Foundation Topics
Threats to Business Operations
There is no shortage of events that can endanger business operations. Such events can come from inside or outside the organization and are typically categorized as either human-caused, technical, or natural threats, as shown in Figure 4-1. Natural threats are high on the list. In 2016, events such as Hurricane Matthew in the Caribbean, earthquakes in Ecuador, and catastrophic flooding in China topped the list. Such events highlight the need to be adequately prepared. Companies tend to seriously underestimate how long it would take to restore operations. In 2017, many companies were hit with ransomware because of flaws in their backup and offsite storage programs; other companies suffered because they had no workstation recovery plans for end users.
Figure 4-1 Sources of Security Threats
Answers to the “Do I Know This Already?” Quiz:
D;
B;
A;
C;
A;
A;
D;
C;
B;
C
A company may not always update its plans as the company grows, changes, or modifies existing processes, even though the results of poor planning can be disastrous for the company. Some estimates indicate that only a small percentage of businesses are required by regulation to have a disaster recovery plan. Disaster recovery must compete for limited funds. Companies might be lulled into thinking that these funds might be better spent on more immediate needs. Some businesses might simply underestimate the risk and hope that adverse events don’t happen to them. Disaster recovery planning requires a shift of thinking from reactive to proactive.
Many of us would prefer not to plan for disasters. Many see it as an unpleasant exercise or would just prefer to ignore it. Sadly, we all must deal with disasters and incidents. They are dynamic by nature. For example, mainframes face a different set of threats than distributed systems, just as users connected to free wireless networks face a different set of threats than those connected to wired networks inside an organization. This means that management must be dynamic and must be able to change with time. Regardless of the source of a threat, each one has the potential to cause an incident. Incident management and disaster recovery are closely related. Incidents might or might not cause disruptions to normal operations. From the perspective of an auditor, a review of incident management should be performed to determine whether problems and incidents are prevented, detected, analyzed, reported, and resolved in a timely manner. This means the auditor should review existing incident response plans. The auditor also plays a critical role after an incident in that there should be a review of what worked and what did not so the plan can be optimized to be better prepared for the next incident.
An organization needs to have a way to measure incidents and quantify their damage. Table 4-2 lists the incident classification per ISACA. An auditor should have knowledge of problem and incident management practices.
Table 4-2 Incident Classification
Level |
Description |
Crisis |
A crisis is considered a major problem. It is of sufficient impact that it adversely affects the organization’s ability to continue business functions. |
Major |
A major incident is of sufficient strength to negatively impact one or more departments, or it might even affect external clients. |
Minor |
Although these events are noticeable, they cause little or no damage. |
Negligible |
These detectable events cause no damage or have no longer-term effect. |
