Contingency Planning Flashcards
This type of plan focuses on sustaining an organization’s mission/ business processes during and after disruption
BUSINESS CONTINUITY PLAN (BCP)
This plan focuses on restoring an organization’s mission essential functions (MEF) at an alternate site for up to 30 days
CONTINUITY OF OPERATIONS (COOP) PLAN
The documentation of standard procedures for internal and external communications in the event of a disruption
CRISIS COMMUNICATIONS PLAN
Designed to mitigate the risk of system and service unavailability and provide solutions to enhance system availability
CONTINGENCY PLANNING
This document provides guidelines on determining information system impact to organizational operations and assets
FIPS 199
What are the 3 security objectives?
- CONFIDENTIALITY
- INTEGRITY
- AVAILIBILITY
This type of planning applies to the mission/business itself; it concerns the ability to continue critical functions after an emergency event
CONTINUITY PLANNING
This type of planning applies to information systems, and provides the steps needed to recover the operation of all or part of designated information systems
CONTINGENCY PLANNING
A set of policies and procedures that serve to protect and recover assets and mitigate risks and vulnerabilities
CRITICAL INFRASTRUCTURE PLAN (CIP)
This plan establishes procedures to address cyber-attacks against an organization’s information system(s)
CYBER INCIDENT RESPONSE PLAN
This plan applies to major (usually physical) disruptions to service that deny access to primary facility infrastructure for an extended period
DISASTER RECOVERY PLAN (DRP)
This plan provides established procedures for the assessment and recovery of a system following a system disruption
INFORMATION SYSTEM CONTINGENCY PLAN (ISCP)
This plan outlines first-response procedures for occupants of a facility in the event of a threat or incident to the health and safety or personnel, property, and the environment
OCCUPANT EMERGENCY PLAN (OEP)
Step 1 in ISCP planning
Develop the contingency planning policy
Step 2 in ISCP planning
Conduct the business impact analysis (BIA)
Step 3 in ISCP planning
Identify preventive controls
Step 4 in ISCP planning
Create contingency strategies
Step 5 in ISCP planning
Develop an information system contingency plan
Step 6 in ISCP planning
Ensure plan testing, training, and exercises
Step 7 in ISCP planning
Ensure plan maintenance
Represents the total amount of time the system owner/authorizing official is willing to accept for a mission/business process outage or disruption and includes all impact considerations
MAXIMUM TOLERABLE DOWNTIME (MTD)
Defines the maximum amount of time a system resource can remain unavailable before an there is an unacceptable impact on other resources
RECOVERY TIME OBJECTIVE (RTO)
Represents the point in time, prior to a disruption or outage, to which mission/business process data can be recovered. Unlike the RTO, this is not considered part of the MTD
RECOVERY POINT OBJECTIVE (RPO)
COOP functions must be sustained within ___ hours and for up to ___ days from an alternate site
12 and 30