SPP - Ch1 ESRM, Crisis Management Flashcards

1
Q

What is essential to ensure recovery from business interruptions and to protect the profitability of the enterprise?

A

Planning

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Even with emergency planning, why is it necessary to improvise and remain flexible when a disaster or other emergencies strikes?

A

Because the variety of emergencies make planning for every possible contingency impossible.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the elements, the primary training of emergency response personnel should focus?

A

The most likely situations and the location, construction, size and function of each site.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

While developing a plan for emergency management what elements should be included in the plan?

A

The development of a plan for emergency management includes:
1. Defining emergency
2. Establishment of an organization to perform specific tasks, before, during and after an emergency.
3. Esablish a method of using available resources and for obtaining additional resources at the time of an emergency.
4. A means from moving normal operaitons into and back of the emergency mode of operations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What should an emergency plan provide?

A

The basis for orderly action and for making decisions that minimize loss.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the four elements of emergency management?

A

Mitigation, preparedness, response and recovery.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How is it possible to prevent from causing substantial loss from an emergency?

A

By responding promptly to an emergency.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

To achieve what business continuity encompasses all the actions taken by a business before, during or after an emergency?

A

To minimize the emergency’s negative impact on the organization’s operations and to bring a timely response, resumption of critical business functions and recovery if an emergency does occur.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What kind of activities are included in the recovery efforts of emergency management?

A

Recovery efforts include implementation of continuity of operation or business resumption plan, activations of emergency relocation and reconstitution or restoration at the original location or a new permanent location.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are those key elements to achieve the objectives of emergency management?

A

What is to be done and who is to do it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Explain the term continuity of operations (COOP).

A

Continuity of operations or COOP is a term normally applied specifically to the US federal government. COOP is different from Business Continuity in that it entails movement of critical functions and personnel to an alternate operating site or sites in accordance with a pre established COOP plan.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is an effective tool that can be utilized in the developmental stage of an emergency plan for determining the probability of a threat or a disaster, and its impact on an organization?

A

To conduct a risk analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

An organization needs to develop an emergency plan depending on what factors?

A

On the nature of the organization’s activities, the organization’s criticality, its attractiveness as a target, and the type of facilities it occupies, among other considerations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

After what type pf action, each emergency plan should be evaluated and modified?

A

The emergency plan should be evaluated and modified as required after the following
1. Each training drill
2. Each emergency
3. Changes in personnel or their responsibilities
4. Changes in the facility’s physical design
5. Changes in policies or procedures.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Why does an all hazard approach works well?

A

An all hazard approach recognizes that many emergency planning requirements are similar regardless of whether an accident is natural threat, a human threat or an accident

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

In choosing a planning format for an emergency, what are the significant considerations?

A

The dissemination of the plan and the maintenance of the plan.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

While developing emergency operations plan what kind of approaches can be undertaken?

A

The emergency planning approaches are:
All hazard approach
Stand alone plans
A combination of all-hazard and stand alone

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

How is it possible to make emergency plan effective?

A

Every emergency plan should be reviewed and updated regularly.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Why is it essential that all emergency plans are reviewed at least once an year?

A

To ensure that all dynamic information such as floor plans, contact numbers, key personnel, and key assets are accurate.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Why is the all hazard approach better in comparison to the stand alone approach?

A

The all hazards approach is relatively simple and it is easier to disseminate information common to multiple emergencies like emergency contact numbers. On the other hand, in a series of stand alone plans, there is a need to update every plan each time common points of contacts or emergency number changes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

An EOP developed with _________ approach will address preparedness and response aspects of business continuity.

A

the all hazards approach

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Who can make risk analysis more manageable in an organization?

A

Managers directly involved in day-to-day operations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What is the purpose of an emergency plan?

A

To highlight the type of problems that decision makers and other key emergency management personnel will encounter and to require them to consider, in advance, how to react when an emergency develops.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

What is an effective plan?

A

A plan must reflect the requirements of the organization to which it pertains.
All persons tasked with responsibilities must clearly understand their responsibilities and be trained to fulfil them.
The plan must be tested through practice and should be revised in light of such testing.
It might need revisions, reassignment of responsibilities or retraining of personnel and thereafter retesting.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

What is the most important part of planning?

A

It is a continuous process that is never finished as long as the plan exists.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

Why are emergency tests and exercises conducted?

A

Checking the workability of a plan or a part thereof
Determining the level of staff awareness and training
Evaluating the adequacy of emergency communications
Identifying shortcomings in evaluation procedures.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

What are the elements that scope of the emergency training in the organization depends?

A

The scope of the training depends on the nature of the entity’s activities. Additionally, it depends on its employees, its recurring visitors, contractors and others who have frequent access to the facility.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

How to validate an organization’s emergency plan?

A

Conduct an unannounced test with appropriate controls and safeguards in place.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

What kind of special planning needs to be addressed in the development process of emergency plan?

A

Special planning needs such as personnel with disabilities, including those of vision hearing, mental function and mobility.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

To control losses, a business needs emergency response systems. What should be the components of emergency response systems?

A

People, equipment and procedures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

In setting priorities in EOP, certain time tested principles should be applied to the protection of life. What could be those principles?

A

Evaluation and shelter
Personnel protection
Relief and recue

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

What are the guiding principles for minimizing injuries?

A

Design safety and training

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

In developing EOP, why planning assumptions are considered?

A

Planning assumptions reduce the number of “what ifs.”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

What could be done to avoid gap in emergency plan maintenance?

A

There should be a designated alternative by name or position.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

After designating primary and alternate decision makers, what are important things to do?

A

It is important to brief, train and test them on their assigned duties and on most significant aspects of the planning process.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

Who should and should not handle emergencies?

A

A totally new organization should not be developed to handle emergencies. Existing organizations, temporarily reconfigured, along with executives responsible for the day to day operations of the enterprise should handle emergencies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

Who is one of the most important considerations in developing an emergency management structure?

A

To designate alternatives for the primary decision maker and for anyone else who is charged, by name or position, with a particular responsibility under the plan.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

What are the primary elements of an Incident Command System?

A

Command
Operations
Planning
Logistics
Finance and Administration

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

Based on what an organization ultimately determines its level of response during crisis or an emergency?

A

The nature and scope of the emergency.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

When the unified command is established?

A

If incident involves multiple agencies or multiple jurisdiction.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

What types of elements dictate the location and scope of EOC/CMC?

A

The size, nature and location of the organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
42
Q

In emergencies that develop during non working hours, telephone communications and electrical power may be severed preventing contact with appropriate executives and making road travel to the facility impossible. In such a situation, the initial implementation of the plan and control of the facility may rest under whom?

A

With the senior manager present at the site, who in some cases may be a security manager, security supervisor or security officer.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
43
Q

What pre-requisites must be fulfilled by the primary and alternate EOC/CMC?

A

The primary and alternate EOC/CMC locations should be able to accommodate the CMT and should provide redundant communication capacities. Additionally, the location should have backup power and an independent supply of portable water.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
44
Q

What is the most important ingredient in effectively managing an emergency event?

A

Communications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
45
Q

If an incident requires a public safety response, who is normally the incident commander?

A

The senior member of the responding agency.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
46
Q

Where are successions list recorded?

A

In a written emergency plan

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
47
Q

To avoid confusion, what should an emergency plan provide?

A

The orderly release of information, preferably through a single source in the organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
48
Q

In forming a mutual aid association, an organization’s emergency planners take a few steps. What are those steps?

A
  1. Obtain advise, assistance, and guidance of the government representatives responsible for disaster planning.
  2. Invite local industies, utilities and other businesses to send representatives to an organizational meeting.
  3. Arrange to have the group addressed by someone experienced in the operation of a mutual aid association.
  4. Elect association officer and appoint a coordinator.
  5. Appoint communities to develop plans and procedures for various aspects of mutual aid operations such as membership and bylaws, traffic and security control, fire protection, communications.
  6. Schedule periodic meetings
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
49
Q

What is the purpose of the mutual aid organization?

A

The purpose of the mutual aid organization is to establish a workable emergency management organization that minimizes damage and ensures the continued operation or early restoration of damaged facilities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
50
Q

When should the names of those who have been killed or injured in an emergency be released?

A

ASAP but relatives of victims should be informed before such information can be released to the public.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
51
Q

What can pose a serious challenge in an emergency?

A

Aiding the welfare and morale of employees and their families.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
52
Q

During or post crisis situation, what may have an extremely negative effect on public perception of the organization?

A

Any missteps connected to media relations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
53
Q

While developing the medical services portion of an emergency plan, what planners should ascertain first?

A

The type and capabilities of an in-house medical support.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
54
Q

With regards to fire and rescue operations, why a distinction needs to be made between industrial and non industrial facilities?

A

Because industrial facilities may have a volunteer in house fire and rescue operation; however, non-industrial facilities, particularly office buildings, operate differently. Their occupants are typically instructed to identify the problem, notify the appropriate authorities and evaluate the affected areas.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
55
Q

Why a survey of neighbouring installations should be conducted regularly?

A

To ascertain the existence of any potential hazards that could aggravate the impact of the crisis for the organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
56
Q

During an emergency, looting is a hazard that must be considered because spectators are attracted to any disaster scene. To maintain security and protect the assets and personnel, what measures should be undertaken?

A

Deployment of additional security personnel

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
57
Q

While planning for alerts and warning system, why outdoor as well as indoor warning systems must be considered?

A

Because individuals might be outdoors during an emergency.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
58
Q

Why should alert and warning systems be tested periodically?

A

So that employees can experience and become familiar

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
59
Q

What should be considered during emergency evacuation?

A
  1. Need to think well beyond simple sounding an alarm and asking the building occupants to move to the nearest emergenct exit.
  2. Consider alternate exits, routes and assembly points.
  3. Use of these alternates must be practiced regularly.
  4. Evacuation drill should continue till all occupants have reached the designated assembly points.
  5. The emergency plan needs to provide for shelter in place for situations where evacuation is infeasible or undesirable such as hazmat release, tornado, earthquake.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
60
Q

In evacuation planning, organizations must consider alternate exits, routes, and assembly points. Furthermore, use of these exits must be practiced regularly. What is one way to do so?

A

Block the primary exit for a different exit for a different floor or part of a building for each fire drill.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
61
Q

For which type of crisis situation, emergency plan should provide shelter in place?

A

When evacuation is infeasible or undesirable such as hazmat release, tornado, or earthquake.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
62
Q

During emergency shutdown, who may be the last to leave the facility or establishment when an evacuation is ordered or who may even have to stay in the facility?

A

Emergency shutdown crew

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
63
Q

If restoration has been planned, recovery is less difficult and more efficient. What can simplify emergency operations?

A

Developing a list of key recovery items simplifies emergency operations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
64
Q

Define business continuity

A

A comprehensive managed effort to prioritize key business processes, identify significant threats to normal operations, and plan mitigation strategies to ensure effective and efficient operational response to the challenges that surface during and after a crisis.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
65
Q

What is the use of a business impact analysis?

A

To identify an entity’s critical functions
To assess the impact of a disaster or other emergency on those functions over time
To determine the other elements of the business on which those critical functions depend, and
To help develop and prioritize recovery strategies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
66
Q

What is organizational resilience?

A

The adaptive capacity of an organization in a complex and changing environment and also it is the ability of an organization to resist being affected by an event or the ability to return to an acceptable level of performance in an acceptable period of time after being affected by an event.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
67
Q

What elements should be included in business continuity strategies?

A

Depending on the nature and needs of the business, business continuity strategies may include resumption and recovery in place, the contracting out of selected functions, or relocation of critical functions and personnel to one or more sites.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
68
Q

Who can find emergency or crisis overwhelming?

A

Those who have done no planning or preparation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
69
Q

What are the elements the primary training of emergency response personnel should focus?

A

The most likely situations and the location, construction, size and function of each site.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
70
Q

In large organizations with multiple locations, it is essential to ___________to ensure proper coordination throughout various sites.

A

require an overall emergency operations plan

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
71
Q

Emergency response requires

A

organization and structure.

72
Q

If an incident command system needs to be formally implemented due to the size of the incident,____________.

A

it would be a single incident command.

73
Q

If the incident involves multiple agencies or jurisdictions, then ___________.

A

a single command structure is typically established.

74
Q

With whom security professionals should built relationships?

A

Security professionals should build relationships with public safety and supply chain partners, conducting joint drills and other exercises.

75
Q

What is the major function of emergency response?

A

Coordinating across multiple groups and departments with differing responsibilities is a major function of emergency response.

76
Q

When should planners take a wide range of agencies and individuals?

A

Planners should take a wide range of agencies and individuals into account when developing an emergency plan.

77
Q

Information that may be obtained from some of these entities and other organizations can be of great value in _________.

A

developing and implementing the emergency plan.

78
Q

True or False?
In large organizations it is common for the senior leadership team to be separate from the CMT. This allows the senior leadership team to focus on strategic decisions that affect the organization’s strategic goals.

A

True.
Explanation: This allows the senior leadership team to focus on strategic decisions that affect the organization’s strategic goals.

79
Q

True or false?
Effective crisis planning includes all areas within the organization that can be activated if necessary.

A

True

80
Q

The crisis team list should describe what all for each person on the team?

A

Their role in the incident
Critical contact information and
Alternate chain of command.

81
Q

What are the three types of crisis team?

A

Operational team
Tactical crisis team
Strategic crisis team

82
Q

What should be the goal of continuity planning?

A

Save lives and reduce chances of further injuries or deaths
Protect assets
Restore critical business processes and systems
Reduce the length of the interruption of business
Protect reputation damage
Control media coverage (e.g. local, regional, national, or global)
Maintain customer relations (ASIS BCM 2021)

83
Q

Effective crisis management includes all areas within the organisation _____.

A

that can be activated if necessary.

84
Q

It is common for the senior leadership team to be separate from the CMT in ______.

A

Large organizations.

85
Q

What gives great value in developing and implementing the emergency plan?

A

Information that may be obtained from some of the entities and other organizations.

86
Q

What is essential in large organizations with multiple locations?

A

An overall emergency operations plan.

87
Q

What is essential to ensure recovery from business interruptions and to protect the profitability of the enterprise?

A

Planning

88
Q

What is a key part of preparing for an emergency?

A

Developing a plan.

89
Q

What is the emergency planning format depends on?

A

The nature of the organization and the organization’s policy.

90
Q

What is the best course of action for planning for organizations that are exposed to a variety of different types of threats and hazards?

A

An All Hazards Approach

91
Q

What is an All Hazards Approach?

A

This approach provides for a basic emergency operations plan (EOP), with sections that apply to multiple emergency situations.

92
Q

What is an Emergency Rendezvous Point?

A

The location that should be selected in advance to meet and brief the responding services in an emergency.

93
Q

To control losses, a business needs emergency response systems that can rapidly deploy to threatened locations and be supported operationally. What are these systems?

A

People, equipment, and procedures.

94
Q

Emergency plan should provide for ___________ for situations where evacuation is not possible.

A

Shelter in Place.

95
Q

One of the most important ingredients in effectively managing an emergency event is______________.

A

Communications

96
Q

What should be considered while planning an emergency warning system?

A

Ambient noise and distance.

97
Q

Sirens, Flashlights, Strobe Lights, Hooters and visual signs are examples of __________.

A

Warning Systems

98
Q

Responsibility of emergency shut down should be assigned to

A

People familiar with the process.

99
Q

If _________has been planned, recovery is less difficult and more efficient?

A

Restoration.

100
Q

The emergency plan should give priority to the ___________ after the emergency.

A

facility structure

101
Q

To whom should the emergency plan with contact numbers be distributed to?

A

To control centres and senior personnel with plan implementation responsibilities.

102
Q

Some organizations prepare a list of alternatives for key members of emergency management team. What is this list called?

A

Emergency succession list

103
Q

How can asset protection be ensured in emergency situations?

A

By not involving all security personnel in disaster or fire control activities. Also additional security personnel may be needed to maintain security and protect assets from looting.

104
Q

What is key to ensuring understanding and useability of emergency plan?

A

Training and testing

105
Q

When does crisis management begin?

A

Crisis management begins upon notification of any disruptive event.

106
Q

When should crisis communication plan be developed?

A

It is essential to have a crisis communication plan prepared in advance so that less time is spent determining what to say, how to say it, and by whom.

107
Q

What are elements of a crisis communication plan?

A

Planning, Training, Exercising, Response and Recovery

108
Q

What are elements of a crisis communication plan?

A

Planning, Training, Exercising, Response and Recovery

109
Q

Who is the communication advisor or lead?

A

It is typically the most senior communications person in the organization and is ultimately responsible for crisis communications.

110
Q

The handling of information concerning casualties is an important aspect of ___________.

A

human resources and public relations.

111
Q

Why is photographic coverage of incident scene important?

A

For insurance and legal purposes

112
Q

Who helps to make risk analysis more manageable?

A

Managers directly involved in day to day operations

113
Q

What is a critical but often misunderstood part of emergency planning?

A

The planning process is critical and often misunderstood.

114
Q

During an emergency it is best to avoid answering questions with ____________.

A

No comments.

115
Q

To avoid confusion, the emergency plan should provide for the orderly release of information, preferably through _________________.

A

a single source in the organization

116
Q

Setting priorities for asset protection and risk response planning is the responsibility of _________________.

A

the business risk owners.

117
Q

The word __________ often causes us to think immediately of evacuation as the primary response, but different types of crisis event can have different ideal responses.

A

emergency

118
Q

The crisis management team must be documented in the ______________.

A

crisis management plan.

119
Q

The most important part of the CCP is ____________.

A

the actual communications section.

120
Q

CCT members, as well as designated spokespeople, should receive _________communications training.

A

Annual

121
Q

____________facilities may have a volunteer in-house fire and rescue operation.

A

Industrial

122
Q

In setting priorities, what are certain time tested principles that should be applied to the protection of life?

A

Evacuation and shelter
Personal protection
Relief and Rescue

123
Q

What should be the considerations for emergency planning?

A
  1. Shelter
  2. Data search
  3. Assembly Areas
  4. Special Item Removal
  5. Alerting neighbours
  6. Shut down procedures
  7. Security
  8. Emergency Rendezvous point
124
Q

What are the reoccupation considerations that should be involved in emergency plan?

A
  1. Decisions
  2. Search
  3. Client and customers
125
Q

What are the guiding principles for preventing or minimizing injury?

A

Design safety
Training

126
Q

Who are the key members of a Crisis Communication Plan?

A

Senior Communications Advisor/Lead
Crisis Communications Team Lead
Crisis Communications Team (CCT)
Incident Command Staff

127
Q

Why are emergency tests and exercises conducted?

A

*Checking the workability of a plan or a part thereof;
*Determining the level of staff awareness and training;
*Evaluating the adequacy of emergency communications; and
*Identifying shortcomings in evacuation procedures.

128
Q

The rule should always be: train to the plan and exercise the plan. True or False

A

True

129
Q

What are the aspects of a crisis management plan?

A

*Crisis management team;
*Crisis management activation and escalation;
*Crisis command and management succession;
*Crisis recovery logistics and resources; and
*Crisis communications.

130
Q

The incident policies and procedures are tested through _________.

A

tabletop to full scale exercises and drills.

131
Q

What are the categories of a crisis?

A

natural or environmental, human, active, or cyber-based threats

132
Q

Natural or environmental, human, active or cyber based threats are examples of

A

crisis

133
Q

Methods of emergency drills, policies and procedures are__________.

A

Table top or full scale exercises and drills.

134
Q

Inclement weather can pose a serious threat to _____________.

A

property, critical infrastructure and lives.

135
Q

What improves the organization’s security culture and strengthens stakeholder’s trust in ESRM?

A

Transparency.

136
Q

What seeks to transition the security professional from a delegate role to a partner role?

A

ESRM

137
Q

A key outcome of a security risk assessment is to establish _________.

A

Risk prioritization

138
Q

What is the objective of ESRM?

A

To identify, evaluate and mitigate the impact of security risks

139
Q

What is root cause analysis?

A

A technique used to identify the conditions that initiate the occurrence of an undesired activity or state.

140
Q

What is a method of managing security risks?

A

Enterprise Security Risk Management.

141
Q

What is ESRM?

A

ESRM is a strategic approach to security management that ties an organization’s security practice to its overall strategy using globally accepted and established risk management principles. It is a management process or system.

142
Q

How is ESRM different from traditional program based security management?

A

It is not built around a security program.
It identifies all risks, prioritizes risks and develops specific mitigation steps.
ESRM does not assign a risk to a specific program.
Security managers transition from the delegated role of a security function to a trusted advisor to asset owners.
Security manager becomes a strategic resource for the organization.
In ESRM asset owners own decisions for the risks to the assets they manage.

143
Q

What are the major misconceptions of ESRM?

A

The first misconception is that ESRM is simply convergence or the joining of a traditional security program, corporate security, or physical security with information security/cybersecurity under one leadership.
The second misconception is that ESRM is enterprise risk management (ERM).

144
Q

What are the benefits of ESRM?

A
  1. Bring more resources and perspectives to the risk management process.
  2. Security professionals are trusted advisors and strategic partners as opposed to tactical owners of security programs.
  3. Security professionals can more effectively communicate and partner with asset owners.
  4. Will be better at risk identification and prioritization.
  5. As security professionals communicate with different stakeholders, they get better at prioritizing risks and formulating mitigation plans.
  6. With a risk-based approach, they can be more innovative in problem-solving.
  7. Security professionals can provide a broader depth in value and assist in reducing security and security related risks.
  8. There are fewer incidents and reduction in the impact of incidents.
  9. Budgets are more managable and supported.
  10. Security profesisonals can be asked to participate in other strategic areas.
145
Q

What are the benefits of ESRM to an organization

A
  1. ESRM enhances the organization’s resilience, event response and crisis management.
  2. ESRM enables critical risk decisions at the enterprise level, & better supports its mission and objectives.
  3. Allows asset owners to gain a broader and consistent understanding of the security function and security risk.
  4. Top management is able to better see key security risks.
  5. ESRM provides early identification and proactive monitoring of a broader range of risk.
  6. Security resources are better aligned to mitigate prioritized risks.
  7. ESRM improves understanding by and better engagement with stakeholders.
    8.ESRM provides better support for related legal, regulatory, and contractual functions and issues.
    9.ESRM provides a platform for security to become better integrated into the organization’s culture.
146
Q

What are the three components of ESRM?

A

The context of ESRM
The ESRM Cycle
The foundation of ESRM

147
Q

What is the first step in the new understanding of ESRM?

A

Bolstering the understanding of the mission and vision of an organization. It begins with a clear understanding of the products and services of an organization.

148
Q

Some important notes

A

How to adopt ESRM
The context of ESRM
Knowing key staff and leadership along with the organization’s operating structure will allow the security professional to smoothly navigate throughout the organization and find and build key relationships.
It is also critical to learn legal requirements and regulations that impact the organization and that the organization must follow.
Long-term strategic plans and goals are the roadmap for the organization. Being fully aware of both will help the security professional support their management partners and make decisions that will enable the organization to reach its goals.
An organization’s core values can indicate how well ESRM and its emphasis on partnership, collaboration, and transparency might be received by the corporate culture.

149
Q

What are arguably the pinnacle of organizational strategy?

A

The organization’s mission and vision are arguably the pinnacle of organizational strategy.

150
Q

What are the roadmap of an organization?

A

Long-term strategic plans and goals are the roadmap for the organization

151
Q

What are the points to consider while evaluating value and culture?

A

*How does the organization handle change?
*What is the organization’s risk tolerance/risk appetite?
*Are some business units more open to working with security than others?
*What do employee surveys indicate for value, culture, and change?
*Is there effective communication with all stakeholders in the organization?
*What are key motivators for the organization?

152
Q

What are the three kinds of operating environments?

A

Physical, non physical and logical.

153
Q

Who is a champion?

A

An asset owner with whom the security professional has worked and has an existing relationship

154
Q

What is the most defining characteristics of an ESRM cycle?

A

The most defining characteristic is its emphasis on understanding organizational assets and involving asset owners in the risk management process.

155
Q

What are the four processes of ESRM cycle?

A
  1. Identify and prioritize assets;
  2. Identify and prioritize risks;
  3. Mitigate prioritized risks; and
  4. Continuous improvement.
156
Q

Whatever is the scope for the ________ is also the scope for ESRM.
The security professional
Top management
Asset owner

A

Answer: The Security Professional

157
Q

What are the four critical concepts that comprise of the foundation of ESRM?

A

Holistic risk management
Partnership with stakeholders
Transparency
Governance

158
Q

What are the types of transparency relevant from the perspective of ESRM?

A

Risk transparency
Process transparency

159
Q

What does a documentation framework consist of?

A

Policies, standards, guidelines and procedures.

160
Q

What is the asset value based on?

A

The cost of purchasing or replacing the asset
The operational impact of unavailability of the asset through a business impact analysis
The effects of harm to the asset.
The time required to replace the asset
The reputational impact from unavailability of the asset.

161
Q

What are the activities a security professional should perform for identifying and prioritizing security risks?

A

Asset and security risk association
Risk assessment
Risk prioritization
Risk tolerance, appetite and capacity

162
Q

Why does risk identification require expansive thinking?

A

Because risk can arise from inside or outside the organization.

163
Q

What are the different types of risk treatments?

A

Acceptance, transference, spreading, avoidance and mitigation

164
Q

Which are the three security functions that contribute to continuous improvement (in ESRM)?

A

Incident response
Investigations and analysis
Information sharing.

165
Q

How does the process of investigation and analysis help in the continuous improvement of a security program?

A

Identifies possible areas of increased optimization in the management of specific risks
Improves effectiveness of responses and mitigation methods
Helps to identify root cause
Enables ongoing refinement and prioritization of information collection.

166
Q

What requires engagement with the asset owners and stakeholders to establish organizational policies, standards, and procedures to identify, monitor and manage enterprise security risks?

A

Successful and sustainable implementation of ESRM.

167
Q

When implementing ESRM, the security professionals should have a comprehensive understanding of the organization’s ______.

A

Mission and vision
Core values
Operating environment
Stakeholders

168
Q

What is an integral component and driver of corporate culture?

A

Organization’s core values

169
Q

What is essential to assess risks?

A

That the security professional understands the operating environment of the organization.

170
Q

What are the three main categories of the operating environment?

A

Physical, non physical and logical.

171
Q

What is the total amount of risk exposure that an enterprise wishes to undertake?

A

Risk Appetite

172
Q

How can a security professional bring ESRM practice to maturity and maintain high performance over time?

A

By continuously repeating the ESRM cycle.

173
Q

A thorough and integrated risk mitigation approach includes creating cohesion between __________.

A

People, Process and technology.

174
Q

What improves the organization’s security culture and strengthen stakeholder’s trust in ESRM?

A

Transparency.

175
Q

A key outcome of a security risk assessment is to establish _________.

A

Risk prioritization