CYB410-Module1&2

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/131

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 10:08 PM on 9/10/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

132 Terms

1
New cards

What is the first step in any BCP/DR plan?

A Risk Assessment.

2
New cards

What do MTD, RTO, and RPO stand for, and why do they still matter once you move to the cloud?

Maximum Tolerable Downtime, Recovery Time Objective, Recovery Point Objective — they define acceptable downtime and data loss, and remain key business drivers even when backups live in the cloud.

3
New cards

Define continuity planning.

Ensuring the execution of essential functions; it's an integral component of organizational risk management.

4
New cards

Define risk management.

Identifying, analyzing, assessing, and communicating risk, then accepting, avoiding, transferring, or controlling it to an acceptable level given the costs and benefits.

5
New cards

What two outcomes does risk management for continuity of operations aim for?

(1) Identification and, if feasible, mitigation of significant threats. (2) Documentation of essential services.

6
New cards

What does a Business Continuity Threat Assessment do?

Defines potential threats — business-specific, local, regional, national, or global — and rates each by likelihood of occurrence and potential impact without controls. Higher rating = more significant threat.

7
New cards

What does a Business Continuity Risk Assessment evaluate?

The sufficiency of controls to prevent a threat or minimize its impact. The output is the residual risk for each threat.

8
New cards

Name the three options once a business continuity risk has been identified and assessed.

Lowering (lessening) risk, approving risk, and sharing risk.

9
New cards

What is "approving risk"?

An executive-level decision to knowingly accept a risk level even though it's outside the acceptable range.

10
New cards

What is "sharing risk"?

Distributing the risk and its consequences among two or more parties — e.g., outsourcing or insurance.

11
New cards

What is the objective of a Business Impact Assessment (BIA)?

To identify essential services/processes and their recovery time frames.

12
New cards

In BIA terms, what makes a service "essential"?

Its absence or disruption would cause significant, irrecoverable, or irreparable harm to the organization, employees, partners, community, or country.

13
New cards

Define Maximum Tolerable Downtime (MTD).

The total length of time an essential business function can be unavailable without causing significant harm to the business.

14
New cards

Define Recovery Time Objective (RTO).

The maximum amount of time a system resource can be unavailable before there's an unacceptable impact on other resources or business processes.

15
New cards

Define Recovery Point Objective (RPO).

The point in time, prior to a disruption, to which data can be recovered — i.e., the acceptable amount of data loss.

16
New cards

How has cloud computing transformed BCP/DR?

It gives organizations scalability, flexibility, and cost-effective backup — data can be replicated across geographically distributed data centers so operations aren't disrupted.

17
New cards

What challenges do organizations face with cloud backups?

Data privacy and security concerns, regulatory compliance, complexity of cloud environments, and SLA issues with providers.

18
New cards

How are AI and ML changing cloud backup management?

AI can predict some failures and cyber threats before they happen; ML algorithms optimize backup and recovery processes, reducing RTO/RPO.

19
New cards

List the module's four best practices for BCP/DR in the cloud.

Regularly update and test plans; keep clear communications; leverage cloud options and flexibility; focus on security and compliance.

20
New cards

Name the primary global cloud providers mentioned in the notes.

AWS (Amazon), Azure (Microsoft), GCP (Google), and Alibaba Cloud (international, mainly China).

21
New cards

What is multi-cloud?

Using two or more cloud providers together to deliver BCP/DR and other networking services, chosen by cost, technical requirements, geographic availability, and other factors.

22
New cards

Why choose a multi-cloud DR strategy instead of a single provider?

To avoid a single point of failure, cherry-pick best-of-breed services from each provider, and reduce dependency risk on any one vendor.

23
New cards

What is vendor lock-in, and how do you guard against it?

Becoming so dependent on a vendor that they control your decisions instead of you. Guard against it with multiple vendors, negotiating entry AND exit terms upfront, designing portable applications, and keeping on-premises as an option.

24
New cards

How does TechTarget define cloud backup, in short?

A service that copies and stores an organization's data on a remote, cloud-based server as protection against loss.

25
New cards

What is DRaaS?

Disaster Recovery as a Service — a vendor-hosted cloud service that replicates an organization's systems so it can fail over to the vendor's infrastructure during a disaster.

26
New cards

Name the "Big Tech" DR/BC offerings called out in the module.

Google Backup and DR, AWS Elastic Disaster Recovery, and Azure Reliability (including paired regions).

27
New cards

Per the ArsTechnica reading, what's a key risk of a cloud-based DR plan?

When something disrupts connectivity — like an internet or network outage — the cloud may not be your friend, because you can lose access to your own DR resources.

28
New cards

The module asks: does going 100% cloud create new risk? What's the concern?

Yes — relying entirely on the cloud can introduce new Single Points of Failure (SPOFs), such as dependence on one provider, one network path, or internet connectivity itself.

29
New cards

What is the purpose of High Availability (HA)?

To eliminate single points of failure, especially in mission-critical systems where disruption causes adverse business impact or financial loss.

30
New cards

How is High Availability typically measured?

As a percentage of uptime, usually specified in an SLA, and often expressed as a number of "9s" (e.g., 99.999%).

31
New cards

What uptime score does a solution fully resistant to failure or downtime achieve?

A 100% availability score.

32
New cards

What is a Single Point of Failure (SPOF)?

A single component whose failure would bring down the entire system or process — exactly what HA design and multi-cloud strategies try to eliminate.

33
New cards

What uptime claim does the vendor Webscale make in the module readings?

100% uptime using multi-cloud technology.

34
New cards

Describe a Hot Site.

Fully operational and ready to move into, configured with redundant hardware, software, and communications; data is replicated in real- or near-real time.

35
New cards

Describe a Warm Site.

An environmentally conditioned space partially equipped with IT and telecom equipment; systems must still be configured and data restored before use.

36
New cards

Describe a Cold Site.

A backup facility with power, HVAC, and secure access only — no staged equipment at all.

37
New cards

Describe a Mobile Site.

Self-contained, third-party-provided units that generally arrive equipped with required hardware, software, and peripherals; data must be restored.

38
New cards

Describe a Mirrored Site.

Fully redundant with real-time replication from the production site — it can assume processing with virtually no interruption.

39
New cards

Describe a Reciprocal Site.

Based on an agreement to have access to, or use of, another organization's facilities.

40
New cards

Which relocation strategy offers the fastest failover with virtually no interruption?

A mirrored site.

41
New cards

Which relocation strategy is cheapest but takes the longest to bring online?

A cold site — it has power, HVAC, and secure access, but no staged equipment.

42
New cards

What do (Disaster) Response Plans focus on?

Initial and near-term response: authority, plan activation, notification, communication, evacuation, relocation, coordination with public authorities, and security.

43
New cards

What do Contingency Plans focus on?

Immediate, near-term, and short-term alternate workforce and business processes.

44
New cards

What do Recovery Plans focus on?

Immediate, near-term, and short-term recovery of information systems, infrastructure, and facilities.

45
New cards

What do Resumption Plans do?

Guide the organization back to normal operations.

46
New cards

What do you call the combination of response, contingency, recovery, and resumption plans — and the discipline behind it?

The Business Continuity Plan (BCP), also called the Continuity of Operations Plan (COOP); the discipline itself is Business Continuity Management (BCM).

47
New cards

What are the three primary goals in a disaster scenario?

Protect the health of people involved; minimize damage; properly evaluate the scenario and take the proper steps.

48
New cards

What is a command and control center ("war room")?

A central place (with an alternate) where the Business Continuity Team gathers to direct operations, hold status meetings during the disaster, and finalize documentation afterward.

49
New cards

What is an Occupant Emergency Plan (OEP)?

A plan describing evacuation and shelter-in-place procedures to protect personnel health and safety. It's separate from the BCP, usually maintained by HR or facilities management.

50
New cards

During a disaster, who is allowed to communicate messages externally?

Only approved messages from the BCT, delivered through an assigned spokesperson who stays in contact with legal.

51
New cards

What are Operational Contingency Plans, and who owns them?

Plans for how an organization's essential business processes will be delivered during the recovery period; they're developed at the departmental level and owned by the business process owner.

52
New cards

Give an example of an operational contingency plan.

Physical keys as a backup for biometric building entry, rerouting online services to a call center if the internet is down, or backup processes to ensure people still get paid.

53
New cards

What happens during the Disaster Recovery Phase?

The organization restores or replaces damaged infrastructure, systems, and facilities — potentially including immediate failover to redundant systems, procuring equipment, restoring data, and rebuilding facilities.

54
New cards

What are the two major activities of the Resumption Phase?

Validation of Successful Recovery and Deactivation.

55
New cards

What is "Deactivation" in the resumption phase?

The official notification that the organization is no longer operating in emergency or disaster mode.

56
New cards

What is Validation of Successful Recovery?

The process of verifying that recovered systems are operating correctly and that data integrity has been confirmed — it should be the final step of every recovery procedure.

57
New cards

Whose responsibility is BCM governance?

The Board of Directors (or equivalent) — they provide oversight and guidance, authorize BCM-related policy, and are legally accountable for the organization's actions.

58
New cards

What is Executive Management's role in BCM?

Provide leadership, demonstrate commitment, allocate budget and resources, and — in an emergency — declare a disaster, activate the plan, and support the Business Continuity Team.

59
New cards

What is the Business Continuity Team (BCT)?

A cross-section of the organization with authority to make decisions on disaster prep, response, and recovery. After a disaster is declared, it assesses damage, manages response/communications/recovery, reports to executives, and delivers a post-disaster assessment.

60
New cards

What is the IT department's BCM responsibility?

Designing and supporting resilient systems, and recovering information and information systems in a disaster.

61
New cards

What is Internal Audit's role in BCM?

Auditing the BCP and its procedures and reporting findings to executive management — satisfying separation-of-duties and oversight best practices.

62
New cards

Which department handles official statements and media communication during a disaster?

The marketing/communications department.

63
New cards

Which department is responsible for personnel welfare and emergency-related services?

The HR department.

64
New cards

What are the three BCP testing methodologies?

Tabletop exercises, functional exercises, and full-scale testing.

65
New cards

What's the difference between a tabletop "structured review" and a "simulation"?

A structured review walks through one specific procedure to verify accuracy and completeness. A simulation tests participant readiness through a facilitator-presented scenario and questions.

66
New cards

What are Functional exercises?

Scenario-driven, limited-scope exercises — like the failure of one critical business function — that validate plans, procedures, resource availability, and participant readiness. They can run in a parallel or production environment.

67
New cards

What is Full-scale testing?

An enterprise-level test where normal operations are suspended and recovery/contingency plans are actually implemented as if a disaster were declared. Most accurate, but expensive and risky.

68
New cards

What does a Business Continuity Plan Audit validate?

How the business continuity program, in its entirety, is being managed.

69
New cards

Which ISACA certification covers BC/DR as part of a broader information-systems audit scope?

CISA — Certified Information Systems Auditor. It examines all information-system audit areas, not just BC/DR.

70
New cards

At minimum, how often should BCT membership, the BIA, and recovery/contingency plans be revisited?

Annually.

71
New cards

During Hurricane Ida (Aug. 2021), how did Louisiana data centers like Venyu and EdgeConneX stay online despite catastrophic grid damage?

They switched to backup diesel generators — Venyu ran on generators for more than 48 hours straight.

72
New cards

What SPOF lesson does the Ida generator story teach about "the cloud"?

The cloud still runs on physical data centers that depend on local power grids and fuel logistics — a regional disaster can threaten that physical layer even when the service on top feels abstract and distributed.

73
New cards

How did Venyu manage the risk of running generators through an extended grid outage?

It contracted an out-of-state fuel supplier with dedicated drivers and trucks to guarantee continuous diesel resupply.

74
New cards

What second infrastructure failure compounded New Orleans' emergency response during Ida?

A data center fire at City Hall knocked the city's emergency-preparedness websites offline.

75
New cards

What's the takeaway from the Ida case for a 100%-cloud contingency strategy?

Even cloud/data-center resilience ultimately depends on regional physical infrastructure — power, fuel, and connectivity — reinforcing why multi-region or multi-cloud design and SPOF-avoidance still matter.

76
New cards

What's the difference between an information security incident and an event?

An event is any observable occurrence in a system/network, even a benign one (a user logging in, a firewall blocking a connection). An incident is a violation or imminent threat of violation of security policy — an adverse event tied to a loss of confidentiality, integrity, or availability (CIA).

77
New cards

How does a disaster differ from a typical security incident?

A disaster results in widespread damage or destruction, loss of life, or drastic change to the environment — broader and more severe than most day-to-day security incidents.

78
New cards

Name the four incident types every organization should have a plan to defend against.

Intentional unauthorized access, Distributed Denial of Service (DDoS) attacks, malicious code (malware), and inappropriate usage.

79
New cards

Define a False Positive.

A security device triggers an alarm, but there was no actual malicious activity or attack.

80
New cards

Define a False Negative.

An intrusion detection device's inability to detect a true/actual security event under certain circumstances.

81
New cards

What four components make up an incident response program?

Policies (management directives), Plans (the Incident Response Plan), Procedures (detailed implementation steps), and People.

82
New cards

What are the six NIST CSF 2.0 functions behind the NIST SP 800-61 Rev. 3 incident response lifecycle?

Govern, Identify, Protect, Detect, Respond, and Recover.

83
New cards

What's the difference between the Incident Response Coordinator (IRC) and a Designated Incident Handler (DIH)?

The IRC is the central point of contact who maintains non-evidence incident documentation. A DIH is senior personnel responsible for incident declaration, liaising with executive management, and managing the Incident Response Team (IRT).

84
New cards

Who typically sits on an Incident Response Team (IRT)?

A cross-section of the org: senior management, InfoSec, IT, operations, legal, compliance, HR, public affairs/media relations, customer service, and physical security.

85
New cards

Before contacting law enforcement about an incident, what must you do first?

Speak with legal counsel — that decision should be made early in the incident response process, not after the fact.

86
New cards

What's the difference between a CSIRT and a PSIRT?

A CSIRT (Company/Computer Security Incident Response Team) investigates security incidents inside an organization. A PSIRT (Product Security Incident Response Team) is run by a hardware/software vendor to investigate, resolve, and disclose vulnerabilities in its own products.

87
New cards

What does CVSS stand for, and what does it score?

Common Vulnerability Scoring System — rates a vulnerability's severity 1–10 across the Base, Threat, Environmental, and Supplemental metric groups.

88
New cards

What's the difference between a vulnerability and an exploit?

A vulnerability is a flaw or weakness. An exploit is the concrete piece of software or reproducible steps that leverages that vulnerability to actually compromise a system — not every vulnerability has one (an unexploited one is a "theoretical vulnerability").

89
New cards

What is vulnerability chaining?

Attackers combine multiple vulnerabilities in sequence to get further into a network or system and gain more control — a pattern that's difficult to analyze and defend against.

90
New cards

What is an SBOM?

Software Bill of Materials — a comprehensive inventory of every component, library, and module in a piece of software, which lets an organization respond to new vulnerabilities faster.

91
New cards

What do VEX and CSAF stand for, and how do they relate to each other?

Vulnerability Exploitability eXchange (determines whether a vulnerability is actually relevant/exploitable for a given system) and Common Security Advisory Framework (a standard format for publishing security advisories). VEX is a profile within CSAF.

92
New cards

How is a "data breach" defined in the notes?

An incident resulting in compromise, unauthorized disclosure, unauthorized acquisition, unauthorized access, or unauthorized use or loss of control of legally protected PII.

93
New cards

Is there a single federal law requiring breach notification to all U.S. consumers?

No. Notification requirements are set mainly at the state level. Federal law only mandates notification for specific regulated sectors (health care, financial, investment) and for federal agencies.

94
New cards

What does GLBA require of a financial institution after a breach?

Notify affected customers once the institution becomes aware of unauthorized access to their information and determines, after a reasonable investigation, that misuse has occurred or is reasonably possible.

95
New cards

What does HITECH require when unsecured PHI is breached?

Covered entities must notify affected individuals when their unsecured PHI has been, or is reasonably believed to have been, breached — even if the breach happened through a business associate.

96
New cards

What's the difference between PHI and a PHR?

PHI (Protected Health Information) is health information maintained by a HIPAA-covered entity. A PHR (Personal Health Record) is health information provided and managed by the consumer themselves, for their own benefit.

97
New cards

Which state passed the first, most widely known breach-notification law, and when did it take effect?

California — the California Security Breach Information Act, effective 2003.

98
New cards

What does the South Carolina Security Breach Information Act require?

Businesses and state agencies must notify South Carolina residents when unauthorized access to their personal information has occurred (or is reasonably likely) and illegal use has occurred or is reasonably likely to occur.

99
New cards

Does it matter, for notification purposes, whether an organization stores data itself or through a cloud provider?

No — breach notification requirements apply regardless of whether an organization manages its data directly or through a third party such as a cloud service provider.

100
New cards

What's the core difference between NIST and ISO/IEC?

NIST is a U.S. government institute — its frameworks are free and it doesn't issue direct certifications. ISO/IEC is an international body that sells its standards documents and offers paid, internationally recognized certifications.