CORRECT SOLUTIONS
IT downtime cost - ANSWER-tens of billions in lost rev.
information security - ANSWER-a broad term encompassing the protection of
information from accidental or intentional misuse by persons inside or outside an
organization
backup - ANSWER-An exact copy of a system's information
recovery - ANSWER-the ability to get a system up and running in the event of a system
crash or failure that includes restoring the information backup
fault tolerance - ANSWER-is a computer system designed so that in the event a
component fails, a backup component or procedure can immediately take its place with
no loss of service
failover - ANSWER-is a backup operational mode in which the functions of a computer
component (processor, server) are assumed by the secondary system components
when primary component becomes unavailable (makes systems for fault tolerant)
disaster recovery plan - ANSWER-A detailed process for recovering information or an IT
system in the event of a catastrophic disaster such as a fire or flood
hot site - ANSWER-A separate and fully equipped facility where the company can move
immediately after a disaster and resume business
cold site - ANSWER-A separate facility that does not have any computer equipment, but
is a place where employees can move after a disaster
disaster recovery cost curve - ANSWER-charts (1) the cost to the company of the
unavailability of information and technology and (2) the cost to the company of
recovering from a disaster over time (costs lower in beginning and grow over time)
(intercept is optimal disaster recovery plan)
business continuity plan (BCP) - ANSWER-is a plan for recovery and restoration of
party or completely interrupted critical functions within a predetermined time after a
disaster or extended disruption (San Andreas San Fran)
steps in BCP - ANSWER-establish control in disaster (business continuity plan
governance), business impact analysis (ranks order of priority of service/product). the
, plans/measures/arrangements required for business continuity, readiness procedures,
quality assurance techniques
authentication - ANSWER-method for confirming users' identities
authorization - ANSWER-is the process of giving someone permission to do or have
something
authentication and authorization catergories - ANSWER-user knows (password), user
has (fob), part of the user (fingerprint)
identify theft - ANSWER-forging of someones identity for the purpose of fraud
tokens - ANSWER-small electronic devices that change user passwords automatically
smart card - ANSWER-about the size of a credit card and contains an embedded
microprocessor chip for storing important financial and personal information. The chip
can be loaded with information and updated periodically
biometrics - ANSWER-is the identification of a user based on a physical characteristic,
such as a fingerprint, iris, face, voice, or handwriting
key elements in org disruption - ANSWER-response (incident management),
communications management, and operations management
simply reacting to disaster - ANSWER-not a strategy
insiders - ANSWER-legitimate users who purposely or accidentally misuse their access
to the environment and cause some kind of business-affecting incident
social engineering - ANSWER-which means using ones social skills to trick people into
revealing access credentials or other information valuable to the attacker (another way
is dumpster diving)
information security policies - ANSWER-identify the rules required to maintain
information security
information security plan - ANSWER-details how an org will implement the security
policies
things information security plan should do - ANSWER-identify and assess risks to
customer info, identify security plan roles and assign responsibilities, provide ways to
identify and assess risk, develop written polices and procedures to manage and control
identified risks, identify mechanisms to implement and assess the plan