CPP 2022 Domain 7: Crisis Management Flashcards
What is emergency planning/response?
The planning and activity associated with detecting, containing, and dealing with the immediate impact of an event.
Source: POA, Crisis Management, Chapter 1 Introduction, page 1
What is crisis management?
The process of supporting emergency management/response and business continuity operations while dealing strategically with the numerous issues that could impact the long-term viability of the organization.
Source: POA, Crisis Management, Chapter 1 Introduction, page 1
What is business continuity?
The processes and procedures put in place to move from functioning during the crisis to functioning as normal operations after a business interruption.
Source: POA, Crisis Management, Chapter 1 Introduction, page 2
What are the four elements of emergency management?
Mitigation,
Preparedness,
Response,
Recovery.
Source: POA, Crisis Management, 1.1, page 2
This element of emergency management is the process of putting protective measures in place to reduce the likelihood of a disaster occurring or to reduce the impact if a disaster does occur.
Mitigation.
Source: POA, Crisis Management, 1.1, page 2
This element of emergency management encompasses any activities, programs, and systems developed and implemented prior to an incident that may be used to support and enhance mitigation of, response to, and recovery from disruptions, disasters, or emergencies.
Preparedness.
Source: POA, Crisis Management, 1.1, page 2
This element of emergency management deals with executing the plan and performing duties and services to preserve and protect life and property as well as provide services to the surviving population.
Response.
Source: POA, Crisis Management, 1.1, page 2
This element of emergency management ensures that the processes, resources, and capabilities of the organization are reestablished to meet ongoing operational requirements.
Recovery.
Source: POA, Crisis Management, 1.1, page 2
What is the goal of crisis management?
To protect the core assets of the organization (reputation, brand, financial wellbeing, trust, physical and intellectual property, and key relationships) from as much harm as possible caused by a business-interrupting event.
Source: POA, Crisis Management, 1.2, page 4
What should an emergency or crisis management plan do?
Define the term and scope of a crisis or emergency in terms relevant to the organization;
Establish a group or team to perform specific tasks before, during, and after a disruptive event;
Establish a method for using available resources or obtaining additional resources at the time of an event;
Provide a means for moving normal operations into and back out of crisis mode of operations;
Provide a plan and framework to continually test and maintain the plan and response capabilities.
Source: POA, Crisis Management, Chapter 2 Introduction, page 9
How should an emergency and response team be structured?
The emergency coordinator assumes responsibility for the plan.
A committee of representatives from critical departments should be appointed to help the coordinator organize the plan.
Alternate designations for the primary decision maker and anyone else charged, by name or position, in the plan must be made.
Source: POA, Crisis Management, 2.1.1, page 10
What are common features of Incident Command Systems (ICS)?
Command,
Operations,
Planning,
Logistics,
Administrative/finance.
Source: POA, Crisis Management, 2.1.2, page 11
The crisis management team should have members from what areas or departments?
Executives,
Human resources,
Public affairs/communications, Safety/security, IT, Legal, Finance or other shared service, Critical operational departments.
Source: POA, Crisis Management, 2.3.1, page 14
At what three levels can crisis management teams operate?
Operational,
Tactical,
Strategic.
Source: POA, Crisis Management, 2.3.2, page 16
What are the goals of continuity planning?
Save lives and reduce chances of further injuries or deaths,
Protect assets,
Restore critical business processes and systems,
Reduce the length of the interruption of business,
Protect reputation damage,
Control media coverage,
Maintain customer relations.
Source: POA, Crisis Management, Chapter 3 Introduction, page 17
What is the relationship between the business continuity team and the crisis management team?
The business continuity team is treated separately and as a support for the overarching crisis management team.
Source: POA, Crisis Management, 3.1, page 18
What should business continuity plans and procedures do?
Establish the appropriate notification and communications protocol;
Be specific regarding the immediate steps that should be taken during a disruption;
Be flexible to respond to unanticipated threat scenarios and changing conditions;
Focus on the impact of events that could potentially disrupt operations;
Be developed based on stated assumptions and interdependencies;
Be effective in minimizing consequences through appropriate mitigation strategies.
Source: POA, Crisis Management, 3.2, page 19
How should threats and vulnerabilities to the business be identified, evaluated, and prioritized?
Through a risk assessment.
Source: POA, Crisis Management, 3.2, page 19
How can the likelihood of crisis incidents occurring be estimated?
By assessing the organization’s changing profile and the security measures already in place.
Source: POA, Crisis Management, 3.2, page 20
How can the consequences of an incident be assessed?
Based on knowledge of the assets at risk.
Source: POA, Crisis Management, 3.2, page 20
What is management’s role in developing a business continuity plan?
Management must be directly involved in the identification and evaluation of the organizational assets as part of the plan development.
Source: POA, Crisis Management, 3.2.2, page 23
What is the goal of emergency and crisis plan exercises?
To measure the staff’s ability to effectively respond, recover, and continue to perform assigned business activities when faced with specific disruptive scenarios.
To ensure that technology resources function as planned and that staff members are adequately trained in their use and application.
Source: POA, Crisis Management, 3.2.3, page 24
What are four types of exercises?
Orientation,
Tabletop,
Functional,
Full scale.
Source: POA, Crisis Management, 3.2.3, page 25
What is the purpose of a business impact analysis (BIA)?
To identify and evaluate the potential impact of a disruptive event to an organization’s operations.
Source: POA, Crisis Management, 3.4, page 30
What should be addressed in a BIA?
Identify the potential impacts over time of disruptions on activities and resources;
Identify legal, regulatory, and contractual requirements for activities and resources;
Estimate the maximum tolerable downtime that can be withstood while still maintaining viability;
Evaluate resource requirements, activity, and external interdependencies to resume operations within established timescales.
Source: POA, Crisis Management, 3.4, page 30