Business Continuity, Personnel, and Physical Security
This chapter will discuss some auxiliary items that often come up for security teams: business continuity, personnel, and physical safety. They are “auxiliary” because they have little to do with information technology but affect the overall security posture and are often included in the activity scope of security teams. One characteristic that these items have in common is that there are hardly any generally accepted best practices that can be followed and implemented. Because these items deal with the specific physical and process aspects of the business, context matters a lot in all of them. However, security teams can focus on what questions need to be asked to resolve these items and what the answers subsequently mean for the business.
In terms of getting ready for the exam, this chapter will give you a general outline of the issues at play and the activities that security teams usually undertake when they...