Week 10 - Evaluating and Maintaining a BCP Flashcards
When should a BCP be revised? (2)
After any significant changes that can include:
- Restructuring of the organization
- Launch of a new product
(Slide 03)
Why should a BCP be revised? (3)
- Complexity of the business service/organization has changed
- Adoption of new services or assets
- Provide continued assurance
(Slide 04)
Fill in the blank:
Evaluation identifies areas for ___________, _______ or _________ based on ____________ outcomes.
Improvement, Concerns, Weakness, Data-driven
(Slide 05)
Fill in the blank:
Assessments are a _________ basis for making __________ (conclusions based on data).
Systematic, Inferences
(Slide 05)
What are four methods for evaluating and maintaining a BCP?
- Reviews
- Improvements
- Simulations
- Testing
(Slide 06)
True or False:
Reviews are an assessment or examination of the BCP with the possibility or intention of changing it if necessary. It should seek to identify flaws or vulnerabilities in business processes.
TRUE
(Slide 07)
When are improvements more of an effective tool?
After there has been a threat or incident and we have recovered from it.
(Slide 08)
What do simulations indicate?
It indicates that we are limited in scope, which means results are not accurate.
(Slide 09)
True or False:
Testing applies strategies to check the quality, performance, or reliability of the BCP after putting it into use or practice.
FALSE - Its BEFORE not AFTER
(Slide 10)
True or False:
Testing is one of the least effective strategies to enhance BCP.
FALSE - Its MOST not LEAST
(Slide 10)
What are seven challenges to to testing BCPs?
- Difficult to emulate a disaster
- Testing in comfort zones does not produce a precise result
- Testers will test what they know works
- Lack of resources, executive support or organizational engagement
- Insufficient tools and technology
- Lack of routine testing
- Inability to monitor the program
(Slides 18-20)
What is meant by “Testing in comfort zones does not produce a precise result”? (2)
It is very easy to test a plan under ideal circumstances.
The indications will never reflect true disaster recovery capabilities.
(Slide 18)
Explain how “testers will test what they know works” is a challenge of testing BCPs. (3)
It is difficult to examine or test areas that would only be vulnerable under moments of disasters
Limited scope of testing
Fails to challenge areas in which organizations are uncomfortable.
(Slide 19)
Is an Audit a form of assessment or evaluation?
Evaluation
(Slide 22)
What is meant by audit?
It is a formalized method for evaluating how business continuity processes are being managed.
(Slide 23)
What is the goal of an audit?
To determine whether the plan is effective and in line with the organization’s objectives.
(Slide 24)
What is the objective of an audit? (2)
To ensure critical tasks such as limiting downtime during a business interruption, protecting personnel in the event of a disaster, minimizing financial losses due to a disruptive incident and restoring critical business functions and infrastructure following an incident.
With a BCP audit, the main goal is to ensure that the plan is up to completing these critical tasks.