quiz image

Week 9

LowRiskBlack avatar
LowRiskBlack
·
·
Download

Start Quiz

Study Flashcards

40 Questions

What is the primary goal of a business continuity and disaster recovery planning project?

To minimize the impact of a disaster on business operations

What is a disaster, according to the CISSP Guide to Security Essentials?

A natural or man-made event that significantly disrupts business operations

Which of the following is NOT an example of a natural disaster?

Cyber attack

What is the primary objective of testing business continuity and disaster recovery plans?

To identify vulnerabilities in the plan

What is the focus of business continuity and disaster recovery planning?

To minimize the impact of a disaster on business operations

What is an example of a geological disaster?

Earthquake

What is the purpose of training users in business continuity and disaster recovery planning?

To ensure that users understand their roles in the plan

What is the business continuity and disaster recovery planning life cycle?

A continuous process

What is a type of man-made disaster that can disrupt services and supplies?

Labor strike

What is a consequence of a disaster that affects business operations?

Delays in deliveries

What is the primary focus of BCP and DRP in terms of data security?

Availability

What is an example of a social-political disaster?

War

What is a consequence of a disaster that affects employees?

Employees or their family members are killed, injured, frightened, or caring for others

What is a type of utility disaster?

Power failure

What is a security pillar supported by BCP and DRP?

Only Availability

What is a consequence of a disaster that affects business operations?

Direct damage to facilities and equipment

What is a key aspect of Communications in Business Resumption Planning?

Emergency support of business processes

What is the primary goal of Restoration and Recovery in Business Resumption Planning?

To resume business operations in primary business facilities

What is an important aspect of Improving System Resilience and Recovery?

Data replication

What is a key component of Business Resumption Planning?

Access to procedures and business records

What is the purpose of Training Staff in Business Resumption Planning?

To prepare staff for everyday operations and recovery procedures

What is included in the Restoration and Recovery phase of Business Resumption Planning?

Repairs to facilities and equipment

What is a benefit of Server Clusters in Improving System Resilience and Recovery?

Improved availability

What is a key aspect of Access to Procedures and Business Records in Business Resumption Planning?

Maintaining access to business records and procedures

What is the primary component of a Business Impact Assessment (BIA)?

Inventory processes

What is the purpose of a recovery time objective (RTO)?

To establish a timeline for recovery

What is included in a DRP and BCP plan?

Personnel evacuation and safety

What type of BCP and DRP plan testing involves reviewing the plan document?

Document review

What is the purpose of a recovery point objective (RPO)?

To set a target for data recovery

What is the last step in a DRP and BCP plan?

Business resumption

What is the purpose of a maximum tolerable downtime (MTD)?

To determine the amount of downtime an organization can tolerate

What type of BCP and DRP plan testing involves a real-world simulation of a disaster?

Simulation

What is the primary goal of obtaining senior management buyoff on MTD, RTO, RPO, RCO, and RCapO?

To ensure business process continuity

What is the primary purpose of publishing recovery targets into a database or spreadsheet?

To maintain a centralized repository of business processes

What is the recovery time objective (RTO) for hot systems with high-speed backup media?

6-12 hours

Which of the following is a qualitative criterion for criticality analysis?

Reputation

What is the purpose of ranking business processes by criticality criteria?

To allocate resources based on process criticality

What is the recovery point objective (RPO) for a system with a recovery time objective (RTO) of 2-3 days?

Warm systems

What is the primary purpose of criticality analysis?

To rank business processes by criticality criteria

What is the maximum tolerable downtime (MTD) used for in criticality analysis?

To rank business processes by criticality criteria

Study Notes

Business Continuity and Disaster Recovery Planning

  • Running a business continuity and disaster recovery planning project involves developing business continuity and disaster recovery plans, testing them, training users, and maintaining a planning life cycle.

What is a Disaster?

  • A disaster is any natural or man-made event that disrupts business operations, requiring a significant and coordinated effort to achieve recovery.

Types of Disasters

  • Natural disasters include:
    • Geological: earthquakes, volcanoes, lahars, tsunamis, landslides, and sinkholes
    • Meteorological: hurricanes, tornados, wind storms, hail, ice storms, snow storms, rainstorms, and lightning
    • Other: avalanches, fires, floods, meteors and meteorites, and solar storms
    • Health: widespread illnesses, quarantines, and pandemics
  • Man-made disasters include:
    • Labor: strikes, walkouts, and slow-downs that disrupt services and supplies
    • Social-political: war, terrorism, sabotage, vandalism, civil unrest, protests, demonstrations, cyber attacks, and blockades
    • Materials: fires, hazardous materials spills
    • Utilities: power failures, communications outages, water supply shortages, fuel shortages, and radioactive fallout from power plant accidents

How Disasters Affect Businesses

  • Disasters can cause:
    • Casualties: employee or family member injuries, fatalities, or care for others
    • Direct damage to facilities and equipment
    • Transportation infrastructure damage: delays deliveries, supplies, and employee commutes
    • Communications outages
    • Utilities outages

How BCP and DRP Support Data Security

  • BCP and DRP support availability, which is one of the three pillars of data security, along with confidentiality and integrity.

Developing Key Recovery Targets

  • Obtain senior management buy-in on key recovery metrics, such as:
    • MTD (maximum tolerable downtime)
    • RTO (recovery time objective)
    • RPO (recovery point objective)
    • RCO (recovery consistency objective)
    • RCapO (recovery capacity objective)
  • Publish these metrics in a database or spreadsheet listing all business processes.

Sample Recovery Time Objectives

  • RTOs vary depending on the technology required, such as:
    • 8-14 days: new equipment, data recovery from backup
    • 4-7 days: cold systems, data recovery from backup
    • 2-3 days: warm systems, data recovery from backup
    • 12-24 hours: warm systems, recovery from high-speed backup media
    • 6-12 hours: hot systems, recovery from high-speed backup media
    • 3-6 hours: hot systems, data replication
    • 1-3 hours: clustering, data replication
    • < 1 hour: clustering, near real-time data replication

Criticality Analysis

  • Rank processes by criticality criteria, such as:
    • MTD
    • RTO
    • RPO
    • RCO
    • RCapO
    • Cost of downtime or other metrics
    • Qualitative criteria: reputation, market share, goodwill

Business Resumption Planning

  • Business resumption planning involves:
    • Alternate work locations
    • Alternate personnel
    • Communications: emergency, support of business processes
    • Standby assets and equipment
    • Access to procedures, business records

Restoration and Recovery

  • Restoration and recovery involve:
    • Repairs to facilities and equipment
    • Replacement equipment
    • Restoration of utilities
    • Resumption of business operations in primary business facilities

Improving System Resilience and Recovery

  • Improving system resilience and recovery involves:
    • Off-site media storage: assurance of data recovery
    • Server clusters: improved availability, geographic clusters
    • Data replication: hardware, OS, DBMS, application, current data on multiple servers even in remote places

Training Staff

  • Training staff involves:
    • Everyday operations
    • Recovery procedures
    • Emergency procedures
    • Resumption procedures

Test your knowledge of business continuity and disaster recovery planning, including developing, testing, and training plans. Based on Chapter 4 of the CISSP Guide to Security Essentials.

Make Your Own Quizzes and Flashcards

Convert your notes into interactive study material.

Get started for free
Use Quizgecko on...
Browser
Browser