System Availability: BIA and Metrics

0.0(0)
studied byStudied by 0 people
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/25

flashcard set

Earn XP

Description and Tags

ISC 2 Mod 3

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

26 Terms

1
New cards

What is the first step in the BIA Process?

Establish the BIA Approach

2
New cards

What is the second step in the BIA Process?

Identify Critical Resources

3
New cards

What is the third step in the BIA Process?

Define Disruption Impacts

4
New cards

What is the fourth step in the BIA Process?

Estimate Losses

5
New cards

What is the fifth step in the BIA Process?

Establish Recovery Priorities

6
New cards

What is the sixth step in the BIA Process?

Create the BIA Report

7
New cards

What is the seventh step in the BIA Process?

Implement the BIA Recommendations

8
New cards

What trust services criteria does the BIA aid in?

Availability

9
New cards

What best describes step one of the BIA?

Agreement on the necessary approach to performing the BIA is critical and must first be clearly outlined by the organization.

10
New cards

What best describes step two of the BIA?

Management must clearly define critical functions in the organization and delineate which IT resources are required to perform them.

11
New cards

What best describes step three of the BIA?

The organization must identify and evaluate the impact of a service disruption by understanding its effects over time and the resources negatively affected or required to deal with the disruption.

12
New cards

What best describes step four of the BIA?

This step involves the management team outlining an exhaustive list of potential risks and events that could occur that would disrupt operations and assigning each of those threats a probability of likelihood.

13
New cards

What best describes step five of the BIA?

Management must prioritize recovery strategies to decide which tasks personnel should address first.

14
New cards

What best describes step six of the BIA?

These reports may be completed at the department level, business unit level, product level, or by any other appropriate means of segregating a business to evaluate risk, as long as all known risks have been addressed. These individual reports can then be combined to form a company-wide BIA.

15
New cards

What best describes step seven of the BIA?

This phase involves senior management evaluating the comprehensive BIA report, determining which risks pose the greatest threat, and implementing preventative or corrective actions to remediate those threats.

16
New cards

During which steps of the BIA process is the Annualized Rate of Occurrence (ARO) and Annualized Loss Expectancy (ALE) calculated?

Estimate Losses

17
New cards

During which step of the BIA process is the optimal Maximum Tolerable Downtime (MTD) and Mean Time to Repair (MTTR) calculated?

Establish Recovery Priorities

18
New cards

What is the Maximum Tolerable Downtime (MTD)?

The amount of time a business can tolerate an outage without causing long-term significant damage.

19
New cards

What is the Recovery Point Objective (RPO)?

The maximum threshold for acceptable data lost after an unplanned negative event. It defines the "age" of the data that must be recovered to resume normal operations.

20
New cards

What is the Recovery Time Objective (RTO)?

The maximum amount of time it should take to restore business operations to a target state following a system failure.

21
New cards

What is the Mean Time to Repair (MTTR)?

Average length of time it takes to repair a damaged or inoperable device.

22
New cards

What is the Recovery Time Actual (RTA)?

The actual time it takes to restore business operations to its target state after a system failure.

23
New cards

What is the Recovery Point Actual (RPA)?

The actual point in time to which data can be recovered.

24
New cards

What best describes high-impact in terms of BIA?

Cannot operate without the resource, high recovery cost, and may fail to meet the organizations objectives or maintain its reputation.

25
New cards

What best describes moderate/medium - impact in terms of BIA?

Can partially function temporarily, experience some cost of recovery, and may fail to meet the organizations objectives or maintain its reputation.

26
New cards

What best describes low-impact in terms of BIA?

Can operate for an extended period of time, and may notice an effect on achieving the organizations objectives or maintaining its reputation.