CHAPTER SUMMARY

The BIA is a valuable tool that can help identify critical systems and resources. Once they have been identified, the MAO time for resources can then be identified. The impact of the outage and the MAO is then used to determine recovery priorities. Some systems may need to be up and operational almost immediately after a disaster, whereas other systems can be down for days at a time.

Two important terms related to the BIA are the recovery time objective (RTO) and recovery point objective (RPO). The RTO helps identify systems that are time critical, and the RPO helps identify systems that hold data that is mission critical.

KEY CONCEPTS AND TERMS

CHAPTER 12 ASSESSMENT

  1. The ________ identifies the maximum acceptable downtime for a system.
  2. Which of the following can determine what functions are considered critical business functions?
    1. Clients
    2. Stakeholders
    3. Project team
    4. Chief technology officer
  3. The BIA is a part of the ________.
  4. What defines the boundaries of a business impact analysis?
    1. MAO
    2. BCP
    3. Recovery objectives
    4. Scope
  5. What are two objectives of a BIA? (Select two.)
    1. Identifying minimum acceptable outage
    2. Documenting new policy
    3. Identifying critical resources
    4. Identifying critical business functions
  6. In developing a BIA, when calculating the costs to determine the impact of an outage for a specific system, both the direct and ________ costs should be calculated.
  7. In a BIA, the maximum amount of data loss an organization can accept is called what?
    1. BIA time
    2. Maximum acceptable outage
    3. Recovery time objectives
    4. Recovery point objectives
  8. What is the time required for a system to be recovered called?
    1. BIA time
    2. Maximum acceptable outage
    3. Recovery time objectives
    4. Recovery point objectives
  9. Which of the following statements is true?
    1. The RPO applies to any systems or functions, whereas the RTO refers only to data housed in databases.
    2. The RTO applies to any systems or functions, whereas the RPO refers only to data housed in databases.
    3. Both the RTO and RPO apply to any systems or functions.
    4. Both the RTO and RPO apply to data housed in databases.
  10. In a BIA, which one of the following is a direct cost of the impact of an outage for a specific system?
    1. Loss of customers
    2. Loss of public goodwill
    3. Loss of sales
    4. Lost opportunities
  11. What type of approach does a BIA use?
    1. Bottom-up approach in which servers or services are examined first
    2. Top-down approach in which CBFs are examined first
    3. Middle-tier approach
    4. Best-guess approach
  12. Mission-critical business functions are considered vital to an organization. What are they derived from?
    1. Critical success factors
    2. Critical IT resources
    3. Executive leadership
    4. Employees
  13. In developing a BIA, what should the critical business functions be mapped to?
    1. Personnel
    2. Revenue
    3. Replacement costs
    4. IT systems
  14. Of the following choices, which is (are) considered best practice(s) related to a BIA?
    1. Starting with clear objectives
    2. Using different data collection methods
    3. Mitigating identified risks
    4. A and B only
    5. All of the above
  15. A cost-benefit analysis is an important part of a BIA.
    1. True
    2. False
..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset