Podcast
Questions and Answers
What is contingency planning?
What is contingency planning?
Contingency planning is a program developed to prepare for, react to, and recover from events that threaten the security of an organization's information assets.
What is the main goal of contingency planning?
What is the main goal of contingency planning?
The main goal of contingency planning is to restore normal modes of operation with minimal cost and disruption to normal business activities after an unexpected event.
What are the four major components of contingency planning?
What are the four major components of contingency planning?
Contingency planning requires the active involvement of both IT and business managers.
Contingency planning requires the active involvement of both IT and business managers.
Signup and view all the answers
Which of the following are elements required to begin the contingency planning process?
Which of the following are elements required to begin the contingency planning process?
Signup and view all the answers
What does BIA stand for? What is it used for?
What does BIA stand for? What is it used for?
Signup and view all the answers
How does BIA differ from risk management?
How does BIA differ from risk management?
Signup and view all the answers
What is an Incident Response Plan (IRP) designed to do?
What is an Incident Response Plan (IRP) designed to do?
Signup and view all the answers
An Incident Response Plan (IRP) is only activated in the event of a major disruption or disaster.
An Incident Response Plan (IRP) is only activated in the event of a major disruption or disaster.
Signup and view all the answers
What is the purpose of incident classification?
What is the purpose of incident classification?
Signup and view all the answers
What are the three sets of incident-handling procedures created during the planning phase of an IRP?
What are the three sets of incident-handling procedures created during the planning phase of an IRP?
Signup and view all the answers
What are the two main tasks involved in incident containment?
What are the two main tasks involved in incident containment?
Signup and view all the answers
What is an alert roster?
What is an alert roster?
Signup and view all the answers
What is incident damage assessment, and when is it performed?
What is incident damage assessment, and when is it performed?
Signup and view all the answers
A Disaster Recovery Plan (DRP) focuses on preventing disasters from occurring.
A Disaster Recovery Plan (DRP) focuses on preventing disasters from occurring.
Signup and view all the answers
Under what circumstances is a disaster considered to have occurred?
Under what circumstances is a disaster considered to have occurred?
Signup and view all the answers
What is the main objective of a Disaster Recovery Plan (DRP)?
What is the main objective of a Disaster Recovery Plan (DRP)?
Signup and view all the answers
What are the main steps involved in developing a Disaster Recovery Plan?
What are the main steps involved in developing a Disaster Recovery Plan?
Signup and view all the answers
What is the primary role of the business manager in developing a Disaster Recovery Plan?
What is the primary role of the business manager in developing a Disaster Recovery Plan?
Signup and view all the answers
Rapid-onset disasters occur over a longer period of time, allowing for more preparation.
Rapid-onset disasters occur over a longer period of time, allowing for more preparation.
Signup and view all the answers
What is the purpose of a Business Continuity Plan (BCP)?
What is the purpose of a Business Continuity Plan (BCP)?
Signup and view all the answers
A Business Continuity Plan (BCP) is typically managed by the Chief Information Officer (CIO) of the organization.
A Business Continuity Plan (BCP) is typically managed by the Chief Information Officer (CIO) of the organization.
Signup and view all the answers
When is a BCP activated and executed?
When is a BCP activated and executed?
Signup and view all the answers
What are the three primary options for continuity strategies in a BCP?
What are the three primary options for continuity strategies in a BCP?
Signup and view all the answers
What is a hot site?
What is a hot site?
Signup and view all the answers
What are the three primary shared-use contingency options for a BCP?
What are the three primary shared-use contingency options for a BCP?
Signup and view all the answers
A timeshare involves leasing a pre-configured facility from a business partner or a sister organization.
A timeshare involves leasing a pre-configured facility from a business partner or a sister organization.
Signup and view all the answers
A service bureau provides a service for a fee, but the disadvantage is that contracts cannot be renegotiated.
A service bureau provides a service for a fee, but the disadvantage is that contracts cannot be renegotiated.
Signup and view all the answers
What is a mutual agreement in the context of a BCP?
What is a mutual agreement in the context of a BCP?
Signup and view all the answers
What is business resumption planning?
What is business resumption planning?
Signup and view all the answers
What are the five strategies commonly used to test contingency plans?
What are the five strategies commonly used to test contingency plans?
Signup and view all the answers
What is a desk check?
What is a desk check?
Signup and view all the answers
What is a structured walk-through?
What is a structured walk-through?
Signup and view all the answers
What is a simulation?
What is a simulation?
Signup and view all the answers
What is parallel testing?
What is parallel testing?
Signup and view all the answers
What is full interruption testing?
What is full interruption testing?
Signup and view all the answers
Study Notes
Information Security - Planning for Contingencies
- Contingency planning is a program designed to prepare for, react to, and recover from events threatening an organization's information assets.
- The main goal is to restore normal operations with minimal cost and disruption after unexpected events.
- Four teams are involved in contingency planning and operations: The CP team, the incident response team, the disaster recovery team, and the business continuity team.
- Contingency planning consists of four major components: Business Impact Analysis (BIA), Incident Response Plan (IRP), Disaster Recovery Plan (DRP), and Business Continuity Plan (BCP).
- Organizations can choose between a single plan or multiple interlocking plans.
- The CIO, system administrators, and CISO should actively participate in the creation and distribution of responsibilities.
- The contingency planning management team (CPMT) develops the CP document through these steps: Planning methodology, policy environment, understanding causes/effects of core issues(BIA), and financial/resource access. Develop the contingency planning policy statement, Conduct the BIA, Identify preventive controls, Develop recovery strategies, Develop an IT contingency plan, Plan testing, training, and exercises, and Plan maintenance.
- Contingency planning has hierarchies: Contingency planning, Business Impact Analysis, Disaster Recovery Planning, Business Continuity Planning, and Business Resumption Planning.
- The contingency planning lifecycle includes forming the CP team, conducting a BIA, developing subordinate planning policies, creating response strategies, developing subordinate plans, reviewing/revising as needed, developing the CP policy statement, identifying resource requirements, identifying recovery priorities, and identifying preventive controls.
- The BIA is the first phase, providing information about systems and threats. It differentiates from risk management by focusing on identifying controls to protect information versus assuming controls have been bypassed or failed.
- BIA stages include determining mission/business processes and recovery criticality, evaluating each business department, unit or division, identifying resource requirements, and identifying each business process.
- The Incident Response Plan (IRP) is a documented set of processes and procedures for anticipating, detecting, and mitigating the effects of unexpected events that compromise information resources. It's usually activated when incidents cause minimal damage and focuses on immediate response.
- The IRP policy involves defining roles/responsibilities for incident response, determining personnel mobilization, and specifying management commitment, policy purpose/objectives, scope, incident definitions, organizational structure, incident prioritization, performance measures, and reporting forms.
- IRP phases include planning, detection, during the incident, and after the incident.
- Incident detection is classifying possible incidents based on occurrences, e.g., overloaded network, or misbehaving system.
- Incident indicators include possible (unfamiliar files, unusual crashes), probable (unexpected activity, reported attacks), and definite (log changes, hacker tools).
- Reaction steps include notifying personnel, documenting the incident, defining incident containment strategies, and, recovering control of affected systems.
- Incident notification uses alert messages, email, phone recording, and text messages.
- Disaster recovery involves preparing for and recovering from disasters, whether natural or human-made. Disasters occur when containment/control of an incident is impossible or when damage is severe.
- Disaster recovery (DR) also involves defining how to reestablish operations, developing DR planning policy statements, reviewing BIAs, identifying preventive controls, developing recovery strategies, developing DR plan documents, and planning testing, training, and maintenance.
- A DR policy includes disaster classification(natural vs human made, speed of development), prioritizing roles/responsibilities, creating an alert roster, establishing priorities, creating documentation, determining action steps, and implementing alternative implementations.
- Disaster recovery backs up data/information/using traditional backups, electronic vaulting, remote journaling, and database shadowing.
- Crisis management covers actions taken during and after a disaster to affect people inside and outside the organization; involving supporting personnel, determining the event's impact, updating the public, communicating with stakeholders, and involving regulatory agencies and industry organizations.
- The Business Continuity Plan (BCP) ensures critical business functions continue during a disaster, is most effectively managed by the CEO, and is activated when major/long-term disaster recovery is needed.
- BCP structures can be similar to DR structures with minor differences in implementation.
- BCP strategies include hot sites (fully functional, duplicated resources), warm sites (similar to hot sites but less equipped), and cold sites (empty facility with minimal services).
- Business Resumption Planning (BRP) combines DR and BCP into a single planning document with separate teams for execution.
- Contingency plans are tested using five strategies: desk check, structured walk-through, simulation, parallel testing, and full interruption.
Studying That Suits You
Use AI to generate personalized quizzes and flashcards to suit your learning preferences.
Related Documents
Description
Test your knowledge on contingency planning in information security. This quiz covers essential components like Business Impact Analysis, Incident Response Plans, and more. Understand the roles of various teams involved in ensuring the continuity and recovery of organizational operations.