What is CP ?
CP is “contingency planning” it is the overall “what - if” plan that will be used to restore operations with minimal cost and disruption.
What Is IRP
IRP - “ Incident Response Plan” is the immediate response that is activated after an incident occurs.
What is DRP
DRP- “Disaster Recovery Plan” is used to restore operations at the primary site after a disaster.
What is BCP
“Business Contingency Plan” Re-establishes critical functions at an alternate site. runs along Side the DRP.
BIA
BIA - “ Business Impact Anaylsis” is an Assessment of the impact that various adverse events can have on the organization. The BIA assumes that these controls have failed.
The 3 steps of IRP
How the IRP relates to NIST
The IRP aligns with the NIST Cybersecurity Framework
1. Detect Cyber Events.
2. Respond to cyber events.
3. Recover - tactical recovery phase.
Cold sites
A cold site is a secondary location with low cost slow recovery.
it is measured in weeks.
Warm Sites
This also a secondary location but is partially equipped with equipment and connection at location.
It is measured in days/hours.
Hot site
This is a fully equipped secondary location, with equipment and connection at location. It is active before fallout and is measured in hours, minutes.
Pro’s and con’s for using cloud for DPR
4 ways to test CP( Contingency Plans)
Iteration/CPI
Iteration results in improvement.
“Continuous Process Improvement” - A formal implementation of iteration mythology
Laws Vs Ethics
Laws - Enforceable rules that mandate or prohibit Behavior.
Ethics - Principles that regulate socially acceptable behavior.
THE DIFFERENCE IS “ENFORCEABILITY”
Liability vs Restitution
Liability - This the legal obligation of an entity extending beyond criminal or contract law, may include restitution.
Restitution - The legal obligation to compensate an injured party for wrongs committed.
Due Care vs Due Diligence
Due Care- the legal standard to have a prudent org act legally and ethically and know the consequences of actions.
Due Diligence- The legal standard to have a prudent org maintain the standard of due care .
Jurisdiction vs long arm
Jurisdiction- courts right to hear a case if the wrong was committed in its territory.
Long Arm - application of the law to those residing outside a court’s normal jurisdiction.
The difference is whether it’s inside or outside of jurisdiction.
Policy vs Law
Policies: specify acceptable and unacceptable employee behavior in the workplace.
Policy functions as organizational laws
THE DIFFERENCE BETWEEEN POLICY AND LAW IS IGNORANCE OF A POLICY IS AN ACCEPTABLE DEFENSE.
5 criteria for policy enforcement
Computer Crime Laws
What is Privacy
individuals rights to protect themselves and personal info from unauthorized access.
It is Important because it is the #1 ethical issue.
HIPAA
Health Insurance Portability and Accountability Act of 1996 - Protects your health insurance or general health information.
What is GLBA ?
Gramm-leach Bliley Act of 1999 also know as the financial services moderation act protects our financial information
What is the SOX
Sarbanes Oxley Act of 2002 protects financial reporting.