Writing Assignment: Module 10 Flashcards
Why might some organizations abdicate all responsibility for DR planning to the IT department?
They are keenly interested in keeping IT systems available during and immediately following disasters.
How can you classify disasters based on how they may emerge and become an issue for an organization?
The most common way is to separate natural disasters from man-made disasters. Another way of classifying disasters is by speed of development. Rapid-onset disasters are those that occur suddenly, with little warning, taking the lives of people and destroying the means of production. They may be caused by earthquakes, floods, storm winds, tornadoes, mud flows, and so on. Slow-onset disasters occur over time and slowly deteriorate the organization’s capacity to withstand their effects. These disasters include droughts, famines, environmental degradation, desertification, deforestation, and pest infestation.
What entity is responsible for creating the DR team? What roles should the DR team perform?
The CPMT. They aim to reestablish business processes.
Discuss the limitations on the number and type of CP teams to which any one individual should be assigned.
Disaster Management Team, Communications Team, Computer Recovery Team, System Recovery Team, Network Recovery Team
What key elements should be included in the DR policy?
Risk Assessment, Recovery Objectives, Data Backup and Storage, Recovery Procedures, Communication Plan, Training and Testing, and Continuous Improvement.
Why are the DR activity groups presented out of sequence (during, after, before) instead of in chronological order?
Activities that are during are the most urgent. After are the ones that have been resolved
What are the major activities planned to occur during the disaster?
planning for the triggers, determining what must be done
What are the major activities planned to occur after the disaster?
After action review, forensic analysis
What are the major activities planned to occur before the disaster?
preparing by practicing proper security
What is a DR plan addendum, and why will one or more of them be prepared?
DR plan addendum must be updated and revisited annually and you may have Multiple addendums to address specific scenarios or changes in the organization’s technology.
What is a DR after-action review (AAR), and what are the primary outcomes from it?
Once the incident has been contained and all signs of the incident removed, the “actions after” phase begins. During this phase, lost or damaged data is restored, systems are scrubbed of infection, and everything is restored to its previous state. The IR plan thus must describe the stages necessary to recover from the most likely events of the incident. It should also detail other events necessary to the “actions after” phase, such as possible follow-on incidents, forensic analysis, and the after-action review (AAR).
Why should DR planning documents be classified as confidential and have their distribution tightly controlled?
These plans can contain a wealth of sensitive data that would be a significant loss to the organization if the data fell into the wrong hands. Planners need to make arrangements for the ways that planning documents are copied and stored, to accommodate the availability requirement while making sure the necessary confidentiality is maintained.
What is a worst-case scenario? What role does it play in an organization’s planning process?
Service disruptions that may last for weeks or months and the govt could declare a state of emergency. And organizations should educated their staff what is expected of them.
What are the primary goals of the DR plan?
-Initiate implementation of secondary functions.
● Finalize implementation of primary functions.
● Identify additional needed resources.
● Continue planning for restoration
What are the key features of the DR plan?
● Clear delegation of roles and responsibilities
● Execution of the alert roster and notification of key personnel
● Use of employee check-in systems
● Clear establishment and communication of business resumption priorities
● Complete and timely documentation of the disaster
● Preparations for alternative implementations