ISACA Certified Information Systems Auditor (CISA) ExamDomain 2: Governance and Management of ITMedium

A CISA is evaluating an organization's business continuity plan (BCP). The CISA notes that while the BCP identifies critical business processes and their recovery time objectives (RTOs), it lacks detailed procedures for data backup and restoration, particularly for complex, interconnected databases. What is the MOST likely consequence of this deficiency during a business disruption?

  1. ADifficulty in communicating recovery status to stakeholders.
  2. BIncreased risk of data corruption during the recovery process.
  3. CExtended downtime for critical applications due to inefficient data recovery.
  4. DFailure to meet regulatory compliance requirements for data retention.
Show answer & explanation

Correct answer: C. Extended downtime for critical applications due to inefficient data recovery.

Without detailed data backup and restoration procedures, especially for complex systems, the actual recovery process will be inefficient, error-prone, and significantly prolonged. This directly translates to exceeding established RTOs and extended downtime for critical business applications.

Why the other options are wrong

  • A. Communication protocols are a separate part of the BCP; this deficiency specifically impacts the technical recovery process.
  • B. While possible, data corruption is more often related to the backup integrity itself or hardware failure. The lack of procedures primarily impacts the speed and efficiency of restoration.
  • D. Data retention is related but not the direct consequence of lacking backup/restore procedures within the BCP itself.

DRP Data Recovery Procedures

Detailed, step-by-step instructions within a Disaster Recovery Plan (DRP) for backing up, restoring, and ensuring the integrity of critical data and systems following a disruptive event.

  • Crucial for meeting RTOs and RPOs.
  • Must account for complex interdependencies.
  • Requires regular testing and validation.

Memory trick: A plan with no steps is just a wish.

More Domain 2: Governance and Management of IT questions