Ch6Business Continuity And Disaster RecoCISA.ppt
《Ch6Business Continuity And Disaster RecoCISA.ppt》由会员分享,可在线阅读,更多相关《Ch6Business Continuity And Disaster RecoCISA.ppt(60页珍藏版)》请在三一办公上搜索。
1、ISACA,The recognized globalleaders in IT governance,control,security and assurance,Chapter 6Business Continuity And Disaster Recovery,2009 CISA Review Course,Course Agenda,Learning ObjectivesDiscuss Task and Knowledge StatementsDiscuss specific topics within the chapter Case studySample questions,Ex
2、am Relevance,Ensure that the CISA candidate“Understands and can provide assurance that in the event of a disruption the business continuity and disaster recovery processes will ensure the timely resumption of IT services while minimizing the business impact.”The content area in this chapter will rep
3、resent approximately 14%of the CISA examination(approximately 28 questions).,Chapter 6 Learning Objectives,Evaluate the adequacy of backup and restore provisions to ensure the availability of information required to resume processingEvaluate the organizations disaster recovery plan to ensure that it
4、 enables the recovery of IT processing capabilities in the event of a disasterEvaluate the organizations business continuity plan to ensure the organizations ability to continue essential business operations during the period of an IT disruption,6.2 Business Continuity/Disaster Recovery Planning,Bus
5、iness continuity planning(BCP)is a process designed to reduce the organizations business riskA BCP is much more than just a plan for the information systems,Corporate risks could cause an organization to sufferInability to maintain critical customer servicesDamage to market share,reputation or brand
6、Failure to protect the company assets including intellectual properties and personnelBusiness control failureFailure to meet legal or regulatory requirements,6.2 Business Continuity/Disaster Recovery Planning(continued),Practice Question,6-1During an audit of a large bank,the IS auditor observes tha
7、t no formal risk assessment exercise has been carried out for the various business applications to arrive at their relative importance and recovery time requirements.The risk to which the bank is exposed is that the:business continuity plan may not have been calibrated to the relative risk that disr
8、uption of each application poses to the organization.business continuity plan may not include all relevant applications and,therefore,may lack completeness in terms of its coverage.business impact of a disaster may not have been accurately understood by the management.business continuity plan may la
9、ck an effective ownership by the business owners of such applications.,Practice Question,6-2Which of the following is necessary to have FIRST in the development of a business continuity plan?Risk-based classification of systemsInventory of all assetsComplete documentation of all disastersAvailabilit
10、y of hardware and software,Practice Question,6-3An IS auditor should be involved in:observing tests of the disaster recovery plan.developing the disaster recovery plan.maintaining the disaster recovery plan.reviewing the disaster recovery requirements of supplier contracts.,IS processing is of strat
11、egic importanceCritical component of overall BCPMost key business processes depend on the availability of key systems and infrastructure components,6.2.1 IS Business Continuity/Disaster Recovery Planning,Disasters are disruptions that cause critical information resources to be inoperative for a peri
12、od of timeGood BCP will take into account impacts on IS processing facilities,6.2.2 Disasters and Other Disruptive Events,Phases of the business continuity planning processCreation of a business continuity and disaster recovery policyBusiness impact analysisClassification of operations and criticali
13、ty analysisDevelopment of a business continuity plan and disaster recovery procedures Training and awareness programTesting and implementation of planMonitoring,6.2.3 Business Continuity Planning Process,All types of incidents should be categorizedNegligibleMinorMajorCrisis,6.2.5 Business Continuity
14、 Planning Incident Management,Critical step in developing the business continuity planThree main questions to consider during BIA phase:What are the different business processes?What are the critical information resources related to an organizations critical business processes?What is the critical r
15、ecovery time period for information resources in which business processing must be resumed before significant or unacceptable losses are suffered?,6.2.6 Business Impact Analysis,6.2.6 Business Impact Analysis(continued),What is the systems risk ranking?CriticalVitalSensitiveNon-sensitive,6.2.6 Busin
16、ess Impact Analysis(continued),Practice Question,6-4The window of time for recovery of information processing capabilities is based on the:criticality of the processes affected.quality of the data to be processed.nature of the disaster.applications that are mainframe-based.,Recovery Point Objective(
17、RPO)Based on acceptable data lossIndicates earliest point in time in which it is acceptable to recover the dataRecovery Time Objective(RTO)Based on acceptable downtimeIndicates earliest point in time at which the business operations must resume after a disaster,6.2.7 Recovery Point Objective and Rec
18、overy Time Objective,6.2.7 Recovery Point Objective and Recovery Time Objective(continued),Additional parameters important in defining recovery strategiesInterruption windowService delivery objective(SDO)Maximum tolerable outages,6.2.7 Recovery Point Objective and Recovery Time Objective(continued),
19、Practice Question,6-5Data mirroring should be implemented as a recovery strategy when:recovery point objective(RPO)is low.RPO is high.recovery time objective(RTO)is high.disaster tolerance is high.,Practice Question,6-6When preparing a business continuity plan,which of the following MUST be known to
20、 establish a recovery point objective(RPO)?The acceptable data loss in case of disruption of operationsThe acceptable downtime in case of disruption of operationsTypes of offsite backup facilities availableTypes of IT platforms supporting critical business functions,A recovery strategy is a combinat
21、ion of preventive,detective and corrective measuresThe selection of a recovery strategy would depend upon:The criticality of the business process and the applications supporting the processesCostTime required to recoverSecurity,6.2.8 Recovery Strategies,Recovery strategies based on the risk level id
22、entified for recovery would include developing:Hot sitesWarm sitesCold sitesDuplicate information processing facilitiesMobile sitesReciprocal arrangements with other organizations,6.2.8 Recovery Strategies(continued),Types of offsite backup facilitiesHot sites-Fully equipped facilityWarm sites-Parti
23、ally equipped but lacking processing powerCold sites-Basic environmentDuplicate(redundant)information processing facilityMobile sitesReciprocal agreementContract with hot,warm or cold siteProcuring alternative hardware facilities,6.2.9 Recovery Alternatives,6.2.9 Recovery Alternatives(continued),Typ
24、es of offsite backup facilitiesHot sites-Fully equipped facilityWarm sites-Partially equipped but lacking processing powerCold sites-Basic environmentDuplicate(redundant)information processing facilityMobile sitesReciprocal agreementContract with hot,warm or cold siteProcuring alternative hardware f
25、acilities,6.2.9 Recovery Alternatives(continued),Provisions for use of third-party sites should cover:ConfigurationsDisasterSpeed of availabilitySubscribers per site and areaPreferenceInsuranceAudit Reliability,Procuring alternative hardware facilitiesVendor or third-partyOff-the-shelfCredit agreeme
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- Ch6Business Continuity And Disaster RecoCISA
链接地址:https://www.31ppt.com/p-2239702.html