CORES Incident Management & Business Continuity Planning 3 — Questions and Answers
Question 1: A financial institution's BCP must give special consideration to which regulatory requirement unique to the US banking sector?
- ISO 22301 certification
- FFIEC Business Continuity Management booklet guidance (Correct answer)
- OSHA emergency action plan standards
- SEC Regulation S-K disclosures
Correct answer: FFIEC Business Continuity Management booklet guidance
The FFIEC Business Continuity Management booklet provides prescriptive guidance on BCP expectations specifically for US financial institutions supervised by federal banking regulators.
Question 2: Which technique is used to determine which business processes are most critical and must be recovered first?
- Scenario analysis
- Business Impact Analysis (BIA) (Correct answer)
- Monte Carlo simulation
- Key Risk Indicator mapping
Correct answer: Business Impact Analysis (BIA)
A Business Impact Analysis quantifies the operational, financial, and reputational consequences of process disruption, thereby establishing recovery priorities.
Question 3: During an active incident, 'situation reports' (SITREPs) serve to:
- Replace the incident log permanently
- Provide structured, time-stamped updates to stakeholders on incident status and actions taken (Correct answer)
- Document root causes before the incident is resolved
- Authorize expenditure of emergency funds
Correct answer: Provide structured, time-stamped updates to stakeholders on incident status and actions taken
SITREPs deliver consistent, periodic updates that keep decision-makers informed of current status, resource needs, and next actions during an evolving incident.
Question 4: The 'Recovery Point Objective' (RPO) specifically defines:
- The maximum time to restore full system functionality
- The acceptable amount of data loss measured in time (Correct answer)
- The cost threshold for invoking the BCP
- The number of personnel required for recovery operations
Correct answer: The acceptable amount of data loss measured in time
RPO specifies the point in time to which data must be restored, effectively defining the maximum tolerable data loss window.
Question 5: An organization discovers that its BCP has never been tested. The MOST significant risk this creates is:
- Regulatory fines for non-disclosure
- Unvalidated assumptions that could cause plan failure during a real incident (Correct answer)
- Increased insurance premiums immediately
- Loss of ISO 9001 certification
Correct answer: Unvalidated assumptions that could cause plan failure during a real incident
Untested plans contain unverified assumptions about people, systems, and processes that may not hold under real conditions, leading to failure at the worst possible time.
Question 6: In incident classification, a 'Severity 1' or 'Priority 1' designation typically triggers:
- Routine escalation to the next business day
- Immediate activation of senior leadership and crisis management protocols (Correct answer)
- An automatic regulatory filing within 72 hours
- Transfer of the incident to an external vendor
Correct answer: Immediate activation of senior leadership and crisis management protocols
The highest severity classification activates the full crisis management structure because the impact is enterprise-critical and requires executive decision-making authority.
Question 7: Which element distinguishes a 'crisis communication plan' from an 'incident response plan'?
- Crisis communication plans are only for natural disasters
- Crisis communication plans address messaging to external and internal stakeholders, while incident response focuses on operational recovery (Correct answer)
- Incident response plans must be approved by the board; communication plans do not
- Crisis communication plans are optional for organizations under 500 employees
Correct answer: Crisis communication plans address messaging to external and internal stakeholders, while incident response focuses on operational recovery
A crisis communication plan governs how information is crafted and delivered to employees, customers, regulators, and media, complementing the operational focus of the incident response plan.
A financial institution's BCP must give special consideration to which regulatory requirement unique to the US banking sector?