BC & DR Flashcards

(52 cards)

1
Q

What does BCP deal with?

A

Keeping business operations running

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does DRP deal with?

A

Restoring normal business operations after the disaster tales place

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are three common elements between BCP and DRP?

A
  • Identification of critical business functions
  • Identification of disaster scenarios
  • Experts
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What two assessments are commonly used to identify critical business functions?

A
  • Business Impact Assessment

- Vulnerability Assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What two elements are commonly used to rank possible disaster scenarios?

A

Probability and Impact

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What term is used to describe the blending of BCP and DRP into a single mission?

A

COOP (Continuity of Business Operations)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are 3 important elements of a BCP project?

A
  • Senior Management Support
  • Senior Management Involvement
  • Project Team Membership
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

A BCP project generally consists of which 4 components?

A
  • scope determination
  • BIA
  • BCP
  • Implementation
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the term used to describe a project scope when it grows beyond the original intent?

A

Scope Creep

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What type of assessment would you carry out determine which business functions are more resillient and which are more fragile?

A

Business Impact Assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How are the effects of an impact generally categorised?

A

Quantitative and Qualitative

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What 5 tasks need to be performed well as part if a Business Impact Assessment?

A
  1. Perform a Vulnerability Assessment
  2. Carry out a criticality assessment
  3. Determine the maximum tolerable downtime
  4. Establish recovery targets
  5. Determine resource requirements
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is a criticality assessment?

A

Determines how critically important a particular business function is to the ongoing viability of the organisation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What type of assessment determines the impact, both quantitative and qualitative - of the loss of a critical business function?

A

Vulnerability Assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Which type of assessment should identify critical support areas?

A

vulnerability assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the steps in a criticality assessment?

A
  1. Inventory all high level business functions and rank them in order of criticality
  2. Describe the impact of a disruption to each function on overall business operations.
  3. Estimate the duration of a disaster event
  4. Consider the impact of a disruption based on the length of time that a disaster impairs critical business functions.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What does MTD stand for in relation to BCP?

A

Maximum Tolerable Downtime

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What are the two objectives when assessing recovery targets?

A

Recovery Time Objective

Recovery Point Objective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What term is used to describe the maximum period of time in which a business process must be restored after a disaster?

A

Recovery Time Objective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What term is used to describe the maximum period of time in which data might be lost if a disaster strikes?

A

Recovery Point Objective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

4 typical resource requirements are:

A
  • IT Systems and application
  • Key personnel
  • Business equipment
  • Supplier and Partners
22
Q

What is the businesses highest priority in the event of a disaster?

A

Personnel safety

23
Q

What is the difference between an incremental and differential backup?

A

Differential takes a backup of changed files only since last full backup. Incremental takes a backup of changed files only whether it be since last full backup or last incremental backup

24
Q

What 3 things should be considered when scheduling a data backup plan?

A
  • time taken to perform backups
  • time taken to restore backups
  • procedures for restoring data
25
name 4 types of data backup
- Magnetic tape - Virtual Tape Library - Site replication - Remote backup (internet)
26
What type of agreement involves a software vendor sending a copy of its software code to a third party in the event of a disaster
Software escrow agreement
27
What are two ways of providing power during prolonged power outages?
UPS (Uninterrupted power supply) | Emergency electric generator
28
What is another benefit of a UPS asides from continued power supply?
Controlled Shutdown
29
What are the 5 common types of data sites?
``` Cold Site Warm Site Hot Site Reciprocal Site Multi-site ```
30
What is a cold site in relation to a DC?
Empty computer room with basic environmental facilities, ie UP, heating, ventilation, etc.
31
What is a warm site in relation to a DC?
A cold site with computers and communication links in place, but applications and business data must still be loaded
32
What is a hot site in relation to a DC?
Second live site mirroring the primary
33
What is a reciprocal site in relation to a DC?
agreement in place with third party that pledges availability of their DC in the event of a disaster
34
What is a multi site in relation to a DC?
Multiple sites used to run daily operations. site is also staffed
35
Which type of site provides the most rapid recovery in the event of a disaster but is also the most costly to maintain? Hot, Warm or Cold?
Hot
36
All employees in the organisation must know about the business continuity plan. True or False?
True
37
The salvage team is concerned with restoring full functionality to a damaged facility. What are generally the 4 steps to achieving this?
1. Damage assessment. 2. Salvage assets 3. Cleaning 4. Restoring facility to operational readiness
38
A recovery test that includes loading data onto recovery systems without taking the production systems down is otherwise known as:
a parallel test
39
What are the 5 basic functions that should be available after a failover (custover) test?
- User Access - Administrative Access - Support - Integrations to other applications - Reporting
40
What is the first step before starting a Business Continuity Plan?
Gaining senior management support
41
How can financial risk be calculated in relation to Business Continuity?
P * M = C | Probability of harm * Magnitude of harm = Cost of Prevention
42
Title IX of the "The Implementing The 9/11 Commission Reconsiderations Act of 2007" addresses what?
private sector organisations validate their readiness to recover by comparing their programs against an unnamed standard. NFPA 1600 recommended as the standard to be used.
43
What os the British Standard for having a Business Continuity Plan?
BS25999
44
What is the FFIEC BCP Booklet?
Federal Financial Institutions Examination Council
45
Do FFIEC state that a business should be aware of the BCP plans of its third party providers?
Yes
46
What is the US FInancial Integrity Regulatory Authority Rule 4370 (FINRA)
defines a minimum standard for BCP
47
What are additioinal regulations on Financial Frms in relation to BCP?
National Association of Insurance Commissioners (NAIC) National Futures Associatoin Compliance Rule 2-38 Electronic Funds Transfer Act Basel committee - for banks regarding BCP HIPAA - health
48
Which country in the world was the first to introduce a standard and certification program for BCP?
Singapore (Standard for Business COntinuity/Disaster Recovery Service Providers (SS507)
49
What is the Sarbanes Oxley Section 404?
Management assessment of Internal Controls. inlcudes management responsibility for maintaining financial repoting and assessment at end of yer
50
In Sarbanes Oxlet what is PCAOB?
Public Accounting Oversight Board - responsible for BCP
51
What is mobile site?
dc of anorganisation in a mobile trailer
52
Event impacts should be categorised as following?
Non-incident Incident Severe incident