CISSP (Domain 8 - Business Continuity and Disaster Recover Planning) Flashcards
Business Continuity Planning (BCP)
- Short-term
- project scope, planning, business impact analysis, recovery strategy, recovery plan development, implementation
- put in place for business to funcation
Disaster Recovery Planning (DRP)
- Long-term
- recovery plan development, implementation, restoration
NIST 800-34
Business Continuity Standard
Business Continuity Planning (BCP) - Senior Management Responsibilities (7 Things)
- Support and finalize plans
- Setting the business continuity policy
- Prioritizing critical business functions
- Allocating sufficient resources and personnel
- Providing oversight for and approving the BCP
- Directing and reviewing test results
- Ensuring maintenance of a current plan
Business Continuity Planning (BCP) - Senior
Functional Management Responsibilities (5 Things)
- Develop and document maintenance and testing strategy
- Identify and prioritize mission-critical systems
- Monitor progress of plan development and execution
- Ensure period tests
- Create the various teams necessary to execute the plans
*Department Head
Business Continuity Planning (BCP) - Committee
- Execute the BIA
- Coordinate with department representatives
- Develop analysis group
- Findings are input to BR/DR
Business Continuity Planning (BCP) - Rescue Team
Deals with the immediacy of disaster
- Employee evacuation
- Crashing the server room
Business Continuity Planning (BCP) - Recovery Team
Gets the alternative facility up and running
Business Continuity Planning (BCP) - Salvage Team
Return of operations to the original or permanent facility
7 Phases of a Business Continuity Planning (BCP)
- Project initiation
- Business impact analysis
- Risk analysis
- Risk mitigation
- Implementation
- Test
- Maintenance
Business Impact Analysis (BIA)
- See how company would be affected by different identified threats
- Quantitative and Qualitative information gathered
- First step in disaster recovery planning
3 Priority Goals of Business Impact Analysis (BIA)
- Prioritize critical functions
- Determine requirements/applications which serve core business functions
- Estimate amount of downtime company can handle
Management Should Establish Recovery Priorities for Business Processes That Identify These 5 Things
- Essential personnel
- Technologies
- Facilities
- Communications systems
- Vital records and data
Recovery Point Objective (RPO) - BIA Key Metric
Maximum sustainable data loss based on backup schedules and data needs
- Weekly, hourly, daily?
Recovery Time Objective (RTO) - BIA Key Metric
Duration of time required to bring critical systems back online
- System recovery time
Work Recovery Time (WRT) - BIA Key Metric
Duration of time needed to recover lost data (Based on RPO) and to enter data resulting from work backlogs
- Manual workload