IS and Comm F - Disaster Recovery and Business Continuity Flashcards
In the annual review of the data center of a nationwide mortgage servicing company, the IA manager was concerned about the data center not having an adequate contingency plan. The audit manager was especially concerned because the data center was located close to a river that occasionally flooded and in the vicinity of a major railroad and a major highway. Mgmt acted on the internal auditor’s recommendation to prepare a contingency plan. The most critical aspect of the plan would be to provide for
continuation of mortgage servicing
Risk assessments, recovery plans for data systems, and implementation of safeguards are all components of
a disaster recovery plan
The disaster recovery plan for a firm’s data processing function should categorize systems according to their
priority
The best evidence that a contingency plan is effective is to have
successful testing of the plan
Due to the ever changing nature of LANs, a disaster recovery plan would require
frequent updating
Advances in disaster recovery systems has the _____ effect in driving the changes that are currently occurring in the workplace
least
Technological changes in the workplace are most affected by advances in
computer technology, computer applications, and computer availability
To prevent interruptions in IS operation, _______ and ______ controls are typically included in an organization’s disaster recovery plan
backup and downtime
A routine part of an organization’s disaster recover plan should require the ongoing prep of
backup files
The mgmt activity ___________ is essential to ensure continuity of operations in the event a disaster or catastrophe impairs IS processing
contingency planning
Cold site is
a location the provides everything necessary to quickly install computer equipment in the event of a disaster striking an organization
Hot site is
a completely operational data processing facility configured to meet the user’s requirements that can be made available to a disaster-stricken organization on short notice
Closed loop verification is
a mechanism whereby one party verifies the purported identify of another party by requiring them to supply a copy of a token transmitted to that identity
Authentication validation is
a process of ensuring that proper parties are allowed to access the system
Segregation of control testing is
a policy to prevent individuals from accessing software or data without the collusion of another party
A company switches all processing to an alternate site and staff members report to the alternate site to verify that they are able to connect to all major systems and perform all core business processes from the alternate site. This is an example of
disaster recovery planning
The performance audit report of an IT department indicated that the dept lacked a DRP. The first step mgmt should take is
prepare a stmt of responsibilities for tasks included in a DRP
Fraud detection in a computer environment could be detected by
reviewing system access logs
Fraud prevention in a computer environment can be carried out by
data encryption and fraud-awareness training
Validity checks are
a way to ensure data entry input is correct
When an IT director collects the names and locations of key vendors, current hardware configuration, names of team members, an an alternative processing location, he is most likely preparing
a disaster recovery plan (DRP)
The best approach to avoid having a data center identified as a terrorist target is to
establish and maintain as low a profile as possible for the data center
An example of a procedure most likely to be included in a DRP is
to store duplicate copies of files in a location away from the computer center
Disaster plans must include all of the following factors:
- backup for programs and data
- alternative processing site
- off-site storage of backup
- identification of critical apps
- method for testing the plan
When a company decentralizes operations from HQ but doesn’t update their contingency plan that was in place prior to the decentralization, then the plan is likely to be out of date because of
changes in equipment, data, and software
An adequate DRP includes:
- regular testing with a simulated disaster
- a plan coordinator responsible for implementing the plan
- specific assignments for individuals and teams
- constant revision and improvement