Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- A& C should have included business continuity management requirements in contracts with its supplier.
- What strategy would you suggest to A& C after the disruptions caused by risks affecting its supplier?
- Which of the following approaches to BCM strategy did A& C employ?
- What should A& C have not included in the business continuity plan?
- Which statement is correct?
- What does big data include?
- What is big data ?
- By identifying data backups as critical business processes, what did RDK conduct?
- What is the root cause of the phishing attack that occurred in RDK on May 2021?
- One disadvantage of the file backup data continuity strategy is that it is not a good fit for organizations with voluminous data.
- What is the overall objective of conducting exercises?
- What is the purpose of the BCMS internal audit?
- Which parameter is commonly subject to monitoring and measurement?
- Based on the outputs of _____________ and _____________, the organization determines its business continuity strategies.
- What is the main reason that employees fail to follow the business continuity policy?
- What should an organization ensure when undertaking changes?
- The business continuity policy should:
- What should an organization do when defining the BCMS scope?
- What is recommended for organizations that manage multiple compliance frameworks simultaneously?
- What is the first step that should be taken when planning the business impact analysis (BIA)?
- Among others, ________________________ consists of identifying organization’s critical activities and resources needed to support prioritized activities of an organization.
- What are the steps of business continuity planning process?
- Which of the following is considered as a human-caused hazard?
- What is the role of disaster recovery for business continuity management?
- How did business continuity management evolve as a discipline?
- What does business continuity management mainly entail?
- What are accreditation bodies?
- OneMarket is a market research company which helps its customers determine which products and services are on demand. Recently, the company’s BCMS was audited by another party. What is OneMarket in this case?
- What is a certification body?
- ISO develops international standards and systematically verifies whether those standards are implemented in accordance with the requirements defined.
- What does ISO 22313 provide?
- The requirements specified in ISO 22301 are intended to be applicable only to medium and large organizations.
- From the perspective of interested parties, what does a business continuity management system (BCMS) ensure?
- Which cycle does ISO 22301 apply?
- Which statement below is correct?
- Implementation of a records management policy for the BCMS can be a corrective action for the lack of a record of business continuity policy?
- What is the root cause of lacking a record of a business continuity policy?
- The lack of a record of a business continuity policy represents a:
- Did the exercise and testing program of FAR achieve its intended results?
- Should FAR have hired Dolly as an internal auditor?
- Auditors that take part in the audit also participate in the certification decision ?
- What is the main activity of stage 1 audit?
- What can an organization do prior to the commencement of the audit?
- An auditee is not allowed to request that each member of the audit team holds a security clearance or that a background check on each member is conducted before being admitted on-site ?
- Which of the following is a valid reason for rejecting an auditor?
- Feedback from personnel, business partners, clients, critical customers, suppliers, and community do not serve as inputs to continual improvement ?
- What is the correlation between continual improvement and productivity?
- What does continual improvement of the BCMS help the organization with?
- Which of the following is an activity taken toward continual improvement?
- An organization can demonstrate that it continuously strives to improve its BCMS by publishing their performance?
- Which activity below is performed in the situation analysis phase of the corrective action process?
- Who is responsible for evaluating whether the action plan can resolve the nonconformities within the specified time frame?
- There should be an action plan for each nonconformity.
- Preventive actions are often more cost-effective than corrective actions?
- Which method below is not employed to resolve problems and nonconformities?
- Which action should be taken to eliminate the cause of a nonconformity and prevent recurrence?
- ISO 22301 does not provide specific requirements on the frequency of management review meetings. However, annual meetings should suffice.
- What should be included in the management review output?
- Identifying anomalies in the BCMS is one of the main purposes of:
- Who is responsible for providing the input needed for a management review?
- What is ensured when results are achieved in the best way possible?
- To ensure that the mission of the internal auditor is successfully completed, an organization must not:
- How many types of nonconformities are there?
- A nonconformity report should be explicit, unambiguous, linguistically correct, and as concise as possible.
- Which statement below is not correct regarding internal audits?
- The main difference between second and third-party audits is in certification. Second party audits are intended for certification, whereas third - party audits are not.
- What is the aim of a third-party BCMS audit?
- The organization should conduct monitoring and measurement activities twice a year, as specifically indicated in ISO 22301.
- Which of the following is not a method for reporting the monitoring and measurement results?
- Organizations should monitor and measure activities related to:
- It is recommended to introduce as many performance measures as possible to gain more valuable insights regarding the performance of the BCMS.
- What is the purpose of monitoring, measurement, analysis, and evaluation?
- The exercises and tests of the business continuity plans should be spontaneous and conducted randomly once in a two-year period.
- ___________________ refers to a form of exercise where participants are placed in circumstances that are similar to those of an actual incident.
- There are five levels of exercises. Which one is recommended to be done when new staff join an organization?
- What should an effective exercise plan include?
- What are the key stages of an exercise program?
- What should an organization do to validate the effectiveness of its business continuity strategies and procedures?
- What strategy would you suggest to A& C after the disruptions caused by risks affecting its supplier?
- A& C should have included business continuity management requirements in contracts with its supplier.
- What is the expected monetary value for the risk of the company’s building catching fire?
- What is a key success factor during a crisis?
- Whose responsibilities increase during a crisis?
- The size and number of teams involved in crisis management depend on the ________ and _________ of the organization.
- What does a crisis management plan include?
- ISO 22301 does not specifically require the establishment of a crisis management plan.
- What should the primary objective be in an emergency?
- If the expected duration of the disruption lasts longer than the ___________, the incident response should be activated.
- One key principle of incident response investigation is being timely and responsive. Based on this principle, when should incidents be reported?
- Employees should be _________________ to report incidents.
- Incident response structure consists three main types of teams. Which team is responsible for determining how the causes of the incident are to be managed?
- How should incident response plans be?
- The time required to implement the business continuity plan must be within or equal to the RTO.
- Why should business continuity plans be evaluated?
- Which step should be taken first when developing a business continuity plan?
- What should, among others, a business continuity plan include?
- What is the purpose of business continuity plans?
- What should an organization that outsources critical activities do to prevent potential disruptions that may affect them?
- What type of strategy can an organization select in order to mitigate, respond to, and manage impacts of a disruption?
- Which approach for developing a business continuity strategy is suitable for organizations that operate in the service and manufacturing industry and are predominantly people-intensive?
- The business continuity strategy forms the foundation of:
- A business continuity strategy must be identified based on the extent to which the strategy:
- How do the outputs of BIA and risk assessment help the organizations with?
- The organization needs to prioritize risks in order to focus the treatment efforts into risks that have both __________ impact and ____________.
- How is the value of risk (expected monetary value) estimated?
- The purpose of risk evaluation is to support:
- How can the likelihood of an event be estimated?
- The magnitude of consequences can be expressed quantitatively or as a distribution. When is the expression in the form of distribution appropriate?
- If an organization has already conducted _______________, they already possess data on the existing controls.
- Which techniques are used for risk analysis?
- During risk identification, an organization should not include all risks but focus only on those that they can control.
- What is the purpose of risk identification?
- Through risk assessment, organizations are able to assess the risks of:
- When Juto’s business continuity team assessed the impact due to the interruption of the business activities by quantifying the impact, they conducted:
- Why did top management, instead of the business continuity manager, send an official letter to the staff before publishing the business continuity policy?
- Juto’s business continuity policy appears to not detail the:
- The total amount of time Juto is willing to accept for a business process disruption is known as:
- What is the issue with the way Juto addresses the disruptions it experiences?
- The acceptable maximum acceptable outage (MAO) for critical business processes is:
- The _____ indicates how much lost data will be acceptable to users.
- Which of the following can be employed to evaluate the impact of interrupted activities?
- The data collection phase for BIA requires the collection of information for:
- RTO is the amount of time a user is willing to lose before regaining the use of their applications.
- Cost of disruption is _________________ related with cost of recovery.
- What should an organization do, among others, when conducting BIA?
- _____________ involves time and resource allocation in assessing the criticality of functions within the organization.
- What is the purpose of business impact analysis (BIA)?
- Which claim is correct regarding documented information?
- The organization should ________________________ for the business continuity communication to be effective.
- What should an organization ensure when undertaking business continuity communication activities?
- The extent of documented information for a BCMS does not differ from one organization to another.
- Which of the following is a principle of effective communication?
- Communication relevant to BCMS allows the organization to respond to the needs and expectations of:
- Persons doing work under the organization’s control must ____________________ their own role and responsibilities before, during, and after disruptions.
- An employee that is neither aware nor trained represents a potential risk.
- What is an appropriate action for ensuring that people within the organization are competent for undertaking business continuity-related tasks?
- Which factors can create the need for changes in the BCMS?
- ISO 22301 requires organizations to apply a formal risk management process.
- What is of high importance in cases when the BCMS undergoes changes?
- In the change management of the BCMS, it is important to:
- Business continuity objectives should be:
- What is the typical sequence of actions in the process of drafting a business continuity policy?
- A clearly defined business continuity policy does not require review, control, and evaluation.
- What should a business continuity policy include?
- A business continuity policy should:
- A business continuity policy should include a commitment to continual improvement.
- _____________ should be addressed in a business case.
- What is the business continuity management team responsible for?
- A business continuity manager is expected to facilitate:
- The organizational structure for business continuity does not require strong support from the top management.
- Which of the following are identified during the BCMS project planning phase?
- Before defining the organizational structure for business continuity, several factors, such as _____________ should be considered.
- A business case is a tool used to:
- _____________ are/is imperative for the implementation of a BCMS based on ISO 22301.
- Which step below should LCL take?
- In addition to the location, what is another vulnerability or source of risk for LCL that can be detected in the scenario?
- Why were LCL’s employees interviewed individually?
- LCL had already some form of measures in place to ensure business continuity during disruptions. Why did LCL engage in means of determining the current state of the company?
- LCL had considered that the continuity of operations is ensured for as long as employees could work remotely in case its offices are subject to severe flooding. Which of the following did LCL fail to take into account?
- Should the organization pay attention when changing the scope?
- What, among others, should an organization consider when determining its BCMS scope?
- The organization should ____________ and _____________ its BCMS scope.
- How should the BCMS scope statement be?
- What, among others, should be considered when defining organizational boundaries?
- A gap analysis helps the implementation and maintenance of a BCMS by:
- The organization must inform its interested parties concerning the actions taken for the implementation of the BCMS and the impact and responsibilities they have in this regard?
- Which of the following statements is correct regarding the identification and analysis of interested parties?
- Why should a business continuity manager be familiar with the organization’s business processes?
- ___________ is a tool that assists organizations in determining and managing interested parties.
- Why must a BCMS be aligned with the organization’s mission?
- Why should general information about an organization be collected?
- Which of the following is highly important when analyzing the internal context of an organization?
- What, among others, should be ensured when applying the proposed approach to the BCMS implementation?
- What is an integrated approach to implementing a BCMS?
- Among others, initiating the BCMS implementation project includes:
- The PECB approach to the BCMS implementation is based on a range of approaches, including the ___________ approach, which is the integration of the BCMS into the context of commercial activities across the organization.
- Which factor can determine the BCMS implementation approach?
- Recovery time objective (RTO) refers to the time period within which business operations must be resumed.
- What are the main principles of business continuity?
- Who is responsible for the effectiveness of the BCMS?
- What is essential for an effective BCP, at least in the initial phase of a disruptive incident?
- Business continuity is the capability of an organization to:
- What is the primary purpose of business impact analysis (BIA)?
- What does a business continuity plan include?
- ______________________ is documented information that supports an organization in effectively responding to a disruption and resuming the delivery of products and services following a disruption.
- Organizations are encouraged to implement a/an ____________________ if they have to manage several compliance frameworks.
- ___________ is an iterative method that helps implementing, maintaining, and systematically improving a BCMS.
- Which statement regarding management systems is correct?
- What, among others, does ISO 223001 require in relation to understanding the context of the organization?
- An organization, wishing to get certified against ISO 22301, must demonstrate compliance with requirements outlined in clauses:
- Organizations cannot obtain certification against _______________ standard.
- Being ISO/IEC 27001 certified lays the foundation for an easier and more effective implementation of BCMS ?
- Which benefit can be gained from the implementation of a BCMS?
- Which controls of ISO/IEC 27001’s annex are considered similar to some clauses of ISO 22301?
- ISO 22301 provides guidelines on how to implement, maintain, and improve a business continuity management system (BCMS)?
- The process of determining the status of a system, process, or activity is known as:
- Business continuity plans need to be evaluated in order to:
- The organization should conduct exercises and tests that:
- What is the primary and most important objective during an emergency?
- Incident management plans should be:
- “Procedure” is defined as:
- Plans that include programs that ensure the effectiveness of business continuity strategies and solutions are also known as____________?
- Business continuity plan is NOT required to include:
- Clause 8.4.2.4 requires that the documented procedures to guide the actions of the teams shall include:
- According to clause 8.4.2 Response Structure, the organization must:
- What does an employee who is neither aware nor trained represent?
- Apart from the documented information required by ISO 22301, the BCMS must include documented information that:
- Based on what is the organization required to identify and select business continuity strategies?
- What does an organization need to do when dealing with unintended changes?
- With regard to operational planning and control, does the standard require from the organization to control outsourced processes and the supply chain?
- Which of the following is the organization required to determine with regard to communication?
- Which of the following represents a business continuity strategy option?
- What does the standard require to ensure when creating and updating documented information?
- Which of the following is performed at the risk analysis stage?
- With regard to the training program, what is the objective of the introductory sessions?
- What are the external factors that could drive the need for changes?
- When planning the BCMS objectives, organizations must determine which of the following?
- The BCMS objectives, among others, must be:
- Why is it important to consider the risks and opportunities in a BCMS project?
- According to the requirements of ISO 22301, the top management of the organization cannot assign to another party:
- The requirements of ISO 22301 imply that the top management of the organization is required to demonstrate leadership and commitment with regard to the BCMS. Leadership and commitment can be best demonstrated by:
- The top management must ensure that the roles and responsibilities regarding BCMS are:
- The business policy must be:
- Who shall be responsible for establishing the business continuity policy?
- With regard to leadership and commitment, the top management shall ensure:
- When defining the scope, is the organization allowed to claim exclusions?
- With regard to legal and regulatory requirements, the standard does not require:
- Individuals in an area who may be affected by an incident are defined as:
- The internal context of an organization can include:
- With regard to the needs and expectations of interested parties, the organization is required to:
- Why is it important to understand the mission, objectives, values, and strategies of the organization?
- How many management systems is an organization allowed to integrate?
- Why is the application of the PDCA cycle important for ISO 22301?
- Which of the statements below best describes what the PDCA cycle is
- What is the purpose of a business impact analysis?
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement