Module 5: Business Impact Analysis Flashcards

1
Q

organization’s ability to adapt to disruptions and incidents in order to maintain continuous operations and to protect the organization’s assets

A

Business Resilience

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Business Resilience: What should CISA candidates be aware of?

A

Alignment of:
1. Disaster Recovery Plan and Business Continuity Plan
2. DRP and BCP with the organization’s goals and risk tolerance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

is a critical step in developing the business continuity strategy and the subsequent implementation of
the risk countermeasures

A

Business Impact Analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Business Impact Analysis: BIA is most important when developing what?

A

The business continuity plan

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

In what order does risk assessment and business impact analysis happen?

A

Risk Assessment first and then Business Impact Analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Business Impact Analysis: BIA is used to evaluate the critical processes only and not the IT components themselves (T or F)

A

False. It also take into consideration the it components supporting the processes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Business Impact Analysis: What do BIAs aim to determine?

A
  1. Time frames
  2. Priorities
  3. Resources
  4. Interdependencies
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Business Impact Analysis: We don’t need to do a BIA if we have done an extensive Risk Assessment already because it will be redundant (T or F)

A

False. The rule of thumb is to double check always because less visible but vital components can be uncovered

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Business Impact Analysis: What do you need to check when IT activities are outsourced?

A
  • SLAs
  • Warranties
  • Terms and Conditions
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Business Impact Analysis: To perform a BIA successfully what should one have?

A
  1. Understanding of the ORganization
  2. Understanding of Key Business Processes
  3. Understanding of IT resources used
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Business Impact Analysis: To get a better understanding of the organization such as its IT resources and Key Business Processes, where can you get that information?

A

Risk Assessment results

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Business Impact Analysis: BIA requires what, in terms of individuals?

A
  1. High level of senior management support
  2. Extensive Involvement of IT and End-user Personnel
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Business Impact Analysis: To whom do you circulate the questionnaire?

A
  1. Key Users in IT
  2. End-User
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Business Impact Analysis: What are the different approaches in performing BIA?

A
  1. Questionnaire
  2. Interview with key users only
  3. Interview with IT personnel and End Users
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Business Impact Analysis: What type of auditing do these three approaches belong to?

A

Participative Auditing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Business Impact Analysis: What are the two cost factors to consider in a BIA?

A
  1. Downtime Costs
  2. Alternative Recovery Strategies
17
Q

Business Impact Analysis: What is the relationship of downtime costs with time and cost?

A

It is positively sloping

18
Q

Business Impact Analysis: Downtime costs flatten out at some point (T or F)

A

True. This signifies the moment where the business process stops working or it can no longer function

19
Q

Business Impact Analysis: What is the relationship of alternative corrective measure with cost and time

A

It is downward sloping

20
Q

Business Impact Analysis: The recovery cost has also many components most of which are flexible (T or F)

A

False, they are rigid-inelastic

21
Q

Business Impact Analysis: Each possible strategy has a fixed cost (T or F)

A

True

22
Q

Business Impact Analysis: Both Variable Costs and Fixed Costs depend on which strategy is implemented (T or F)

A

True

23
Q

Business Impact Analysis: The curve of the sum is usually a? How can you find the optimal strategy using that curve?

A

U curve. The bottom of the u curve represents the lowest cost strategy

24
Q

Criticality Analysis: What is the risk ranking based off?

A

Likelihood and Impact

25
Q

Criticality Analysis: A critical classification’s tolerance to interruption is ____ and cost of interruption is ______

A

Very low; Very high

26
Q

Criticality Analysis: Critical means that it can’t be performed unless replaced by ________

A

Identical capabilities

27
Q

Criticality Analysis: Critical applications cannot be replaced by manual methods (T or F)

A

True

28
Q

Criticality Analysis: This function can be performed manually but for a brief period only

A

Vital

29
Q

Criticality Analysis: Vital operations must be restored within?

A

5 days or less

30
Q

Criticality Analysis: This can be performed manually for an extended period of time

A

Sensitive

31
Q

Criticality Analysis: Interruptions produce no cost to the company

A

Nonsensitive