Domain 2 - BC / DR and Incident Response Flashcards
What is the Continuity of Operations Plan (COOP)?
Details how we keep operating in a disaster
What is the crisis communications plan?
How we communicate internally and externally
What is a cyber incident response plan?
How we respond in cyber events
What is the Occupant Emergency Plan (OEP)?
How we protect our facilities, our staff, and the environment in a disaster event
What is the Business Recovery Plan?
It lists the steps we need to take in order to restore normal business operations after a disruptive event.
What is the continuity of Support Plan?
It narrowly focuses on support of specific IT systems and applications.
What is the Crisis Management Plan (CMP)?
It provides effective coordination of management of the organization in an emergency.
What are the three disaster categories?
Natural
Human
Environmental (Not nature)
Is the Disaster Recovery Plan a sub-plan of the Business Continuity Plan?
Yes
What is the disaster recovery plan lifecycle?
Mitigation
Preparation
Response
Recovery
What is the definition of RPO?
The acceptable amount of data that cannot be recovered.
Think restore point intervals.
What is the definition for Maximum Tolerable Downtime (MTD) in Disaster Recovery?
The maximum amount of downtime for any given system.
You want to be certain you can rebuild the system before the MTD limit is reached.
What is Work Recovery Time (WRT) in Disaster Recovery?
It is the time required to configure the software for a recovered system.
What is the Minimum Operating Requirements in Disaster Recovery?
It is the bare minimum specifications that a system can run on.
What is a redundant site in Disaster Recovery?
It is an identical site to production and receives a real-time copy of the data.
What is a hot site in Disaster Recovery?
Similar to a redundant site, but it only houses critical applications and systems. Manual failover
What is a warm site in Disaster Recovery?
Similar to a hot site, but the data is not real-time or even near real-time. Takes between 4 - 24 hours to restore. Manual failover
What is a cold site in Disaster Recovery?
A smaller, but full data center with redundancies. Restoration can take weeks.
Incident management is what kind of function?
An Administrative function
What is an event in incident management?
It is an observable change in state
Wha is a problem in incident management?
An incidence with an unknown cause.
What is an inconvenience in incident management?
A non-disruptive failure
What is a disaster in incident management?
Our entire facility is unusable for 24 hours
What is a catastrophe in incident management?
Our entire facility is destroyed.
Should senior management be on the cyber incident response team?
Yes
What are the eight steps of incident management?
Preparation
Detection
Response
Mitigation
Reporting
Recovery
Remediation
Lessons Learned
In what phase of the incident management plan do users begin interacting with affected systems?
The Response phase
What is the mitigation phase of the incident management plan?
It’s when the cause of the incident is identified and now steps can be taken to bring the system back to operational status