IS3110 CHAP 12 Flashcards
The maximum amount of acceptable data loss for a system. It can be as short as under one minute or up to the moment of failure. It can be longer, such as a day or a week. It is dependent on the value of the data, and the ability to reproduce it.
Recovery point objectives (RPO)
The time in which a system or function must be recovered. It would be equal or less than the maximum acceptable outage (MAO).
Recovery time objectives (RTO)
- The ___ identifies the maximum acceptable downtime for a system.
Maximum acceptable outage (MAO)
- Stakeholders can determine what functions are considered critical business functions.
TRUE OR FALSE
TRUE
- The BIA is part of the ___.
Business continuity plan (BCP)
4. What defines the boundaries of a business impact analysis? A. MAO B. BCP C. Recovery objectives D. Scope
Scope
5. What are two objectives of a BIA? (Select two) A. Identify minimum acceptable outage B. Document new policy C. Identify critical resources D. Identify critical business functions
Identify critical resources
Identify critical business functions
- You are working on a BIA. You are calculating costs to determine the impact of an outage for a specific system. When calculating the costs, you should calculate the direct and ___ costs.
Indirect
7. You are working on a BIA. You want to identify the maximum amount of data loss an organization can accept. What is this called? A. BIA time B. Maximum acceptable outage C. Recovery time objectives D. Recovery point objectives
Recovery point objectives
8. You have identified the MAO for a system. You now want to specify the time required for a system to be recovered. What is this? A. BIA time B. Maximum acceptable outage C. Recovery time objectives D. Recovery point objectives
Recovery time objectives
- Which of the following statements is true?
A. The RPO applies to any systems or functions. However, the RTO only refers to data housed in databases
B. The RTO applies to any systems or functions. However, the RPO only refers to data housed in databases.
C. Both the RTO and RPO apply to any systems or functions.
D. Neither the RTO nor RPO apply to data housed in databases.
The RTO applies to any systems or functions. However, the RPO only refers to data housed in databases.
10. You are working on a BIA. You are calculating costs to determine the impact of an outage for a specific system. Which one of the following is a direct cost? A. Loss of customers B. Loss of public goodwill C. Loss of sales D. Lost opportunities
Loss of sales
- What type of approach does a BIA use?
A. Bottom-up approach where servers or services are examined first
B. Top-down approach where CBFs are examined first
C. Middle-tier approach
D. Best-guess approach
Top-down approach where CBFs are examined first
12. Mission-critical business functions are considered vital to an organization. What are they derived from? A. Critical success factors B. Critical IT sources C. Executive leadership D. Employees
Critical success factors
13. You are performing a BIA for an organization. What should you map the critical business functions to? A. Personnel B. Revenue C. Replacement costs D. IT systems
IT systems