Unit 2a Flashcards
Processes of backup and restoral
Contingency
Formal policy provides authority and guidance necessary to develop effective plan
Develop Contingency Planning Policy Statement
Helps identify and prioritize info systems and components critical to supporting organization’s mission/business processes
Conduct Business Impact Analysis (BIA)
Measures taken to reduce effects of system disruptions can increase system availability and reduce contingency life cycle costs
Identify Preventive Controls
Thorough recovery strategies ensure system can be recovered quickly and effectively following disruption
Create Contingency Strategies
Plan should contain detailed guidance and procedures for restoring damaged system unique to system’s security impact level and recovery requirements
Develop Information System Contingency Plan
Exercising plan identifies planning gaps; combined, activities improve plan effectiveness and overall organization preparedness
Ensure Plan Testing, Training, and Exercises
Plan is a living document and should be updated regularly to remain current with system enhancements and organizational changes
Ensure Plan Maintenance
Preserves authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information
Confidentiality
Guards against improper information modification or destruction, and
includes ensuring information nonrepudiation and authenticity
Integrity
Ensures timely and reliable access to and use of information
Availability
Provide means to restore local IT operations quickly and effectively following service disruption
Recovery Strategies
Focuses on restoring an organization’s mission essential functions (MEF) at an alternate site and performing those functions for up to 30 days before returning to normal operations at original location
COOP (Continuity of Operations)
Continuity of Operations Plan must include strategy to recover and perform system operations at alternate facility for extended period
Alternate Sites
Consist of facility with adequate space/infrastructure to support IT
Cold Sites
Partially equipped office spaces containing some or all system hardware, software, telecommunications, and power sources
Warm Sites
Office spaces appropriately sized to support system requirements and fully configured and ready to operate within a few hours
Hot Sites