DRI International BCP Examination

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/77

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 1:35 PM on 7/21/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

78 Terms

1
New cards

Business Continuity

An ongoing process to ensure that the necessary steps are taken to identify the impact of potential losses and maintain viable recovery strategies, recovery plans, and continuity of services. (NFPA 1600)

2
New cards

Disaster Recovery

The technical aspect of business continuity. The collection of resources and activities to re-establish information technology services (including components such as infrastructure, telecommunications, systems,

applications and data) at an alternate site following a disruption of IT services. Disaster recovery includes subsequent resumption and restoration of those operations at a more permanent site. (DRJ)

3
New cards

Risk Assessment

The quantification of threats to an organization and the probability of them being realized. (BCI)

4
New cards

Business Impact Analysis

A method of identifying the effects of failing to perform a function or requirement. (FCD-1)

5
New cards

Recovery Time Objective

Time goal for the restoration and recovery of functions or resources based on the acceptable down time and acceptable level of performance in case of a disruption of operations. (ASIS)

6
New cards

Recovery Point Objective

Point to which information used by an activity must be restored to enable the activity to operate on resumption. ISO Editor's Note: Can also be referred to as "maximum data loss". (ISO 22301)

7
New cards

Crisis Management

The overall coordination of an organization's response to a crisis, in an effective, timely manner, with the goal of avoiding or minimizing damage to the organization's profitability, reputation, and ability to operate. (DRJ)

8
New cards

Incident Management

The process by which an organization responds to and controls an incident using emergency response procedures or plans. (DRJ)

9
New cards

Incident Response

The response of an organization to a disaster or other significant event that may significantly impact the organization, its people, or its ability to function productively. An incident response may include evacuation of a facility, initiating a disaster recovery plan, performing damage assessment, and any other measures necessary to bring an organization to a more stable status.

(DRJ)

10
New cards

The Business Continuity Professional's Role

1. Establish the need for a business continuity program

2. Obtain support and funding for the business continuity program

3. Build the organizational framework to support the business continuity program

11
New cards

Scope

The boundary, or extent, to which a process, procedure, certification, or contract applies - considers the whole entity.

12
New cards

Objectives

Documents what will be delivered at the end of the project and what benefit that will provide to the entity.

13
New cards

Assumptions

Documents the assumptions you are making regarding the program.

14
New cards

The steering committee should ..

Determine/establish objectives, program structure, critical success factors and be involved in project/program management

15
New cards

In which area of the professional practices would you develop teams for the Business Continuity program?

Program initiation and management

16
New cards

Leadership is accountable/liable for?

Understanding their legal responsibilities to the business continuity program. The laws, regulations, contractual/employment agreements.

17
New cards

How often should you conduct a risk assessment?

Annually or as significant changes occur.

18
New cards

What is the first professional practice for Business Continuity Management?

Program Initiation and Management

19
New cards

What is the second professional practice for Business Continuity Management?

Risk Assessment

20
New cards

What is the third professional practice for Business Continuity Management?

Business Impact Analysis

21
New cards

What is the fourth professional practice for Business Continuity Management?

Business Continuity Strategies

22
New cards

What is the fifth professional practice for Business Continuity Management?

Incident Response

23
New cards

What is the sixth professional practice for Business Continuity Management?

Plan development and implementation

24
New cards

What is the seventh professional practice for Business Continuity Management?

Awareness and training programs

25
New cards

What is the eighth professional practice for Business Continuity Management?

Business continuity plan exercise, assessment, and maintenance

26
New cards

What is the ninth professional practice for Business Continuity Management?

Crisis communications

27
New cards

What is the tenth professional practice for Business Continuity Management?

Coordination with external agencies

28
New cards

To establish the need for a business continuity program you must:

Reference legal and regulatory requirements, reference relevant standards, show the benefits of the program within the context of the organization's mission.

29
New cards

Leadership is accountable and liable to know:

Their legal responsibilities including: applicable laws, regulations, and contractual and employment agreements.

30
New cards

What must you present to leadership to establish the need for business continuity management?

Legal and regulatory requirements

31
New cards

In which professional practice would you identify teams that will support the business continuity program implementation?

Program initiation and management

32
New cards

What is the role of the business continuity steering committee?

To implement objectives, program structure, and critical success factors.

33
New cards

Is program management a part of the steering committees role?

Yes, they help manage the business continuity program.

34
New cards

In which of the three elements of a business continuity plan would you put exclusions?

In the scope.

35
New cards

Who is legally responsible for the business continuity program and outcomes?

The CEO and leadership.

36
New cards

What information should be presented to leadership about the need for business continuity?

Legal and regulatory requirements.

37
New cards

Which team is responsible for defining the objectives, structure, policies, and charter for the business continuity program?

The steering committee.

38
New cards

What is the most critical element to the success of the business continuity planning effort?

Leadership commitment.

39
New cards

Which team provides resources and support to the business continuity program?

The steering committee.

40
New cards

The most important role for the business continuity professional in performing a risk assessment is?

To determine the probability and impact of the identified risks.

41
New cards

To collect data for risk assessments and BIA's one must use a combination of what methods?

Forms and questionnaires, interviews and meetings.

42
New cards

How often should a risk assessment be conducted?

Annually or as significant changes occur

43
New cards

The three most important sources of risk are?

Natural phenomena, technological exposure, human acts

44
New cards

Risk Appetite

The amount of risk that an organization is prepared to accept, tolerate, or be exposed to at any point in time.

45
New cards

The purpose of identifying and evaluating the effectiveness of existing controls is?

To mitigate impact exposures

46
New cards

Evaluating the effectiveness of controls involves?

Identifying the existing controls that are in place

47
New cards

Implementing controls and procedures ________?

Minimizes risk

48
New cards

Necessary changes in order to reduce the impact of identified risks include:

Changes to physical protection and changes to cyber security and information technology.

49
New cards

Resilience

The adaptive capacity of an organization in a complex and changing environment

50
New cards

Controls

Processes, procedures, or devices that prevent or mitigate impact exposures/risks

51
New cards

What is the number one emerging supply chain risk?

Cyber attack

52
New cards

Business interruption insurance

The requirement for calculation of adequate

insurance, covering financial loss due to temporary business cessation.

53
New cards

Extra expense insurance

Pays for extra expenses to maintain operations after an accident to an insured item until normal operations can be restored.

54
New cards

Contingent business interruption insurance

Reimburses for lost profits and extra expenses. due to an interruption relating to a customer or supplier.

55
New cards

What are the primary objectives of conducting a risk assessment?

To understand the entity's exposure to loss and evaluate the effectiveness of controls and safeguards.

56
New cards

What is describes mitigation?

Reducing risk

57
New cards

What is an objective of performing a risk assessment?

To identify risks that can adversely affect an entity's resources.

58
New cards

What are examples of quantitative impacts?

Percentages, numbers, money

59
New cards

What are examples of qualitative impacts?

High, medium, low

60
New cards

What is the number one objective of the BIA?

To prioritize functions and processes based on the level of criticality and time sensitivity

61
New cards

What is the second objective of the BIA?

To determine the recovery objectives for core and support functions and processes.

62
New cards

What is the third objective of the BIA?

To analyze the findings to ascertain any gaps between the entity's requirements and it's ability to deliver those requirements.

63
New cards

A BIA sets requirements not?

Strategies

64
New cards

Recovery Point Objective

The amount of data that you can tolerate to lose. Data that is not on the backup.

65
New cards

What is the primary goal of the BIA?

To gain acceptance of the RTO and RPO for each operational area

66
New cards

Sole Source Supplier

The only supplier of that resource, no other options.

67
New cards

Single Source Supplier

The only supplier that you choose to supply your resource, however there are other options out there.

68
New cards

What is one of the last steps in the BIA process?

To prepare a gap analysis

69
New cards

What are example gaps?

Resource, time, and data gaps

70
New cards

Impact should determine?

The frequency of backups

71
New cards

The greater the impact from lost data the?

More frequently backups should be completed

72
New cards

Objective of the BIA?

Entity function/process criticality and time sensitivity

73
New cards

What is the first planning professional practice?

Business Continuity Srategies

74
New cards

What is the objective for the professional practice: Business continuity strategies

Select cost-effective strategies to reduce deficiencies as identified during the risk assessment and business impact analysis (BIA) processes

75
New cards

Who is responsible for developing business continuity strategies?

The functional area manager

76
New cards

What is the difference between a regulation and a standard?

Regulations are enforceable by external agencies and you have to comply with them. While standards are not enforced and you can conform to them, they resemble best practices.

77
New cards

What are the four life safety procedures?

Evacuation, sheltering, shelter-in-place, and lockdown

78
New cards

Reciprocal Agreements need to be documented in what way?

External agreements need to be documented in writing.