MoIS4 CH03 Review Questions
1. What is the name for the broad process of planning for the unexpected? What are its primary components?
Answer: The broad process of planning for the unexpected is called contingency planning. Its major
2. Which two communities of interest are usually associated with contingency planning? Which community must
give authority to ensure broad support for the plans? Answer: Most often, the information technology and
3. According to some reports, what percentage of businesses that do not have a disaster plan go out of business
4. List the seven-step CP process recommended by NIST. Answer: The seven steps recommended by NIST are
1. Develop the contingency planning policy statement.
5. List and describe the teams that perform the planning and execution of the CP plans and processes. What is the
primary role of each? Answer: (1) Contingency planning management team, which collects information about
6. Define the term “incident” as used in the context of IRP. How is it related to the concept of incident response?
Answer: An incident, either natural or human made, is an attack on the information through an intentional effort
or an accident. An incident triggers the incident response plan.
7. List and describe the criteria used to determine whether an actual incident is occurring. Answer: If the
8. List and describe the sets of procedures used to detect, contain, and resolve an incident. Answer: The CP team
creates three sets of procedures for incident handling. The first set of procedures consists of those that must be
9. List and describe the IR planning steps. Answer: The four steps in IR planning are: IR preplanning, incident
detection, incident reaction, and incident recovery. IR preplanning involves assembling the necessary
10. List and describe the actions that should be taken during an incident response. Answer: The steps involved
in incident response are: detection using incident classification, notification of key personnel, documentation of
11. What is an alert roster? What is an alert message? Describe the two ways they can be used. Answer: An
alert roster is a list of individuals within the company who are to be notified in the event of an incident. An alert
12. List and describe several containment strategies given in the text. On which tasks do they focus? Answer:
Containment strategies include: disconnecting impacted sources of communication in order to cut off an attack
13. What is an incident damage assessment? What is it used for? Answer: The incident damage assessment is
the immediate determination of the scope of the breach of confidentiality, integrity, and availability of
14. What criteria should be used when considering whether or not to involve law enforcement agencies during
an incident? Answer: Law enforcement should be involved in all issues in which a criminal act has been
detected. For acts not deemed to be criminal, the decision to involve law enforcement should be based on the
15. What is a disaster recovery plan, and why is it important to the organization? Answer: The disaster
recovery plan is the document outlining the organization’s efforts in preparation for and recovery from a
16. List and describe two rapid-onset disasters. List and describe one slow-onset disaster. Answer: How would
you respond differently to the two types of disasters? Rapid-onset disasters occur suddenly, without a warning,
17. What is a business continuity plan, and why is it important? Answer: A business continuity plan ensures
18. What is a business impact analysis, and what is it used for? Answer: The business impact analysis provides
19. Why should continuity plans be tested and rehearsed? Answer: An untested plan is not a useable plan.
20. Which types of organizations might use a unified continuity plan? Which types of organizations might use
the various contingency planning components as separate plans? Why? Answer: Small to medium-sized