16. Exam Essentials for Disaster Recovery Planning

Natural disasters that commonly threaten organizations include earthquakes, floods, storms, fires, tsunamis, and volcanic eruptions.

Explosions, electrical fires, terrorist acts, power outages, other utility failures, infrastructure failures, hardware/software failures, labor difficulties, theft, and vandalism are all common man-made disasters.

The common types of recovery facilities are cold sites, warm sites, hot sites, mobile sites, service bureaus, and multiple sites. Be sure you understand the benefits and drawbacks for each such facility. The better the more expensive.

Mutual assistance agreements (MAAs) provide an inexpensive alternative to disaster recovery sites, but hey are not commonly used because they are difficult to enforce. Organizations participating in MAA may also be shut down by the same disaster, and MAAs raise confidentiality concerns.

Databases benefit from three backup technologies. Electronic vaulting is used to transfer database backups to a remote site as part of a bulk transfer. In remote journaling, data transfers occur on a more frequent basis. With remote mirroring technology, database transactions are mirrored at the backup site in real time.

The five types of disaster recovery plan tests are:

  1. Checklist tests
  2. Structured Walk-throughs
  3. simulation tests
  4. Parallel tests
  5. Full interruption tests.

Checklist tests are purely paperwork exercises, whereas structured walk-throughs involve a project team meeting. Neither has an impact on business operations. Simulation tests may shut down noncritical business units. Parallel tests involve relocating personnel but do not affect day-to-day operations. Full-interruption tests involve shutting down primary systems and shifting responsibility to the recovery facility.

This entry was posted in CISSP-Study and tagged , , . Bookmark the permalink.