Security Architecture Domain 5 Flashcards
BCP is defined as:
- Preparation that facilitates the rapid recovery of mission-critical
business operations - The reduction of the impact of a disaster
- The continuation of critical business functions
DRP is defined as:
A subset of BCP that emphasizes the procedures for emergency
response relating to the information infrastructure of the
organization
DRP includes:
- Extended backup operations
- Post-disaster recovery for data center, network, and
computer resources
While performing the BIA, security architects should avoid using the term critical or essential in defining the processes or people during this phase of the planning. Instead, use the term __________
Time sensitive
All applications, and the business functions that they support, need to be classified as to their time sensitivity for recovery even if they do not support business functions that are time sensitive. For applications, this is commonly referred to as
Recovery Time Objective (RTO).
This is the amount of time the business can function without that application before significant business impact occurs.
Recovery Time Objective (RTO).
Decisions need to be made about all types of data because data is what is needed to run the business. How much data is it acceptable to lose? A minutes worth? An hour’s worth? A whole business day’s worth? The answers to these questions are used to determine the
Recovery Point Objective (RPO).
The RTO is determined during the …
Business Impact Analysis
BS 25999-2 was a British standard issued in 2007, which quickly became the main standard for business continuity management - although it is a British national standard, it was used in many other countries; on May 15, 2012 BS25999-2 was replaced by international standard
ISO 22301.
In addition to BS 25999-2, BS 25999-1 is an “auxiliary” standard which provides more details on
how to implement specific parts of BS 25999-2.
ISO 22301
is the new de-facto standard for Business Continuity Management.
ISO/IEC 27031
- Guidelines for information and communication
technology readiness for business continuity
PAS 200
Crisis management - Guidance and good practice
PD 25666
- Guidance on exercising and testing for continuity and
contingency programmes
PD 25111
- Guidance on human aspects of business continuity
ISO/IEC 24762
- Guidelines for information and communications
technology disaster recovery services
ISO/PAS 22399
- Guideline for incident preparedness and
operational continuity management 32
ISO/IEC 27001
- Information security management systems-
Requirements 33
NIST Special Publication 800-34 Rev 1 -
Contingency Planning
Guide for Federal Information Systems 34
Incremental backups take copies of only the files that are new or have changed since
the last full OR incremental backup was taken, and then set the
archive bit to “0.”
Differential backups copy only the files that are new or have changed since
the last full backup and do not change the archive bit value.
If an organization wants the backup and recovery strategy to be as simple as possible, then they should only use ______ backups.
full
In how many steps can a differential backup be restored
2
Which backup takes the longest to restore
Incremental