Management of Information Security, Fourth Edition 3-1
© 2014 Course Technology, Cengage Learning
Chapter 3
Planning for Contingencies
At a Glance
Instructor’s Manual Table of Contents
Overview
Objectives
Teaching Tips
Management of Information Security, Fourth Edition 3-2
Lecture Notes
Overview
In this chapter, students will learn about the different components of contingency planning, and
Chapter Objectives
After reading this chapter and completing the exercises, the student will be able to:
Discuss the need for contingency planning
Teaching Tips
Introduction
1. Explain to students that planning for unexpected events typically involves both general
business management and information technology management.
2. Describe the importance of having a plan in place that addresses how to identify,
Fundamentals of Contingency Planning
1. Review the definition of contingency planning with students, and note that it involves
the planning for unexpected adverse events.
2. Discuss the four major components of contingency planning:
a. Business impact analysis (BIA)
d. Business continuity plan (BC plan)
3. Describe how each element of contingency planning functions, and note how an
organization uses plans depending on the scale of an event, which is determined by a
response team.
Management of Information Security, Fourth Edition 3-3
4. Note that all four components of contingency planning can be included in a single plan,
or can be developed separately.
5. Discuss the role of a contingency planning management team (CPMT) in developing a
7. Discuss the different teams and roles involved in CP and contingency operations:
a. CPMT, which gathers information for the development of contingency plans,
and should include the following personnel:
i. Champion
ii. Project Manager
Components of Contingency Planning
Business Impact Analysis
1. Explain to students that the Business Impact Analysis (BIA) works by assuming all risk
management controls have been bypassed, essentially assuming that the worst has
happened, and then estimating the impact.
2. List some of the considerations that should be taken into account when performing a
BIA:
3. Discuss the NIST SP 800-34, Rev. 1 document on how a CPMT should conduct a BIA
in three stages:
4. Define the first major BIA task as the analysis and prioritization of business processes
within an organization, based on its mission.
5. Describe a business process as a task performed by an organization or organizational
sub-unit in support of an organization’s overall mission.
6. Educate students on potential issues arising in the prioritization of one department or
9. Provide information about the recommendations made by NIST regarding the use of
categories, such as low impact, moderate impact, and high impact, to organize security
objectives.
10. Explain the following key recovery measures:
a. Maximum Tolerable Downtime (MTD), which represents the maximum amount
of time that a system can be down.
11. Describe Work Recovery Time (WRT) as an extension of RTO that measures the
amount of effort (time) required to get a business function operation after a technology
element is recovered.
12. Explain to students that longer interruptions result in larger impacts to an organization,
and note that solutions that reduce the RTO are typically more expensive.
15. Explain that the last stage of BIA involves the prioritizing of resources associated with
mission/business processes, and the use of weighted tables.
16. Discuss how to use a simple valuation and classification scale, using values such as
Primary/Secondary/Tertiary, or Critical/Very Important/Important/Routine.
Contingency Planning Policies
1. Make students aware of the need to have a proper policy environment for assisting with
the BIA process and the creation of planning components, such as the IR, DR, and BC.
Incident Response
Teaching
See the following website for more information about business impact analysis:
Management of Information Security, Fourth Edition 3-5
1. Introduce the incident response plan (IR plan) as a plan designed to deal with the
effects of an unexpected event, and note that incident response planning (IRP) involves
4. List the key components of a typical IR policy that are recommended by NIST, such as
the statement of management commitment and purpose / objectives of the policy.
5. Discuss the characteristics of an event that make up an information security incident:
a. It is directed against information assets
b. It has a realistic chance of success
c. It threatens confidentiality / integrity / availability of information resources and
assets
6. Point out that incident response is a reactive measure, rather than a preventive one.
7. Explain how an organization’s IR plan is created by a CISO or IT manager, and note
10. Discuss incident classification as the process of examining an incident, or incident
candidate, to determine if it qualifies as a genuine incident. Note that this determination
is made by the IR team.
11. Provide some examples of candidates that would not qualify as incidents, such as
overloaded networks, computers, or servers.
12. List some of the indicators of an actual incident:
a. Presence of unfamiliar files
13. In comparison, list some probable indicators of an actual incident:
a. Activities at unexpected times
14. Explain that the following list consists of definite indicators of an incident:
a. Use of dormant accounts
15. Note that when the following actual incidents are confirmed, the corresponding IR must
be immediately activated:
Management of Information Security, Fourth Edition 3-6
16. Educate students regarding the move from the detection phase to the reaction phase,
once an actual incident has occurred. The reaction phase should be described as
involving recovery processes, notification of key personnel, assignment of tasks, and
documentation of the incident.
17. Define an alert roster as a document that lists contact information for personnel that
must be notified of an actual incident. Explain that this list can be sequential or
hierarchical.
21. Incident containment should be described as consisting of two tasks: stopping the
incident and recovering control of affected systems. Provide examples of potential
containment strategies, such as the application of access lists, disabling compromised
user accounts, or stopping all computers and devices.
22. Educate students on the process of incident escalation to a disaster, or handing over an
incident to law enforcement or outside agencies.
26. Define an after-action review (AAR) as a detailed examination of events that have
occurred, starting with first detection and ending with the final recovery.
27. Make students aware of the responsibility to notify proper authorities, such as the FBI,
when an incident violates civil or criminal law. List some of the capabilities of the FBI
in pursuing cyber-crime.
28. Students should understand some of the advantages and disadvantages of involving law
enforcement. One advantage is that law enforcement typically has more resources for
Management of Information Security, Fourth Edition 3-7
Quick Quiz 1
1. The ____________________ contains the contact information of individuals that need
to be notified in the event of an actual incident.
2. True or False: Detecting a modification of system logs is an indicator that an actual
incident has taken place.
3. Which term below describes the point in time, prior to a disruption or outage, to which
mission / business process data can be recovered?
A. Maximum Tolerable Downtime (MTD)
B. Recovery Time Objective (RTO)
C. Recovery Point Objective (RPO)
D. Work Recovery Time (WRT)
4. What is the first phase of the CP process?
A. Business impact analysis
B. Incident response planning
C. Disaster recovery planning
D. Business continuity planning
5. Which of the following is NOT a major component of contingency planning?
A. Incident response plan
B. Business relief plan
C. Disaster recovery plan
D. Business continuity plan
Disaster Recovery
1. Explain disaster recovery planning (DRP) as involving the preparation for and recovery
2. Discuss the two criteria for determining a disaster:
a. An organization is unable to contain or control the impact of an incident
b. Level of damage from an incident is so severe that it prevents quick recovery
Teaching
Management of Information Security, Fourth Edition 3-8
3. List the eight-steps that have been adapted from the seven-step program from NIST
regarding the DRP process:
a. Organize the DR team
4. Discuss the DR policy, which is developed soon after the formation of a DR team, and
list the key elements in a DR policy:
a. Purpose
5. Educate students on how a disaster might be classified, such as whether an event is a
natural disaster or man-made disaster. Note that disasters can be classified as rapid-
onset disasters, which occur without warning, or slow-onset disasters, which occur over
time.
6. Discuss the importance of human resource considerations in a disaster recovery
7. Explain some of the key elements that a CPMT should build into a DR plan:
a. Clear delegation of roles and responsibilities
b. Execution of the alert roster and notification of key personnel
8. Describe some additional options that can be used by an organization to protect
information and assist in the recovery process:
a. Traditional data backups
Management of Information Security, Fourth Edition 3-9
11. Database shadowing can be explained as being a hybrid of electronic vaulting and
remote journaling, in which a copy of a database exists in two or more separate
locations.
15. Discuss the nine steps within a simple DR plan, and note that a larger organization will
most likely require a more complex DR plan. Outline the following steps:
a. Name of agency
b. Date of completion or update of the plan and the date of the most recent test
Business Continuity
1. Explain to students how business continuity planning (BCP) ensures that critical
business functions can continue if a disaster occurs.
4. Emphasize that the first step in contingency efforts is the development of policy,
followed by planning.
5. Demonstrate how to adapt the NIST approach for contingency planning to make a
viable BC program:
a. Form the BC team
Teaching
The Disaster Recovery Journal has extensive information on the process of
Management of Information Security, Fourth Edition 310
6. Note that BCP begins with the development of a BC policy, and list the key sections of
a BP policy:
a. Purpose
7. Explain that the one of the most important pieces of a BC plan involves the
identification of critical business functions.
8. Emphasize the importance of testing the health of an offsite facility regularly, as well as
looking for better alternative offsite locations.
9. Discuss the different strategies for CP and BC planning, and note the three different
types of usage strategies:
10. Discuss the three different strategies for shared use of a facility when needed for
contingency options:
a. Timeshare, typically operated in conjunction with a business partner or
11. Describe specialized alternatives to the basic strategies, such as a rolling mobile site.
Timing and Sequence of CP Elements
1. Discuss the concurrent nature of the BC plan and the DR plan when damage is major or
long term.
Teaching
Tip
U.S. Regulators have recently pushed for an improvement in business continuity
plans, as well as disaster recovery. See the following Reuters article for
Management of Information Security, Fourth Edition 311
Crisis Management
1. Crisis management (CM) should be described as the action steps that affect people
inside and outside of an organization that are taken during and after a disaster.
2. Explain that some organizations plan for crisis management as a completely separate
process.
3. Discuss the roles performed by a crisis management team:
a. Supporting personnel and their loved ones during the crisis
4. Stress the importance of the crisis management team (CMT) establishing a base of
Business Resumption
1. Explain how the DR and BC plans can be combined into a single document, known as
Testing Contingency Plans
1. Discuss the importance of testing a contingency plan to discover areas for
improvement. Discuss five strategies that can be used to test contingency plans:
a. Desk check
b. Structured walk-through (or talk-through / chalk talk)
Final Thoughts
1. Educate students on the need to perform continuous process improvement (CPI). Note
Management of Information Security, Fourth Edition 312
Quick Quiz 2
1. The ____________________ has two primary responsibilities during a disaster:
verification of personnel status and activation of the alert roster.
2. True or False: Slow-onset disasters occur over time and gradually degrade an
organization’s ability to withstand their effects.
3. A __________ is a site with a fully configured computer facility, including all services,
communications links, and physical plant operations.
4. Which type of offsite backup service provides backups for transactional data only,
typically in real time?
A. Electronic vaulting
B. Traditional data backups
C. Database shadowing
D. Remote journaling
5. At what point during an incident should law enforcement be notified?
A. Immediately after the detection of an event
B. When an incident is determined to violate civil or criminal law
C. After the incident is escalated to a disaster
D. When an organization no longer has the ability to handle an incident with its
Class Discussion Topics
1. Start a class discussion on why organizations may not place enough importance on
disaster recovery. What might happen to these organizations in the event of an actual
disaster?
Additional Projects
1. Task students with researching the disaster response plans of major organizations that
have had to respond to fairly recent disasters, then have the students discuss the results
of the organization’s recovery efforts.
Additional Resources
1. FFIEC article on Business Impact Analysis: