1/131
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is the first step in any BCP/DR plan?
A Risk Assessment.
What do MTD, RTO, and RPO stand for, and why do they still matter once you move to the cloud?
Maximum Tolerable Downtime, Recovery Time Objective, Recovery Point Objective — they define acceptable downtime and data loss, and remain key business drivers even when backups live in the cloud.
Define continuity planning.
Ensuring the execution of essential functions; it's an integral component of organizational risk management.
Define risk management.
Identifying, analyzing, assessing, and communicating risk, then accepting, avoiding, transferring, or controlling it to an acceptable level given the costs and benefits.
What two outcomes does risk management for continuity of operations aim for?
(1) Identification and, if feasible, mitigation of significant threats. (2) Documentation of essential services.
What does a Business Continuity Threat Assessment do?
Defines potential threats — business-specific, local, regional, national, or global — and rates each by likelihood of occurrence and potential impact without controls. Higher rating = more significant threat.
What does a Business Continuity Risk Assessment evaluate?
The sufficiency of controls to prevent a threat or minimize its impact. The output is the residual risk for each threat.
Name the three options once a business continuity risk has been identified and assessed.
Lowering (lessening) risk, approving risk, and sharing risk.
What is "approving risk"?
An executive-level decision to knowingly accept a risk level even though it's outside the acceptable range.
What is "sharing risk"?
Distributing the risk and its consequences among two or more parties — e.g., outsourcing or insurance.
What is the objective of a Business Impact Assessment (BIA)?
To identify essential services/processes and their recovery time frames.
In BIA terms, what makes a service "essential"?
Its absence or disruption would cause significant, irrecoverable, or irreparable harm to the organization, employees, partners, community, or country.
Define Maximum Tolerable Downtime (MTD).
The total length of time an essential business function can be unavailable without causing significant harm to the business.
Define Recovery Time Objective (RTO).
The maximum amount of time a system resource can be unavailable before there's an unacceptable impact on other resources or business processes.
Define Recovery Point Objective (RPO).
The point in time, prior to a disruption, to which data can be recovered — i.e., the acceptable amount of data loss.
How has cloud computing transformed BCP/DR?
It gives organizations scalability, flexibility, and cost-effective backup — data can be replicated across geographically distributed data centers so operations aren't disrupted.
What challenges do organizations face with cloud backups?
Data privacy and security concerns, regulatory compliance, complexity of cloud environments, and SLA issues with providers.
How are AI and ML changing cloud backup management?
AI can predict some failures and cyber threats before they happen; ML algorithms optimize backup and recovery processes, reducing RTO/RPO.
List the module's four best practices for BCP/DR in the cloud.
Regularly update and test plans; keep clear communications; leverage cloud options and flexibility; focus on security and compliance.
Name the primary global cloud providers mentioned in the notes.
AWS (Amazon), Azure (Microsoft), GCP (Google), and Alibaba Cloud (international, mainly China).
What is multi-cloud?
Using two or more cloud providers together to deliver BCP/DR and other networking services, chosen by cost, technical requirements, geographic availability, and other factors.
Why choose a multi-cloud DR strategy instead of a single provider?
To avoid a single point of failure, cherry-pick best-of-breed services from each provider, and reduce dependency risk on any one vendor.
What is vendor lock-in, and how do you guard against it?
Becoming so dependent on a vendor that they control your decisions instead of you. Guard against it with multiple vendors, negotiating entry AND exit terms upfront, designing portable applications, and keeping on-premises as an option.
How does TechTarget define cloud backup, in short?
A service that copies and stores an organization's data on a remote, cloud-based server as protection against loss.
What is DRaaS?
Disaster Recovery as a Service — a vendor-hosted cloud service that replicates an organization's systems so it can fail over to the vendor's infrastructure during a disaster.
Name the "Big Tech" DR/BC offerings called out in the module.
Google Backup and DR, AWS Elastic Disaster Recovery, and Azure Reliability (including paired regions).
Per the ArsTechnica reading, what's a key risk of a cloud-based DR plan?
When something disrupts connectivity — like an internet or network outage — the cloud may not be your friend, because you can lose access to your own DR resources.
The module asks: does going 100% cloud create new risk? What's the concern?
Yes — relying entirely on the cloud can introduce new Single Points of Failure (SPOFs), such as dependence on one provider, one network path, or internet connectivity itself.
What is the purpose of High Availability (HA)?
To eliminate single points of failure, especially in mission-critical systems where disruption causes adverse business impact or financial loss.
How is High Availability typically measured?
As a percentage of uptime, usually specified in an SLA, and often expressed as a number of "9s" (e.g., 99.999%).
What uptime score does a solution fully resistant to failure or downtime achieve?
A 100% availability score.
What is a Single Point of Failure (SPOF)?
A single component whose failure would bring down the entire system or process — exactly what HA design and multi-cloud strategies try to eliminate.
What uptime claim does the vendor Webscale make in the module readings?
100% uptime using multi-cloud technology.
Describe a Hot Site.
Fully operational and ready to move into, configured with redundant hardware, software, and communications; data is replicated in real- or near-real time.
Describe a Warm Site.
An environmentally conditioned space partially equipped with IT and telecom equipment; systems must still be configured and data restored before use.
Describe a Cold Site.
A backup facility with power, HVAC, and secure access only — no staged equipment at all.
Describe a Mobile Site.
Self-contained, third-party-provided units that generally arrive equipped with required hardware, software, and peripherals; data must be restored.
Describe a Mirrored Site.
Fully redundant with real-time replication from the production site — it can assume processing with virtually no interruption.
Describe a Reciprocal Site.
Based on an agreement to have access to, or use of, another organization's facilities.
Which relocation strategy offers the fastest failover with virtually no interruption?
A mirrored site.
Which relocation strategy is cheapest but takes the longest to bring online?
A cold site — it has power, HVAC, and secure access, but no staged equipment.
What do (Disaster) Response Plans focus on?
Initial and near-term response: authority, plan activation, notification, communication, evacuation, relocation, coordination with public authorities, and security.
What do Contingency Plans focus on?
Immediate, near-term, and short-term alternate workforce and business processes.
What do Recovery Plans focus on?
Immediate, near-term, and short-term recovery of information systems, infrastructure, and facilities.
What do Resumption Plans do?
Guide the organization back to normal operations.
What do you call the combination of response, contingency, recovery, and resumption plans — and the discipline behind it?
The Business Continuity Plan (BCP), also called the Continuity of Operations Plan (COOP); the discipline itself is Business Continuity Management (BCM).
What are the three primary goals in a disaster scenario?
Protect the health of people involved; minimize damage; properly evaluate the scenario and take the proper steps.
What is a command and control center ("war room")?
A central place (with an alternate) where the Business Continuity Team gathers to direct operations, hold status meetings during the disaster, and finalize documentation afterward.
What is an Occupant Emergency Plan (OEP)?
A plan describing evacuation and shelter-in-place procedures to protect personnel health and safety. It's separate from the BCP, usually maintained by HR or facilities management.
During a disaster, who is allowed to communicate messages externally?
Only approved messages from the BCT, delivered through an assigned spokesperson who stays in contact with legal.
What are Operational Contingency Plans, and who owns them?
Plans for how an organization's essential business processes will be delivered during the recovery period; they're developed at the departmental level and owned by the business process owner.
Give an example of an operational contingency plan.
Physical keys as a backup for biometric building entry, rerouting online services to a call center if the internet is down, or backup processes to ensure people still get paid.
What happens during the Disaster Recovery Phase?
The organization restores or replaces damaged infrastructure, systems, and facilities — potentially including immediate failover to redundant systems, procuring equipment, restoring data, and rebuilding facilities.
What are the two major activities of the Resumption Phase?
Validation of Successful Recovery and Deactivation.
What is "Deactivation" in the resumption phase?
The official notification that the organization is no longer operating in emergency or disaster mode.
What is Validation of Successful Recovery?
The process of verifying that recovered systems are operating correctly and that data integrity has been confirmed — it should be the final step of every recovery procedure.
Whose responsibility is BCM governance?
The Board of Directors (or equivalent) — they provide oversight and guidance, authorize BCM-related policy, and are legally accountable for the organization's actions.
What is Executive Management's role in BCM?
Provide leadership, demonstrate commitment, allocate budget and resources, and — in an emergency — declare a disaster, activate the plan, and support the Business Continuity Team.
What is the Business Continuity Team (BCT)?
A cross-section of the organization with authority to make decisions on disaster prep, response, and recovery. After a disaster is declared, it assesses damage, manages response/communications/recovery, reports to executives, and delivers a post-disaster assessment.
What is the IT department's BCM responsibility?
Designing and supporting resilient systems, and recovering information and information systems in a disaster.
What is Internal Audit's role in BCM?
Auditing the BCP and its procedures and reporting findings to executive management — satisfying separation-of-duties and oversight best practices.
Which department handles official statements and media communication during a disaster?
The marketing/communications department.
Which department is responsible for personnel welfare and emergency-related services?
The HR department.
What are the three BCP testing methodologies?
Tabletop exercises, functional exercises, and full-scale testing.
What's the difference between a tabletop "structured review" and a "simulation"?
A structured review walks through one specific procedure to verify accuracy and completeness. A simulation tests participant readiness through a facilitator-presented scenario and questions.
What are Functional exercises?
Scenario-driven, limited-scope exercises — like the failure of one critical business function — that validate plans, procedures, resource availability, and participant readiness. They can run in a parallel or production environment.
What is Full-scale testing?
An enterprise-level test where normal operations are suspended and recovery/contingency plans are actually implemented as if a disaster were declared. Most accurate, but expensive and risky.
What does a Business Continuity Plan Audit validate?
How the business continuity program, in its entirety, is being managed.
Which ISACA certification covers BC/DR as part of a broader information-systems audit scope?
CISA — Certified Information Systems Auditor. It examines all information-system audit areas, not just BC/DR.
At minimum, how often should BCT membership, the BIA, and recovery/contingency plans be revisited?
Annually.
During Hurricane Ida (Aug. 2021), how did Louisiana data centers like Venyu and EdgeConneX stay online despite catastrophic grid damage?
They switched to backup diesel generators — Venyu ran on generators for more than 48 hours straight.
What SPOF lesson does the Ida generator story teach about "the cloud"?
The cloud still runs on physical data centers that depend on local power grids and fuel logistics — a regional disaster can threaten that physical layer even when the service on top feels abstract and distributed.
How did Venyu manage the risk of running generators through an extended grid outage?
It contracted an out-of-state fuel supplier with dedicated drivers and trucks to guarantee continuous diesel resupply.
What second infrastructure failure compounded New Orleans' emergency response during Ida?
A data center fire at City Hall knocked the city's emergency-preparedness websites offline.
What's the takeaway from the Ida case for a 100%-cloud contingency strategy?
Even cloud/data-center resilience ultimately depends on regional physical infrastructure — power, fuel, and connectivity — reinforcing why multi-region or multi-cloud design and SPOF-avoidance still matter.
What's the difference between an information security incident and an event?
An event is any observable occurrence in a system/network, even a benign one (a user logging in, a firewall blocking a connection). An incident is a violation or imminent threat of violation of security policy — an adverse event tied to a loss of confidentiality, integrity, or availability (CIA).
How does a disaster differ from a typical security incident?
A disaster results in widespread damage or destruction, loss of life, or drastic change to the environment — broader and more severe than most day-to-day security incidents.
Name the four incident types every organization should have a plan to defend against.
Intentional unauthorized access, Distributed Denial of Service (DDoS) attacks, malicious code (malware), and inappropriate usage.
Define a False Positive.
A security device triggers an alarm, but there was no actual malicious activity or attack.
Define a False Negative.
An intrusion detection device's inability to detect a true/actual security event under certain circumstances.
What four components make up an incident response program?
Policies (management directives), Plans (the Incident Response Plan), Procedures (detailed implementation steps), and People.
What are the six NIST CSF 2.0 functions behind the NIST SP 800-61 Rev. 3 incident response lifecycle?
Govern, Identify, Protect, Detect, Respond, and Recover.
What's the difference between the Incident Response Coordinator (IRC) and a Designated Incident Handler (DIH)?
The IRC is the central point of contact who maintains non-evidence incident documentation. A DIH is senior personnel responsible for incident declaration, liaising with executive management, and managing the Incident Response Team (IRT).
Who typically sits on an Incident Response Team (IRT)?
A cross-section of the org: senior management, InfoSec, IT, operations, legal, compliance, HR, public affairs/media relations, customer service, and physical security.
Before contacting law enforcement about an incident, what must you do first?
Speak with legal counsel — that decision should be made early in the incident response process, not after the fact.
What's the difference between a CSIRT and a PSIRT?
A CSIRT (Company/Computer Security Incident Response Team) investigates security incidents inside an organization. A PSIRT (Product Security Incident Response Team) is run by a hardware/software vendor to investigate, resolve, and disclose vulnerabilities in its own products.
What does CVSS stand for, and what does it score?
Common Vulnerability Scoring System — rates a vulnerability's severity 1–10 across the Base, Threat, Environmental, and Supplemental metric groups.
What's the difference between a vulnerability and an exploit?
A vulnerability is a flaw or weakness. An exploit is the concrete piece of software or reproducible steps that leverages that vulnerability to actually compromise a system — not every vulnerability has one (an unexploited one is a "theoretical vulnerability").
What is vulnerability chaining?
Attackers combine multiple vulnerabilities in sequence to get further into a network or system and gain more control — a pattern that's difficult to analyze and defend against.
What is an SBOM?
Software Bill of Materials — a comprehensive inventory of every component, library, and module in a piece of software, which lets an organization respond to new vulnerabilities faster.
What do VEX and CSAF stand for, and how do they relate to each other?
Vulnerability Exploitability eXchange (determines whether a vulnerability is actually relevant/exploitable for a given system) and Common Security Advisory Framework (a standard format for publishing security advisories). VEX is a profile within CSAF.
How is a "data breach" defined in the notes?
An incident resulting in compromise, unauthorized disclosure, unauthorized acquisition, unauthorized access, or unauthorized use or loss of control of legally protected PII.
Is there a single federal law requiring breach notification to all U.S. consumers?
No. Notification requirements are set mainly at the state level. Federal law only mandates notification for specific regulated sectors (health care, financial, investment) and for federal agencies.
What does GLBA require of a financial institution after a breach?
Notify affected customers once the institution becomes aware of unauthorized access to their information and determines, after a reasonable investigation, that misuse has occurred or is reasonably possible.
What does HITECH require when unsecured PHI is breached?
Covered entities must notify affected individuals when their unsecured PHI has been, or is reasonably believed to have been, breached — even if the breach happened through a business associate.
What's the difference between PHI and a PHR?
PHI (Protected Health Information) is health information maintained by a HIPAA-covered entity. A PHR (Personal Health Record) is health information provided and managed by the consumer themselves, for their own benefit.
Which state passed the first, most widely known breach-notification law, and when did it take effect?
California — the California Security Breach Information Act, effective 2003.
What does the South Carolina Security Breach Information Act require?
Businesses and state agencies must notify South Carolina residents when unauthorized access to their personal information has occurred (or is reasonably likely) and illegal use has occurred or is reasonably likely to occur.
Does it matter, for notification purposes, whether an organization stores data itself or through a cloud provider?
No — breach notification requirements apply regardless of whether an organization manages its data directly or through a third party such as a cloud service provider.
What's the core difference between NIST and ISO/IEC?
NIST is a U.S. government institute — its frameworks are free and it doesn't issue direct certifications. ISO/IEC is an international body that sells its standards documents and offers paid, internationally recognized certifications.