Chapter 1: Security and Risk Management Flashcards
(35 cards)
NIST Document for Disaster Recovery
800-34
BCP
sustaining operation & more business than IT long term “the sky is fallen” now what do we do… umbrella term
DRP
part of the BCP plan.
Life Safety
1 Priority
Categories of Disaster
Non-disaster, urgent, disaster, catastropheemergency - an immediate event.
warm site
office furniture general equipment
hot site
ready to go in 24hrs
cold site
empty building
4 steps of BCP
project scope and planning, biz impact assessment, continuity planning, and approval and implementation
MTD
max tolerable downtime = WRT x RTO
bridges gap between BIA and BCP
strategy development task.
provision and process phase
BCP team designs procedures to mitigate risk
BCP Coordinator
only he can declare disaster.
wrt
CONFIGURE!!!! work recovery time to configure a recovered system (WRT) describes the time required to configure a recovered system.
mtbf
mean time between failures
BRP
provides plans to recover business after a disaster
RPO
Max amount of data loss a organization can withstand -recovery point objective example: how much time to go without a backup.
rto
RECOVER SYSTEM!!! max about of time to recover a biz system —-recovery time objective—–
WRT
work recovery time X RPO
Threat
Anything that can cause harm to an asset
Vulnerability
a weakness that allows a threat to cause harm.
Risk
Threat x Vulnerabilityadded variable called impact which addresses severity in dollars
EF
Exposure Factor is the percentage of value an asset lost due to an incident.
SLE
AV x EF