7 - Business Continuity and Disaster Recovery Plan Flashcards
- Once a business continuity plan is developed and approved by senior management, what final critical element must be addressed?a. Filing of the plan with local emergency servicesb. Performing a qualitative risk analysisc. Creating awareness of the plan throughout the organizationd. Perform a structured walk-through test
C: This is the final required step in business continuity planning.
- Each time the business continuity plan is updated or revised, what must be done?a. Perform a new cost/benefit analysisb. A checklist test must be performedc. Update your countermeasuresd. Destroy all copies of all old version of the plan.
D: This is a required step to ensure that only one version of the plan is distributed within the organization. 9. What is the primary objective of a disaster recovery plan?
- What is the primary objective of a disaster recovery plan?a. To recover critical processes in a timely mannerb. Manage public relations after a crisisc. To minimize financial loss during normal operations outaged. Re-design the security infrastructure of the organization after an emergency
A: This is the primary objective of a disaster recovery plan.
- Which of the following is not an objective of a disaster recovery plan?a. Protecting the organization from significant loss due to the failure of its IT infrastructureb. Empowering personnel for decision making during a crisis situationc. Minimizing risks to the organization from delays in providing servicesd. Guaranteeing the reliability and availability of standby systems through testing and evaluation
B: An objective of a disaster recovery plan is to minimize decision making during a crisis.
- The security issue that addresses ongoing processing activity in the face of minor disruptive events is known as?a. business continuity planningb. disaster recovery planningc. mission critical relocation planningd. redundancy development planning
A: Business continuity planning is the security issue that addresses ongoing processing activity in the face of minor disruptive events.
- Who is ultimately responsible for the business continuity planning?a. Disaster recovery teamb. IT staffc. End usersd. Senior management
D: Senior management is ultimately responsible for the success or failure of the business continuity plan. 5. Which of the following is not one of the three primary goals of business impact analysis?
- Which of the following is not one of the three primary goals of business impact analysis?a. Plan testing and verificationb. Criticality prioritizationc. Downtime estimationd. Resource requirements
A: Business impact analysis is the disaster equivalent of risk analysis, it does not have an implementation plan associated with it and there such a plan does not need testing or verification.
- Which of the following is not an aspect of quantitative loss criteria associated with business impact analysis?a. Financial loss due to violations of contract agreementsb. Loss of competitive advantage or market sharec. Financial losses due to capital expenditured. Losses associated with financial liability expenditures
B: This is a qualitative loss criteria.
- Business continuity planning is designed to handle what sort of conditions?a. Moderate disruptive eventsb. Major disruptive events to very destructive eventsc. Daily work activitiesd. Total destruction of a company and its assets
A: Business continuity planning is designed to handle moderate disruptive events.
- Which of the following is not a goal of business continuity planninga. Reduce the risk of financial lossb. Reformulate the security policy to more adequately prepare for intrusion attempts during the recovery processc. Recover from a disruptive event quicklyd. Mitigate the risks associated with a disruptive event
B: This is not a goal of business continuity planning. This is part of the normal review and improvement process of the formalized security structure.
- What is the top priority of business continuity planning?a. Quick and efficient recovery of the organizationb. Minimizing financial losses due to a disruptive eventc. Safety of the personneld. Managing public opinion about the organization during a crisis
C: The top priority of business continuity planning is the safety of personnel.
- Which of the following is considered an essential element of due care and due diligence?a. creation of InfoSec teamsb. business continuity and disaster recovery planningc. delegating implementation tasks to subordinatesd. senior management sign off on all security planning
B: Business continuity and disaster recovery planning are considered essential elements of due care and due diligence.
- Business continuity planning should address all but which of the following?a. local area network componentsb. telecommunicationsc. employee personal possessionsd. applications and software
C: Employee personal possessions are the responsibility of the employees, not the organization and its business continuity planning.
- Which of the following is not an event that would be considered to trigger application of the business continuity plan?a. fire in the data centerb. earthquake resulting in broken communication linesc. floods affecting the basement levels onlyd. an intrusion attack that compromises a Web server
D: Intrusion attacks are not events that trigger the business continuity plan. Instead, intrusion attacks trigger normal InfoSec or CIRT response teams.
- Which of the following is not a goal or objective of business continuity planning?a. reduce the risks associated with a disruptive eventb. minimize costs associated with recovering from a disruptive eventc. promptly recover from a disruptive eventd. provide a procedural guide so minimal decisions are made during an event.
B: Business continuity planning does not deal with recovering from disruptive events, rather maintaining business activity during a disruptive event. Disaster recovery planning deals with recovery.
- Which of the following should be accomplished first when acting out a business continuity plan?a. Restore critical functionsb. Restore non-critical functionsc. Maintain personnel safetyd. Locate an alternate site
C: Maintaining personnel safety is always the first and top priority.
- What is the primary difference between a disaster recovery plan and a business continuity plan?a. The severity of the damage to the area caused by a disasterb. The use of a secondary sitec. The cost of maintenanced. The interruption of mission critical processes
D: The primary difference is whether mission critical processes are interrupted. If they are, then disaster recovery is used, if not, then business continuity is used.
- Although the activities themselves can be delegates, who is ultimately responsible for all phases of business continuity planning?a. Senior managementb. InfoSec teamsc. Systems auditord. Department managers
A: Senior management is always ultimately responsible for all aspects of security and maintaining productivity in their organization, even though the actual tasks to accomplish this may be delegated.
- Which of the following is not a goal of business impact assessment?a. criticality prioritizationb. establishing resource requirementsc. personnel safetyd. downtime estimation
C: Personnel safety is the most important factor for business continuity and disaster recovery planning. However, it is not a factor or goal of a business impact assessment.
- The Maximum Tolerable Downtime estimation is an indication of whata. how long the business continuity plan takes to developb. how long the business continuity plan takes to implementc. how long the migration to the secondary site will taked. how long can mission critical processes be down and still allow the organization to recover
D: The Maximum Tolerable Downtime estimation is an indication of how long can mission critical processes be down and still allow the organization to recover.
- The business continuity planning task of identifying key business processes, ordering those processes, and evaluating event impact is known as? a. criticality prioritizationb. business impact assessmentc. vulnerability assessmentd. quantative analysis
B: Business impact assessment is the business continuity planning task of identifying key (critical) business processes, ordering (prioritizing) those processes, and evaluating event impact.
- When performing a business impact analysis, which of the following is the least useful assessment material item to gather?a. organizational chartb. mission statementc. definition of business unitsd. outline of relationships within the organization
B: The mission statement is inconsequential and useless to the act of business impact analysis.
- Which of the following is not one of the four aspects or elements of a business continuity plan?a. business impact assessmentb. scope and plan initiationc. business continuity plan developmentd. testing
D: While testing is important, it is not one of the four primary elements of a business continuity plan. In fact, testing seems to be mentioned only in relation to disaster recovery planning.
- When updating or maintaining a business continuity plan, which of the following is most important?a. only a single version of the plan should exist throughout the organizationb. each department should develop and maintain their own planc. the business continuity plan cannot make recommendations outside of the organization’s security policyd. keeping the cost of the plan to a minimum
A: Only a single version of the business continuity plan should exist throughout the organization.