BCM Program Governance & Compliance Flashcards
6 cards from real BCM practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 BCM Program Governance & Compliance flashcards as text
What is the purpose of a BCM audit program?
Answer: To independently verify that BCM controls are effective and the program meets defined requirements
A BCM audit program provides independent verification that BCM controls are effective and that the program conforms to defined policies, standards, and regulations.
What does 'management review' mean in the context of ISO 22301 BCM compliance?
Answer: A formal periodic review by top management of BCMS performance, suitability, and need for changes
Management review under ISO 22301 is a formal, periodic top-level review of BCMS performance data to assess suitability, adequacy, and effectiveness.
Which BCM governance artifact maps responsibilities for each activity to specific roles using a matrix format?
Answer: RACI Matrix
A RACI Matrix (Responsible, Accountable, Consulted, Informed) maps each BCM activity to specific roles, clarifying ownership and communication responsibilities.
What is the key difference between a BCM 'policy' and a BCM 'plan'?
Answer: A policy sets organizational intent and direction; a plan provides specific procedures for responding to a disruption
A BCM policy establishes organizational intent and governance direction, while a BCM plan provides the specific operational steps to respond to and recover from disruptions.
In BCM governance, what is the purpose of a 'lessons learned' process following an exercise or actual incident?
Answer: To identify gaps, improve plans and procedures, and strengthen the overall BCM program
A lessons learned process identifies gaps and weaknesses revealed during exercises or real incidents and drives improvements to plans, procedures, and the overall program.
Which US federal guidance document provides BCM requirements specifically for federal government agencies?
Answer: NIST SP 800-34 (Contingency Planning Guide for Federal Information Systems)
NIST SP 800-34 provides comprehensive contingency planning guidance specifically tailored for US federal information systems and agencies.