Contingency Planning Flashcards

1
Q

This type of plan focuses on sustaining an organization’s mission/ business processes during and after disruption

A

BUSINESS CONTINUITY PLAN (BCP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

This plan focuses on restoring an organization’s mission essential functions (MEF) at an alternate site for up to 30 days

A

CONTINUITY OF OPERATIONS (COOP) PLAN

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

The documentation of standard procedures for internal and external communications in the event of a disruption

A

CRISIS COMMUNICATIONS PLAN

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Designed to mitigate the risk of system and service unavailability and provide solutions to enhance system availability

A

CONTINGENCY PLANNING

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

This document provides guidelines on determining information system impact to organizational operations and assets

A

FIPS 199

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the 3 security objectives?

A
  • CONFIDENTIALITY
  • INTEGRITY
  • AVAILIBILITY
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

This type of planning applies to the mission/business itself; it concerns the ability to continue critical functions after an emergency event

A

CONTINUITY PLANNING

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

This type of planning applies to information systems, and provides the steps needed to recover the operation of all or part of designated information systems

A

CONTINGENCY PLANNING

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

A set of policies and procedures that serve to protect and recover assets and mitigate risks and vulnerabilities

A

CRITICAL INFRASTRUCTURE PLAN (CIP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

This plan establishes procedures to address cyber-attacks against an organization’s information system(s)

A

CYBER INCIDENT RESPONSE PLAN

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

This plan applies to major (usually physical) disruptions to service that deny access to primary facility infrastructure for an extended period

A

DISASTER RECOVERY PLAN (DRP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

This plan provides established procedures for the assessment and recovery of a system following a system disruption

A

INFORMATION SYSTEM CONTINGENCY PLAN (ISCP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

This plan outlines first-response procedures for occupants of a facility in the event of a threat or incident to the health and safety or personnel, property, and the environment

A

OCCUPANT EMERGENCY PLAN (OEP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Step 1 in ISCP planning

A

Develop the contingency planning policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Step 2 in ISCP planning

A

Conduct the business impact analysis (BIA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Step 3 in ISCP planning

A

Identify preventive controls

17
Q

Step 4 in ISCP planning

A

Create contingency strategies

18
Q

Step 5 in ISCP planning

A

Develop an information system contingency plan

19
Q

Step 6 in ISCP planning

A

Ensure plan testing, training, and exercises

20
Q

Step 7 in ISCP planning

A

Ensure plan maintenance

21
Q

Represents the total amount of time the system owner/authorizing official is willing to accept for a mission/business process outage or disruption and includes all impact considerations

A

MAXIMUM TOLERABLE DOWNTIME (MTD)

22
Q

Defines the maximum amount of time a system resource can remain unavailable before an there is an unacceptable impact on other resources

A

RECOVERY TIME OBJECTIVE (RTO)

23
Q

Represents the point in time, prior to a disruption or outage, to which mission/business process data can be recovered. Unlike the RTO, this is not considered part of the MTD

A

RECOVERY POINT OBJECTIVE (RPO)

24
Q

COOP functions must be sustained within ___ hours and for up to ___ days from an alternate site

A

12 and 30

25
Q

Types of Alternate Sites

A
  • Cold
  • Warm
  • Hot
  • Mobile
  • Mirrored
26
Q

Facilities with adequate space and infrastructure (power, connections, environmental controls) to support information system recovery activities

A

COLD SITES

27
Q

Partially equipped office spaces that contain some or all of the system hardware, software, telecom, and power sources

A

WARM SITES

28
Q

Facilities appropriately sized to support system requirements and configured with the necessary system hardware, supporting infrastructure, and support personnel.

A

HOT SITES

29
Q

Self-contained, transportable shells custom-fitted with specific telecommunications and system equipment necessary to meet system requirements

A

MOBILE SITES

30
Q

Fully redundant facilities with automated real-time information mirroring; identical to the primary site in all technical respects

A

MIRRORED SITES

31
Q

What are the 3 classifications of threats?

A
  • Natural
  • Human
  • Environmental
32
Q

The ________________ ( ) focuses on restoring an organization’s essential functions at an alternate site and performing those functions up to ___ days before returning to normal ops.

A

Continuity of Operations Plan (COOP) / 30

33
Q

This provides detailed procedures to facilitate recovery of capabilities at an alternate site when major disruptions will have a long term affect.

A

Disaster Recovery Plan (DRP)

34
Q

This enables the Contingency Planning Coordinator to fully characterize the system requirements, processes, and interdependencies and use this information to determine contingency planning requirements and priorities.

A

Business Impact Analysis (BIA)

35
Q

Which type of agreement allows two organizations to backup each other?

A

Reciprocal Agreement

36
Q

What is the first step to take before writing an IT contingency plan?

A

Develop a planning policy statement supported by senior management (i.e. Chief Information Officer)

37
Q

How often should my IT Contingency Plan be tested?

A

At least annually, and when significant changes are made to the IT system, supported business process(s), or the IT Contingency Plan

38
Q

How often should my Contingency Plan be updated?

A
  • It should be reviewed annually for accuracy and completeness
  • Upon significant changes to any element of the plan, system, processes, or recovery resources
39
Q

What COMDINST covers Command Incident Response?

A

COMDINST 3120.15