IS3350 CHAPTER 14 Flashcards
The number of times a threat might affect an organization during a one-year time frame is called ___?
ANNUAL RATE OF OCCURRENCE (ARO)
The amount of loss that an organization can expect to have each year due to a particular risk is called \_\_\_? ALE is often expressed as the equation: ALE = SLE x ARO. SLE is single loss expectancy ARO is annual rate or occurrence
ANNUALIZED LOSS EXPECTANCY (ALE)
These ___ address the recovery of an organization’s business processes and functions in the event of a disaster.
These tend to be comprehensive plans for returning an organization to normal operating conditions.
BUSINESS CONTINUITY (BC) PLANS
A process that identifies key business operations and the resources used to support those processes is called ___?
This also identifies maximum tolerable down-time for critical business functions.
BUSINESS IMPACT ANALYSIS (BIA)
A basic type of disaster recovery and business continuity test that checks to make sure that supplies and inventory items needed to an organization’s business recovery are on hand is called ___?
CHECKLIST TEST
A backup site for disaster recovery and business continuity planning purposes that is little more than reserved space is called ___?
It doesn’t have any hardware or equipment ready for business operations.
It will have electrical service, but most likely won’t have network connectivity.
It can take weeks to months for an organization to ready this site for business operations.
COLD SITE
Any situation where a person’s private interests and professional obligations collide is called ___?
Independent observers might question whether a person’s private interests improperly influence his or her professional decisions.
CONFLICT OF INTEREST
A sudden, unplanned event that negatively affects the organizations’ critical business functions for an unknown period is called ___?
DISASTER
Plans that address the recovery of an organization’s information technology systems in the event of a disaster is called ___?
DISASTER RECOVERY (DR) PLANS
The percentage of asset loss that is likely to be caused by an identified threat or vulnerability is called ___?
EXPOSURE FACTOR
A disaster recovery and business continuity test where an organization stopes all of its normal business operations and transfers those operations to its backup site is called ___?
This is the most comprehensive form of disaster recovery and business continuity plan testing; also the most expensive.
FULL INTERRUPTION TEST
An operation backup site for disaster recovery and business continuity planning purposes is called ___?
It has equipment and infrastructure that is fully compatible with an organization’s main facility.
It is not staffed with people.
It can become operational within minutes to hours after a disaster.
HOT SITE
An event that adversely affects the confidentiality, integrity, and/or availability of an organization’s data and information technology systems is called ____?
INCIDENT
A contingency plan that helps an organization respond to attacks against an organizations’ information technology infrastructure is called ___?
INCIDENT RESPONSE (IR)
The amount of time that critical business processes and resurrect can be offline before an organization begins to experience irreparable business harm is called ___?
MAXIMUM TOLERABLE DOWNTIME (MTD)
A fully operational backup site for disaster recovery and business continuity planning purposes is called ___?
This site actively runs an organization’s information technology functions in parallel with the organization’s mail processing facility.
It is fully staffed.
It has all necessary data and equipment to continue business operations.
MIRRORED SITE