ISACA Certified Information Systems Auditor (CISA) ExamDomain 2: Governance and Management of ITMedium
An organization relies heavily on a cloud service provider (CSP) for its core business applications and data storage. During an audit, the CISA finds that the organization's disaster recovery plan (DRP) primarily focuses on on-premise infrastructure recovery and does not explicitly address the responsibilities and recovery procedures involving the CSP. Which of the following is the MOST significant risk identified by the CISA?
- ARecovery time objectives (RTOs) and recovery point objectives (RPOs) for cloud-based services may not be met.
- BThe organization's IT staff may lack the necessary skills for cloud infrastructure management.
- CThe organization may be overpaying for redundant on-premise recovery solutions.
- DRegulatory compliance requirements for data residency in the cloud may be violated.
Show answer & explanationAnswer & explanation
Correct answer: A. Recovery time objectives (RTOs) and recovery point objectives (RPOs) for cloud-based services may not be met.
A DRP must encompass all critical systems, including those hosted by cloud providers. Failure to address CSP responsibilities and recovery procedures directly jeopardizes the ability to meet recovery time and point objectives for cloud-based services, which are crucial for business continuity.
Why the other options are wrong
- B. Staff skills are a separate issue from the DRP's content, though relevant to execution. The primary risk is the plan's inadequacy itself.
- C. While possible, this is a financial concern, whereas the immediate and most significant risk of an inadequate DRP is operational failure.
- D. Data residency is a compliance issue, but the DRP's direct purpose is recovery, and the immediate risk of an incomplete DRP is the failure to recover.
Cloud DRP Integration
Integrating cloud service provider (CSP) responsibilities and recovery procedures into an organization's disaster recovery plan (DRP) is essential for ensuring business continuity for cloud-hosted assets.
- DRP must cover all critical systems, on-premise and cloud.
- Shared responsibility model in cloud environments.
- RTO/RPO targets depend on CSP's recovery capabilities and contract.
Memory trick: Don't just float in the cloud; have a parachute plan for disaster.