OSG Chapter 3 Flashcards
What is the difference between BCP and DR?
BCP is the plan to keep the organisation running in the event of a disaster. This is typically higher level strategy and focuses around business processes and operations.
DR is the plan to recover the systems/data that have been impacted. This is typically more tactical and technical.
What are the 4 main steps in BCP?
1) Project scope and planning
2) BIA
3) Continuity Planning
4) Approval and Implementation
What is step 1 in BCP planning and what are the 4 main points to consider within this?
Project Scope and Planning
1) Perform a structured review of the business’s organisation from a crisis management planning point of view.
2) Create a BCP team with the approval of senior management
3) Assess the resources available to participate in the business continuity activities.
4) Analyse the legal and regulatory landscape that governs an organisation’s response to a catastrophic event.
What is step 2 of BCP and what are the 5 stages to consider?
1) Identify Priorities
2) Risk Identification
3) Likelihood Assessment
4) Impact Assessment
5) Resource prioritisation
What is MTD, MTO, RTO and RPO?
1) Mean tolerable downtime
2) Mean tolerable outage
3) Recovery time objective
4) Recovery point objective
What is step 3 in BCP and what are the 2 key points in this?
1) Strategy Development
2) Provisions and Processes:
(Specific procedures and mechanisms that will mitigate risks)
- People
- Buildings & facilities
- Infrastructure
What is a COOP?
Continuity of operations plan
Focuses on how an organisation will carry out critical business functions beginning shortly after a disruption occurs and extending for up to one month of sustained operations.
What is the final step in BCP and what are it’s main points?
Plan Approval & Implementation
- Plan Approval
- Plan implementation
- Training & Education
- BCP documentation
- Continuity planning goals
- Statement of importance
- Statement of priorities
- Statement of organisational responsibility
- Statement of urgency & timing
- Risk assessment
- Risk acceptance/mitigation
- Vital records program
- Emergency response guidelines
- Maintenance
- Testing & Exercises