP) A collection of procedures and information which is developed, tested and maintained in preparation for use in a disruptive event to continue operations at predefined levels follow the event.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Conformity

A

Fulfillment of a requirement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Continual Improvement

A

Recurring process of enhancing the security, preparedness, and continuity (SPC) management system to achieve improvements in overall SPC management performance consistent with the organization’s SPC management policy.

NOTE: The process need not take place in all areas activity simultaneously.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Crisis

A

An unstable condition invovlving an impending abrupt or significant change that requires urgent attention and action to protect life, assets, property, or the enviroment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Crisis Management

A

Holistic management process that identifies potential impacts that threaten and organization and provides a framework for building resilience with the capability for an effective response that safeguards the interests of its key stakeholders, reputation, brand, and values creating activities, as well as effectively restoring operational capabilities.

NOTE: Crisis management also involves the management of preparedness, mitigation response, continuity or recovery in the event of an incident, as well as management of the overall program through training, rehearsals, and reviews to ensure the preparedness, response, and continuity plans stays current and up to date.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Crisis Management Team

A

Group of individuals functionally responsible for directing the development and execution of the response and operational continuity plan, declaring an operational disruption or emergency/ crisis situation, and providing direction during the recovery process, both pre-and post-incident.

NOTE: The crisis management team may include individuals from the organization as well as immediate and first responders, stakeholders, and other interested parties

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Disaster

A

Event that causes significant damage to assets or loss of life.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Disruption

A

An event that interrupts normal business, functions. operations, or processes, whether anticipated (hurricane, political unrest) or unanticipated (blackout, terror attack, technology failure, or earthquake).

NOTE: A disruption can be caused by either positive or negative factors that will disrupt normal functions, operations, or processes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Downtime

A

Period of time when something is not in operation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Emergency

A

Serious, unexpected, and precarious situation requiring immediate action.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Evacuation

A

Organized, phased, and supervised dispersal of people from dangerous or potentially dangerous areas. (ASIS International Business Continuity Guideline: 2004)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Exercises

A

Evaluating management programs, rehearsing the roles of team members and staff, and testing the recovery or continuity of an organization’s systems (technology, telephony, administration)
to demonstrate management competence and capability

NOTE 1: Exercises include activities performed for the purpose of training and conditioning team members and personnel in appropriate responses with the goal of achieving maximum performance.

NOTE 2: An exercise can involve invoking response and operational continuity procedures, but it is more likely to involve the simulation of a response and/or operational continuity incident, announced or unannounced, in which participants role-play to assess what issues might arise, prior to a real invocation.
structure)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Facility (Infrastucture)

A

Plant, machinery, equipment, property, buildings, vehicles, information systems, transportation facilities, and other items of infrastructure or plant and related systems that have a distinct and quantifiable function or service.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

First Responder

A

A member of an emergency service who is first on the scene at a disruptive incident

NOTE: Emergency services include any public or private service that deals with disruptions, such as the initial responding law enforcement officers, other public safety officials, emergency medical personnel, rescuers, and/or other emergency response service providers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Hazard

A

Possible source of danger or conditions (physical or operational) that have a capacity to produce a particular type of adverse effect.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Incident Command System

A

(ICS) A command and control mechanism used by many public safety agencies and jurisdictions.

22
Q

Internal Audit

A

Systematic, independent, and documented process for obtaining audit evidence and evaluating it objectively to determine the extent to which the management system audit criteria set by the organization are fulfilled.

NOTE: In many cases, particularly in smaller organizations, independence can be demonstrated by the freedom from responsibility for the activity being audited.

23
Q

Key Performance Indicator

A

Key performance indicator (KPI) is a metric used to evaluate factors that are crucial to the success of an organization or of a particular activity in which it engages.

NOTE: A KPI is a metric that indicates how an organization is performing against its objectives.

24
Q

Loss

A

Being deprived of someone or something of value.

25
Q

Management Plan

A

Clearly defined and documented plan of action, typically covering the key personnel, resources, services, and actions needed to implement the incident management process.

26
Q

Mitigation

A

Limitation of any negative consequence of a particular incident. Encompasses activities providing a critical foundation in the effort to reduce the loss of life and property from natural and/or manmade disasters by avoiding or lessening the impact of a disaster and providing value to the public by creating safer communities.

27
Q

Mutual Aid Agreement

A

Written agreement between agencies, organizations, or iurisdictions to lend assistance across jurisdictional boundaries.

28
Q

Organizational Resilience Management System

A

(ORMS) Includes coordinated activities to direct and Management System control an organization with regard to managing risk
to enhance resilience and security in the organization and its supply chain.

NOTE: Direction and control with regard to ORMS generally include establishment of the policy, planning, and objectives directing operational processes and continual improvement.

29
Q

ORMS Objective

A

Something sought, or aimed for, related to managing risk to enhance resilience and security in the organization and its supply chain.

NOTE 1: Quality objectives are generally based on the organization’s quality policy.

NOTE 2: Quality objectives are generally specified for relevant functions and levels in the organization.

30
Q

ORMS Policy

A

Overall intentions and direction of an organization related to managing risk to enhance resilience and security in the organization and its supply chain as formally expressed by top management.

NOTE 1: Generally, the security and resilience policy is consistent with the overall policy of the organization and provides a framework for the setting of security and resilience objectives.

NOTE 2: ORMS principles can form a basis for the establishment of a quality policy

31
Q

Policy

A

Overall intentions and direction of an organization, as formally expressed by top management. (ANSI/ ASIS/RIMS RA. 1-2015)

32
Q

Prepardness (Readiness)

A

Activities, programs, and systems developed and implemented prior to an incident that may be used to support and enhance mitigation of, response to, and recovery from disruptions, disasters, or emergencies.

33
Q

Probability

A

A number between zero and one that shows how likely a certain event is.

34
Q

Problem Assessment

A

An evaluative process of decision making that will determine the nature of the issue to be addressed.

35
Q

Procedure

A

An established or specified way to conduct an activity or a process. (ANSI/ASIS/RIMS RA.1-2015)

36
Q

Process

A

Actions, changes, or steps taken to achieve a particular end.

37
Q

Product

A

Goods and services that are the result of a process.

NOTE: Typically, a product is an item or service that is produced to create value.

38
Q

Recovery Point Objective

A

The point in time to which data or capacity of a process is in a known and valid or integral state can be restored from. This should be less than the maximum amount of loss tolerance and may be defined in hours or days.

39
Q

Recovery Time Objective

A

(RTO) The time goal for the restoration and recovery of functions or resources based on the acceptable downtime and acceptable level of performance in case of a disrupution of operations.

40
Q

Resilience

A

Absorptive and adaptive capacity in a complex and changing environment.

41
Q

Resources

A

Any asset (human, physical, information, or intangible), facilities, equipment, materials, products, or waste that has potential value and can be used.

42
Q

Response Plan

A

Documented collection of procedures and information that is developed, compiled, and maintained in readiness for use in an incident.

43
Q

Response Team

A

Group of individuals responsible for developing, executing, rehearsing, and maintaining the response plan, including the processes and procedures.

44
Q

Safety

A

Freedom from danger, risk, or injury.

45
Q

Security

A

The condition of being protected against risks, hazards, threats, or loss.

46
Q

Severity Assessment

A

The process of determining the severity of the crisis and what any associated costs may be in the long run.

47
Q

Target

A

Something you are trying to do or achieve with defined metrics.

48
Q

Testing

A

Activities performed to evaluate the effectiveness or capabilities of a plan relative to specified objectives or measurement criteria. Testing usually involves exercises designed to keep teams and employees effective in their duties, and to reveal weaknesses in the preparedness and response/continuity/recovery plans. (ASIS International Business Continuity Guideline: 2004)

49
Q

Threat

A

Potential cause of an unwanted incident, which may result in harm to individuals, assets, a system or organization, the environment, or the community.

50
Q

Top Management

A

Directors, managers, and officers of an organization who can ensure that effective management systems, including financial monitoring and control systems, have been put in place to protect assets, earning capacity, and the reputation of the organization.

51
Q

Vulnerablity

A

State of being susceptible to harm or injury.

NOTE: Susceptibility to negative outcomes or a risk.

52
Q

Vulnerablity Analysis

A

Process of indentifying and quantifying something that creates susceptibility to a source of risk that can lead to a consequence.