SSP Business Continuity & Resilience 5 — Questions and Answers
Question 1: Under NIST SP 800-34, what is the correct sequence for developing a Contingency Plan?
- Test → BIA → Develop Strategies → Train
- BIA → Identify Preventive Controls → Develop Strategies → Plan Development → Training → Testing → Maintenance (Correct answer)
- Plan Development → BIA → Testing → Maintenance
- Risk Assessment → Training → Plan Development → BIA
Correct answer: BIA → Identify Preventive Controls → Develop Strategies → Plan Development → Training → Testing → Maintenance
NIST SP 800-34 prescribes a seven-step process beginning with the BIA, followed by preventive controls, strategy development, plan writing, training, testing, and maintenance.
Question 2: A retail company's BCP includes a workaround for processing sales transactions manually when the POS system fails. This workaround is an example of:
- A cold site recovery option
- A manual fallback or degraded mode procedure (Correct answer)
- A compensating control for PCI-DSS compliance
- A risk acceptance strategy
Correct answer: A manual fallback or degraded mode procedure
Manual fallback procedures allow essential operations to continue in a degraded capacity when automated systems are unavailable.
Question 3: Which stakeholder group is MOST critical to include during the initial Business Impact Analysis (BIA) interview process?
- IT security staff responsible for system hardening
- Process owners and department managers who understand operational dependencies (Correct answer)
- External auditors who assess compliance frameworks
- Public relations staff who manage communications
Correct answer: Process owners and department managers who understand operational dependencies
Process owners and department managers have direct knowledge of which functions are critical, their interdependencies, and the impact of their loss.
Question 4: An organization activates its BCP but recovery efforts are slowed because staff are unfamiliar with their assigned roles. Which program element failed?
- Risk assessment methodology
- Training and awareness program (Correct answer)
- Vendor management process
- Executive sponsorship
Correct answer: Training and awareness program
If personnel do not know their roles during activation, the training and awareness component of the BCP program has not been adequately implemented.
Question 5: What distinguishes a 'resilience' approach from a traditional 'recovery' approach in business continuity?
- Resilience focuses solely on faster RTO targets
- Resilience builds organizational capacity to absorb disruptions and adapt, while recovery focuses on restoring previous state after failure (Correct answer)
- Recovery is proactive and resilience is reactive
- Resilience applies only to cybersecurity incidents while recovery covers physical disasters
Correct answer: Resilience builds organizational capacity to absorb disruptions and adapt, while recovery focuses on restoring previous state after failure
Resilience is a broader capability encompassing anticipation, absorption, adaptation, and transformation, whereas recovery narrowly addresses restoring prior state post-incident.
Question 6: A supply chain disruption prevents a manufacturer from obtaining critical components. Which BCP strategy specifically addresses this scenario?
- Activating the alternate data center
- Pre-qualifying substitute suppliers and maintaining safety stock inventory (Correct answer)
- Increasing cybersecurity controls on supplier portals
- Implementing a business interruption insurance claim
Correct answer: Pre-qualifying substitute suppliers and maintaining safety stock inventory
Pre-qualifying alternate suppliers and holding safety stock are supply chain resilience strategies that mitigate the impact of a single-source disruption.
Question 7: Which document type formally authorizes continuity plan activation and identifies the conditions or thresholds that trigger plan execution?
- Business Impact Analysis report
- Plan Activation Criteria and Authority Matrix (Correct answer)
- After-Action Review report
- Risk Register
Correct answer: Plan Activation Criteria and Authority Matrix
The Plan Activation Criteria and Authority Matrix defines who has authority to activate the BCP and specifies the measurable thresholds that trigger activation.
Under NIST SP 800-34, what is the correct sequence for developing a Contingency Plan?