Disaster Recovery Flashcards

1
Q

Acceptance

A

Level of tolerance specified by an organization. When all security measures are taken to mitigate a risk, the remainder of impact will be accepted and tolerated as there is not a way to remove it 100 percent.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Avoidance

A

Removing cause of risk to “avoid” security risks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Business Continuity Plan (BCP)

A

Decides which services are sensitive for the regular operations to continue.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Cold Site

A

Location owned by the organization but contains nothing. In case of disaster the organization will star to equip the cold site to perform the business operations. Could take weeks or months

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Disaster Relief Plan (DRP)

A

Policy that defines how an org will recover from a disaster. The DRP should protect both people and assets of a given organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Electronic Vaulting

A

An alternate location to preserve backed up data. When the backup is complete, it is copied over to a different location. When a disaster occurs the electronic vault is used and the backup is ready to be restored.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Hot Site

A

Identical site of Primary, equipped with systems and services just like the primary. Data is duplicated here.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Human Threats

A

Insiders who have access to systems and Hackers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Internal Users

A

Employees or visitors who could introduce a threat by exploiting a vulnerable or weak point.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Journaling

A

Less expensive solution to preserve the data as journaling captures only transactions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Long term

A

Low Damage recovery, things that affect the daily routine of employees but not productivity, such as having a designated break area.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Mid Term

A

If part of the business is affected, the business should still be able to meet the needs of its customers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Mitigation

A

Using security controls to protect against a risk until the risk impact is reduced to a level that is tolerated by the organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Qualitative Analysis

A

Uses words or ranks to measure the impact of identified risk rather than numbers. Low, medium, and high are usually used to rank the risks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Quantitative Analysis

A

Numeric numbers and values and is usually base on statistics, historic records, best practices, testing, and experiments. This method can identify which risk has higher loss impact and which risk requires higher budget to mitigate.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Risk Analysis

A

Based on qualitative and quantitative analysis; in some cases we see semi-quantitative analysis.

17
Q

Risk exposure

A

The impact caused by the risk on the enterprise

18
Q

Short term

A

when a line of service is fully affected, this is high priority and requires immediate action to recover.

19
Q

Stakeholders

A

The owners, management team, clients, employees, investors, suppliers, and board management

20
Q

SWOT Analysis

A

Strength, Weakness, Opportunity, and Threats; Those four points are the main studies in order to manage a given risk

21
Q

Transference

A

When you transfer the risk to another entity, such as insurance or service provider, where they are accountable 100 percent for the impact in case an attack occurs

22
Q

Warm Site

A

Location that performs non-critical functions for the organization, but can be converted to primary location within days.