198 ◾ Information Security Fundamentals
◾ Number of post-incident review activities that resulted in control changes or
improvements to the CoOP process
◾ Number of risks in which corrective action is still pending (by risk rank)
◾ Level of adherence to process policies, number of policy violations, number
of policy exceptions requested, and number approved
◾ Number of process activities that are on track per remediation plan
◾ Resource needs to support the remediation process
◾ Costs to implement the recommended changes
CoOP Review Exercises and Testing Procedures
However beautiful the strategy, you should occasionally look at the
results.
—Winston Churchill
Establishing the initial BCP/CoOP is an important early milestone for protecting