Writing Assignment: Module 10 Flashcards

1
Q

Why might some organizations abdicate all responsibility for DR planning to the IT department?

A

They are keenly interested in keeping IT systems available during and immediately following disasters.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How can you classify disasters based on how they may emerge and become an issue for an organization?

A

The most common way is to separate natural disasters from man-made disasters. Another way of classifying disasters is by speed of development. Rapid-onset disasters are those that occur suddenly, with little warning, taking the lives of people and destroying the means of production. They may be caused by earthquakes, floods, storm winds, tornadoes, mud flows, and so on. Slow-onset disasters occur over time and slowly deteriorate the organization’s capacity to withstand their effects. These disasters include droughts, famines, environmental degradation, desertification, deforestation, and pest infestation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What entity is responsible for creating the DR team? What roles should the DR team perform?

A

The CPMT. They aim to reestablish business processes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Discuss the limitations on the number and type of CP teams to which any one individual should be assigned.

A

Disaster Management Team, Communications Team, Computer Recovery Team, System Recovery Team, Network Recovery Team

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What key elements should be included in the DR policy?

A

Risk Assessment, Recovery Objectives, Data Backup and Storage, Recovery Procedures, Communication Plan, Training and Testing, and Continuous Improvement.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Why are the DR activity groups presented out of sequence (during, after, before) instead of in chronological order?

A

Activities that are during are the most urgent. After are the ones that have been resolved

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the major activities planned to occur during the disaster?

A

planning for the triggers, determining what must be done

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the major activities planned to occur after the disaster?

A

After action review, forensic analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the major activities planned to occur before the disaster?

A

preparing by practicing proper security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is a DR plan addendum, and why will one or more of them be prepared?

A

DR plan addendum must be updated and revisited annually and you may have Multiple addendums to address specific scenarios or changes in the organization’s technology.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is a DR after-action review (AAR), and what are the primary outcomes from it?

A

Once the incident has been contained and all signs of the incident removed, the “actions after” phase begins. During this phase, lost or damaged data is restored, systems are scrubbed of infection, and everything is restored to its previous state. The IR plan thus must describe the stages necessary to recover from the most likely events of the incident. It should also detail other events necessary to the “actions after” phase, such as possible follow-on incidents, forensic analysis, and the after-action review (AAR).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Why should DR planning documents be classified as confidential and have their distribution tightly controlled?

A

These plans can contain a wealth of sensitive data that would be a significant loss to the organization if the data fell into the wrong hands. Planners need to make arrangements for the ways that planning documents are copied and stored, to accommodate the availability requirement while making sure the necessary confidentiality is maintained.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is a worst-case scenario? What role does it play in an organization’s planning process?

A

Service disruptions that may last for weeks or months and the govt could declare a state of emergency. And organizations should educated their staff what is expected of them.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are the primary goals of the DR plan?

A

-Initiate implementation of secondary functions.
● Finalize implementation of primary functions.
● Identify additional needed resources.
● Continue planning for restoration

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are the key features of the DR plan?

A

● Clear delegation of roles and responsibilities
● Execution of the alert roster and notification of key personnel
● Use of employee check-in systems
● Clear establishment and communication of business resumption priorities
● Complete and timely documentation of the disaster
● Preparations for alternative implementations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Describe the phases in a DR plan.

A

a.Preparation — The planning and rehearsal necessary to respond to a disaster
b.Response — The identification of a disaster, notification of appropriate individuals, and immediate reaction to the disaster
c.Recovery — The recovery of necessary business information and systems
d.Resumption — The restoration of critical business functions
e.Restoration — The reestablishment of operations at the primary site, as they were before the disaster

17
Q

What is job rotation? Why is it a useful practice from a DR plan perspective?

A

The routine training of all employees for at least one other job, either vertically or horizontally prepares the organization to handle normal personnel shortages or outages

18
Q

What does it mean when operations are in degraded mode? Should organizations prepare to operate in this mode?

A

employees are operating under adverse conditions. When training, an organization should periodically try this variation, including the loss of power or lighting, the loss of communications,and so on, to see how employees can adapt to these conditions. During a disaster, it is very likely that some utilities will be unavailable.

19
Q

What should be the primary focus of the training that is provided to the network recovery team?

A

Much of their DR operations training should focus on establishing ad hoc networks quickly but securely.

20
Q

What are the primary duties of the business interface team?

A

This team is responsible for working with the remainder of the organization to assist in the recovery of nontechnology functions.

21
Q

Describe the various rehearsal and testing strategies that an organization can employ.

A

Use of an alert roster. Some organizations can make use of an auxiliary phone alert and reporting system. The use of the “I’m okay” automated emergency response line

22
Q

Why must the alert roster and the notification procedures that use it be tested more frequently than other components of the DR plan?

A

it is subject to continual change because of employee turnover

23
Q

What are the primary objectives of the response phase of the DR plan?

A

designed to:
Protect human life an dwell-being
Attempt to limit and contain the damage to the organization’s facilities and equipment
Manage communications with employees and other stakeholders

24
Q

What are the primary objectives of the recovery phase of the DR plan?

A

Recover critical business functions
Coordinate recovery efforts
Acquire resources to replace damaged or destroyed materials and equipment
Evaluate the need to implement the BC plan

25
Q

What are the primary objectives of the restoration phase of the DR plan?

A

Initiate implementation of secondary functions
Finalize implementation of primary functions
Identify additional needed resources
Continue planning for restoration