Contingency Planning Flashcards

1
Q

This type of plan focuses on sustaining an organization’s mission/ business processes during and after disruption

A

BUSINESS CONTINUITY PLAN (BCP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

This plan focuses on restoring an organization’s mission essential functions (MEF) at an alternate site for up to 30 days

A

CONTINUITY OF OPERATIONS (COOP) PLAN

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

The documentation of standard procedures for internal and external communications in the event of a disruption

A

CRISIS COMMUNICATIONS PLAN

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Designed to mitigate the risk of system and service unavailability and provide solutions to enhance system availability

A

CONTINGENCY PLANNING

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

This document provides guidelines on determining information system impact to organizational operations and assets

A

FIPS 199

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the 3 security objectives?

A
  • CONFIDENTIALITY
  • INTEGRITY
  • AVAILIBILITY
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

This type of planning applies to the mission/business itself; it concerns the ability to continue critical functions after an emergency event

A

CONTINUITY PLANNING

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

This type of planning applies to information systems, and provides the steps needed to recover the operation of all or part of designated information systems

A

CONTINGENCY PLANNING

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

A set of policies and procedures that serve to protect and recover assets and mitigate risks and vulnerabilities

A

CRITICAL INFRASTRUCTURE PLAN (CIP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

This plan establishes procedures to address cyber-attacks against an organization’s information system(s)

A

CYBER INCIDENT RESPONSE PLAN

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

This plan applies to major (usually physical) disruptions to service that deny access to primary facility infrastructure for an extended period

A

DISASTER RECOVERY PLAN (DRP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

This plan provides established procedures for the assessment and recovery of a system following a system disruption

A

INFORMATION SYSTEM CONTINGENCY PLAN (ISCP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

This plan outlines first-response procedures for occupants of a facility in the event of a threat or incident to the health and safety or personnel, property, and the environment

A

OCCUPANT EMERGENCY PLAN (OEP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Step 1 in ISCP planning

A

Develop the contingency planning policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Step 2 in ISCP planning

A

Conduct the business impact analysis (BIA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Step 3 in ISCP planning

A

Identify preventive controls

17
Q

Step 4 in ISCP planning

A

Create contingency strategies

18
Q

Step 5 in ISCP planning

A

Develop an information system contingency plan

19
Q

Step 6 in ISCP planning

A

Ensure plan testing, training, and exercises

20
Q

Step 7 in ISCP planning

A

Ensure plan maintenance

21
Q

Represents the total amount of time the system owner/authorizing official is willing to accept for a mission/business process outage or disruption and includes all impact considerations

A

MAXIMUM TOLERABLE DOWNTIME (MTD)

22
Q

Defines the maximum amount of time a system resource can remain unavailable before an there is an unacceptable impact on other resources

A

RECOVERY TIME OBJECTIVE (RTO)

23
Q

Represents the point in time, prior to a disruption or outage, to which mission/business process data can be recovered. Unlike the RTO, this is not considered part of the MTD

A

RECOVERY POINT OBJECTIVE (RPO)

24
Q

COOP functions must be sustained within ___ hours and for up to ___ days from an alternate site

25
Types of Alternate Sites
* Cold * Warm * Hot * Mobile * Mirrored
26
Facilities with adequate space and infrastructure (power, connections, environmental controls) to support information system recovery activities
COLD SITES
27
Partially equipped office spaces that contain some or all of the system hardware, software, telecom, and power sources
WARM SITES
28
Facilities appropriately sized to support system requirements and configured with the necessary system hardware, supporting infrastructure, and support personnel.
HOT SITES
29
Self-contained, transportable shells custom-fitted with specific telecommunications and system equipment necessary to meet system requirements
MOBILE SITES
30
Fully redundant facilities with automated real-time information mirroring; identical to the primary site in all technical respects
MIRRORED SITES
31
What are the 3 classifications of threats?
* Natural * Human * Environmental
32
The ________________ ( ) focuses on restoring an organization’s essential functions at an alternate site and performing those functions up to ___ days before returning to normal ops.
Continuity of Operations Plan (COOP) / 30
33
This provides detailed procedures to facilitate recovery of capabilities at an alternate site when major disruptions will have a long term affect.
Disaster Recovery Plan (DRP)
34
This enables the Contingency Planning Coordinator to fully characterize the system requirements, processes, and interdependencies and use this information to determine contingency planning requirements and priorities.
Business Impact Analysis (BIA)
35
Which type of agreement allows two organizations to backup each other?
Reciprocal Agreement
36
What is the first step to take before writing an IT contingency plan?
Develop a planning policy statement supported by senior management (i.e. Chief Information Officer)
37
How often should my IT Contingency Plan be tested?
At least annually, and when significant changes are made to the IT system, supported business process(s), or the IT Contingency Plan
38
How often should my Contingency Plan be updated?
* It should be reviewed annually for accuracy and completeness * Upon significant changes to any element of the plan, system, processes, or recovery resources
39
What COMDINST covers Command Incident Response?
COMDINST 3120.15