Week 10 - Evaluating and Maintaining a BCP Flashcards

1
Q

When should a BCP be revised? (2)

A

After any significant changes that can include:

  1. Restructuring of the organization
  2. Launch of a new product

(Slide 03)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Why should a BCP be revised? (3)

A
  1. Complexity of the business service/organization has changed
  2. Adoption of new services or assets
  3. Provide continued assurance

(Slide 04)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Fill in the blank:

Evaluation identifies areas for ___________, _______ or _________ based on ____________ outcomes.

A

Improvement, Concerns, Weakness, Data-driven

(Slide 05)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Fill in the blank:

Assessments are a _________ basis for making __________ (conclusions based on data).

A

Systematic, Inferences

(Slide 05)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are four methods for evaluating and maintaining a BCP?

A
  1. Reviews
  2. Improvements
  3. Simulations
  4. Testing

(Slide 06)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

True or False:

Reviews are an assessment or examination of the BCP with the possibility or intention of changing it if necessary. It should seek to identify flaws or vulnerabilities in business processes.

A

TRUE

(Slide 07)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

When are improvements more of an effective tool?

A

After there has been a threat or incident and we have recovered from it.

(Slide 08)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What do simulations indicate?

A

It indicates that we are limited in scope, which means results are not accurate.

(Slide 09)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

True or False:

Testing applies strategies to check the quality, performance, or reliability of the BCP after putting it into use or practice.

A

FALSE - Its BEFORE not AFTER

(Slide 10)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

True or False:

Testing is one of the least effective strategies to enhance BCP.

A

FALSE - Its MOST not LEAST

(Slide 10)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are seven challenges to to testing BCPs?

A
  1. Difficult to emulate a disaster
  2. Testing in comfort zones does not produce a precise result
  3. Testers will test what they know works
  4. Lack of resources, executive support or organizational engagement
  5. Insufficient tools and technology
  6. Lack of routine testing
  7. Inability to monitor the program

(Slides 18-20)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is meant by “Testing in comfort zones does not produce a precise result”? (2)

A

It is very easy to test a plan under ideal circumstances.

The indications will never reflect true disaster recovery capabilities.

(Slide 18)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Explain how “testers will test what they know works” is a challenge of testing BCPs. (3)

A

It is difficult to examine or test areas that would only be vulnerable under moments of disasters

Limited scope of testing

Fails to challenge areas in which organizations are uncomfortable.

(Slide 19)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Is an Audit a form of assessment or evaluation?

A

Evaluation

(Slide 22)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is meant by audit?

A

It is a formalized method for evaluating how business continuity processes are being managed.

(Slide 23)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is the goal of an audit?

A

To determine whether the plan is effective and in line with the organization’s objectives.

(Slide 24)

17
Q

What is the objective of an audit? (2)

A

To ensure critical tasks such as limiting downtime during a business interruption, protecting personnel in the event of a disaster, minimizing financial losses due to a disruptive incident and restoring critical business functions and infrastructure following an incident.

With a BCP audit, the main goal is to ensure that the plan is up to completing these critical tasks.