03. Business Continuity Plan (404) Flashcards

1
Q

Business Continuity Planning (BCP)

Business Continuity Plan - Emergency operations
Business Recovery Plan - Salvage, restoration, recovery

404

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Business Continuity Planning (BCP)

  • Business Continuity Planning (BCP) reduces risks related to onset of disasters or other disruptive events
  • Primary objective - Improve changes organisation will survive a disaster without costly or fatal damage to critical activities

404

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

BCP - Disasters

DIsasters are unexpected or unplanned events that result in disruption of business operations. Types include;

  1. Natural Disasters
  2. Human-Caused Disasters

405

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

BCP - Risk Analysis

  • During risk analysis, primary, secondary, upstream and downstream effects of a disaster scenario must be identified and considered
  • The person performing the analysis needs a broad understanding of interdependencies of business processes and IT systems
  • Personnel developing continguency and recovery plans need to be familiar with the effects of a disaster also to help plan adequately

410

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

BCP

BCP process is a life-cycle process. A set of activities that result in ongoing preparedness and need for review

A
  1. Assign ownership of program
  2. Develop BCP policy
  3. Conduct business impact analysis
  4. Perform criticality analysis
  5. Establish recovery targets
  6. Define KRIs and KPIs
  7. Develop Recovery and continuity strategies and plans
  8. Test recovery and continity plans and procedures
  9. Test intergration of business continuity and disaster recovery plans
  10. Train personnel
  11. Maintain strategies, plans, and procedures through periodic reviews and updates
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

BCP and COBIT

The COBIT objective lists 8 specific controls that constitute the BCP continuity life cycle;

  1. Define the business continuity policy, objectives, and scope
  2. Maintain business resilience
  3. Develop and implement a business continuity response
  4. Exercise, test, and review the BCP and DRP
  5. Review, maintain, and improve the continuity plans
  6. Conduct conttinuity plan training
  7. Manage backup arrangements
  8. Conduct post-resumption review

413

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Developing Continuity Plans

An organisation must develop the following procedures to be prepared;

  • Personnel safety procedures
  • Disaster declaration procedures
  • Responsibilities
  • Contact information
  • Recovery procedures
  • Continuing operations
  • Restoration procedures

413

A

Personnel safety procedures
Measures to ensure safety of personnel are first priority
Disaster declaration procedures
Initiated when a disaster is declared
Responsibilities
Assigning resposibilities for the execution and management of important tasks
Contact information

Recovery procedures
Processes and sequences (instructions) personnel use to recover critical systems
Continuing operations
Aligned more with business processes than IT operations. Procedures for continuing operations however may include IT systems and as such, both are related
Restoration procedures
Processes and procedures for transitioning back to normal business operations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Maintaining Recovery and Continuity Plans

BCPs are likely to be out of date within months, and obsolete within a year. A schedule should be implemented to review the plan as a minimum once a year, or when there is a major change

429

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Maintaining Recovery and Continuity Plans

Periodic testing of a disaster recovery plan and validation of dcuments is a vital activity

429

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Sources of Best Pracitce

THere are several sources of best practices and methodologies for BCP/DR planning;

  1. National Institute of Standards and Technology (NIST)
  2. National Incident Management Systems (NIMS)
  3. Business Continuity Institute (BCI)
  4. National Fire Protection Agency (NFPA)
  5. Federal Emergency Management Agency (FEMA)
  6. Disaster Recovery Institute Intenratioanl (DRI International)
  7. Business Continnuity Management Institute (BCM Institute)

430

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly