1. How often should contingency plans be tested? How do we determined what needs to be tested? If you were a Chief Information Security Officer how would you develop contingency plans? Where would you begin and why?

2. Explain why disaster recovery is not business continuity. There are 3 main areas that can turn into a disaster within an organization what are they? What is the purpose of disaster recovery planning? What is the difference between an incident, disaster, and catastrophe? Why do we need these categorizations?

