Flashcards: Information Security and Continuity Planning — 63 cards

All cards

1Question

What does information security protect in an organization?

Answer

An organization's valuable resources.

2Question

What are the three basic information security requirements?

Answer

Availability, integrity, and confidentiality.

3Question

What does availability assure in information security?

Answer

That authorized users can access a system whenever needed.

4Question

What does integrity protect in a computer system?

Answer

System information from unauthorized changes.

5Question

What does confidentiality assure about protected information?

Answer

That unauthorized people cannot access it.

6Question

What is identification in information security?

Answer

How users claim their identities.

7Question

What does authentication test in information security?

Answer

Evidence of identity.

8Question

What does authorization grant to users?

Answer

Rights and permissions.

9Question

Why does information classification focus protection on certain data?

Answer

Because not all data has the same value to an organization.

10Question

Which private-sector classification term is similar to unclassified?

Answer

Public

11Question

What classification term describes very sensitive data harming a company if disclosed?

Answer

Confidential

12Question

Who identifies the administrator or custodian in the classification procedure?

Answer

The classification procedure itself specifies the administrator or custodian.

13Question

What role does the information owner have in classification?

Answer

The information owner determines the required classification and delegates protection duties.

14Question

What is a security policy in information security?

Answer

The highest level of documentation guiding security implementation.

15Question

What does the senior management statement of policy acknowledge?

Answer

The importance of computing resources.

16Question

What does the senior management policy commit to managing?

Answer

Lower-level standards, procedures, and guidelines.

17Question

How do standards differ from guidelines in security policies?

Answer

Standards are compulsory and uniform, guidelines are flexible and non-compulsory.

18Question

What do procedures contain in security documentation?

Answer

Detailed steps for performing specific tasks.

19Question

Who has ultimate security responsibility in an organization?

Answer

The senior manager.

20Question

Who determines data classification in security roles?

Answer

The owner.

21Question

Why is security awareness training necessary?

Answer

Because people are often the weakest link in a security chain.

22Question

What does risk management do before mitigating or transferring risk?

Answer

It identifies, analyzes, and assesses risk.

23Question

What does risk analysis examine in a target environment?

Answer

It examines risk-related attributes and vulnerabilities.

24Question

What does risk analysis associate vulnerabilities with?

Answer

Affected assets.

25Question

What does risk analysis determine and evaluate?

Answer

Potential undesirable results and risk-reducing countermeasures.

26Question

What does risk assessment assign value to?

Answer

Assets, threat frequency, consequences, and elements of chance.

27Question

What must risk decisions consider about the impact?

Answer

How severe the impact could be.

28Question

What frequency aspect must risk decisions consider?

Answer

How often the risk could happen annually.

29Question

What cost-related factors must risk decisions consider?

Answer

Annualized cost and cost-effectiveness of mitigation.

30Question

What formula defines Single Loss Expectancy (SLE)?

Answer

SLE=Asset Value×Exposure FactorSLE = Asset\ Value \times Exposure\ Factor

31Question

What does Exposure Factor measure in risk management?

Answer

The magnitude of loss on an asset as a percentage of its value.

32Question

How is Exposure Factor expressed?

Answer

As a percentage from 0 to 100% of asset value lost.

33Question

What does Annualized Rate of Occurrence (ARO) represent?

Answer

The frequency a threat is expected to occur annually.

34Question

Give an example of an Annualized Rate of Occurrence (ARO).

Answer

50 occurrences in one year produce an ARO of 50.

35Question

What formula defines Annualized Loss Expectancy (ALE)?

Answer

ALE=SLE×AROALE = SLE \times ARO

36Question

What formula calculates the value of a safeguard?

Answer

Value of safeguard=ALEbeforeALEafterannual safeguard costValue\ of\ safeguard = ALE_{before} - ALE_{after} - annual\ safeguard\ cost

37Question

What does Business Continuity Planning ensure during an emergency?

Answer

Business can continue during an emergency.

38Question

What is the main goal of Disaster Recovery Planning?

Answer

To recover from an emergency with minimum organizational impact.

39Question

Name one objective of Business Continuity Planning.

Answer

Preventing interruptions.

40Question

What type of events are fires and earthquakes classified as?

Answer

Natural disruptive events.

41Question

What type of events include bombings and sabotage?

Answer

Man-made disruptive events.

42Question

What does BCP scope and plan initiation examine?

Answer

Operations and support services.

43Question

What document does Business Impact Analysis create?

Answer

A document that helps determine the impact of a disruptive event on the business.

44Question

What is Maximum Tolerable Downtime?

Answer

The longest period a critical process can be interrupted before the company cannot recover.

45Question

What does BIA identify regarding business processes?

Answer

Interdependencies and acceptable interruption periods.

46Question

What impacts does BIA record?

Answer

Quantitative and qualitative impacts.

47Question

What does BIA recommend to senior management?

Answer

Recovery priorities.

48Question

What information is used to create a recovery strategy in continuity plan development?

Answer

Business Impact Analysis (BIA) information.

49Question

What must senior management do for disaster recovery plan approval?

Answer

Provide approval for the plan.

50Question

What is one objective of disaster recovery planning (DRP)?

Answer

To organize crisis decisions effectively.

51Question

What does continuity plan documentation include besides recovery strategy?

Answer

Computing, facilities, people, supplies, and equipment details.

52Question

What is required to ensure personnel readiness in disaster recovery plan implementation?

Answer

Training for personnel with specific duties.

53Question

What does disaster recovery planning aim to reduce in personnel during disasters?

Answer

Disaster-time decision-making by personnel.

54Question

What must be prevented to maintain disaster recovery plan integrity?

Answer

Multiple versions of the plan.

55Question

What reliability aspect is tested in disaster recovery planning objectives?

Answer

Standby-system reliability.

56Question

What does the DRP process develop and maintain?

Answer

Recovery plans for data-processing continuity during disasters.

57Question

How does a hot site differ from a cold site?

Answer

A hot site is fully configured and immediately available; a cold site provides only space and utilities without hardware.

58Question

What are examples of alternate processing services besides hot, warm, and cold sites?

Answer

Mutual aid agreements, multiple centers, service bureaus, and other data-center backup alternatives.

59Question

What distinguishes electronic vaulting from remote journaling and database shadowing?

Answer

Electronic vaulting transfers backup data off-site.

60Question

What is a mutual aid agreement in disaster recovery?

Answer

An arrangement where companies with similar computing needs support each other during disruptions.

61Question

What service does a service bureau provide in disaster recovery?

Answer

Contracted alternate backup processing services with quick response and possible testing.

62Question

What is the purpose of DRP maintenance?

Answer

To keep the recovery plan current and regularly report its status through maintenance and audits.

63Question

What are the five types of DRP tests ordered from review to full disaster replication?

Answer

Checklist, structured walk-through, simulation, parallel, and full-interruption testing.

Test yourself with the quiz

Test your knowledge with 32 questions on Information Security and Continuity Planning.

1. What is the primary purpose of information security within an organization?

2. Which set correctly identifies the three basic requirements of information security?

Take the quiz →

Read the study sheet

Review the complete course in the study sheet for Information Security and Continuity Planning.

See study sheet →

Similar courses

Create your own flashcards

Import your course and AI generates flashcards in 30 seconds.

Flashcard generator