CORES Incident Management & Business Continuity Planning 5 — Questions and Answers
Question 1: Which BCP component specifically addresses continuity of critical operations when key personnel are unavailable?
- Data backup schedule
- Succession planning and cross-training program (Correct answer)
- Vendor management policy
- Network redundancy architecture
Correct answer: Succession planning and cross-training program
Succession planning and cross-training ensure that critical functions can continue even when designated personnel are unavailable due to illness, travel, or crisis-related absences.
Question 2: An organization's BCP is activated but the recovery team cannot locate the most current version of the plan. This MOST likely indicates a failure in:
- Business Impact Analysis methodology
- Plan document control and distribution management (Correct answer)
- Risk appetite setting
- Board-level risk governance
Correct answer: Plan document control and distribution management
Proper document control ensures that only current, approved versions are accessible to authorized personnel at all times, including during an active crisis.
Question 3: When evaluating supply chain risk for BCP purposes, 'single-source dependencies' are concerning because:
- Single suppliers always charge higher prices
- The failure of one supplier has no available substitute, creating a potential single point of failure (Correct answer)
- Regulators prohibit single-source procurement in financial services
- Single-source vendors require more frequent audits
Correct answer: The failure of one supplier has no available substitute, creating a potential single point of failure
Reliance on one supplier without alternatives means any disruption to that supplier directly and immediately disrupts the organization's own operations.
Question 4: The 'lessons learned' report issued after an incident should PRIMARILY drive:
- Individual performance reviews for incident responders
- Updates to plans, procedures, and training to prevent recurrence or improve response (Correct answer)
- Media communications about how the incident was handled
- Quarterly reporting to shareholders
Correct answer: Updates to plans, procedures, and training to prevent recurrence or improve response
The lessons learned process closes the feedback loop by translating post-incident insights into concrete improvements to plans, controls, and organizational readiness.
Question 5: Under FFIEC guidance, financial institutions are expected to test their BCP at minimum:
- Every five years
- Annually, with testing scope commensurate with the complexity of operations (Correct answer)
- Only after a significant incident occurs
- Whenever there is a change in senior leadership
Correct answer: Annually, with testing scope commensurate with the complexity of operations
FFIEC guidance requires annual BCP testing scaled to the institution's operational complexity and systemic importance to ensure plans remain effective.
Question 6: Which scenario represents a 'cascading failure' risk relevant to business continuity?
- A single server fails and is restored from backup within the RTO
- A power outage disables the data center, which then overwhelms the backup site, causing it to fail too (Correct answer)
- An employee calls in sick and a cross-trained colleague covers their duties
- A regulatory deadline is missed due to a planned system upgrade
Correct answer: A power outage disables the data center, which then overwhelms the backup site, causing it to fail too
Cascading failures occur when an initial disruption triggers secondary failures in dependent systems or sites, potentially overwhelming continuity measures designed for single-point failures.
Question 7: A CORES practitioner recommends embedding risk considerations into the incident triage process. The BEST rationale for this recommendation is:
- It reduces the need for post-incident reviews
- Early risk assessment during triage enables proportionate resource allocation and escalation decisions (Correct answer)
- It eliminates the need for an incident commander
- Risk assessment during triage is required by all state regulations
Correct answer: Early risk assessment during triage enables proportionate resource allocation and escalation decisions
Integrating risk assessment into triage ensures that response resources and escalation protocols are matched to the actual severity and potential impact of the incident from the outset.
Which BCP component specifically addresses continuity of critical operations when key personnel are unavailable?