You have been employed by Challenger Constructions as theirfirst Chief Information Security Officer (CISO). You have beentasked by the Board to conduct a review of the company’s risks andstart to deploy security policies to protect their data andresources.
You are concerned that the company has no existing contingencyplans in case of a disaster.
The Board indicated that some of their basic requirements forcontingency planning include:
- A Recovery Time Objective (RTO) of 4 hours
- A Recovery Point Objective (RPO) of 6 hours
Based on these, you now need to determine:
- The Maximum Tolerable Downtime (MTD),
- The Work Recovery Time (WRT) and
- The system and data recovery priority
The Board expects that you will propose a Business ContinuityPlan (BCP) for Challenger Constructions. The Board expects you touse as much of their existing resources as possible for the BCP,but understands that some additional resources may be required.Your BCP proposal must clearly state what additional resources, interms of hardware, software and locations, are required.
Tasks:
You are to develop a proposal for a Business Continuity Plan(BCP) for Challenger Constructions in accordance with the Board'sinstructions above. Your proposed BCP must include:
- An overview of the entire BCP,
- A Business Impact Analysis
- An Incident Response Plan
- A Backup plan,
- A Disaster Recovery plan,