ISACA Certified Information Systems Auditor (CISA) ExamDomain 3: Information Systems Acquisition, Development and ImplementationHard
An IS auditor is reviewing the go-live readiness assessment for a new critical financial system. The assessment indicates that all functional requirements have been met, and user acceptance testing (UAT) was successful. However, the disaster recovery plan (DRP) has not yet been fully tested with the new system. What is the auditor's PRIMARY recommendation?
- AAccept the risk, given that functional requirements are met and UAT was successful.
- BDelay go-live until the DRP has been fully tested and validated for the new system.
- CProceed with go-live, but schedule DRP testing as a high-priority post-implementation task.
- DImplement a temporary manual workaround for disaster recovery until the DRP is tested.
Show answer & explanationAnswer & explanation
Correct answer: B. Delay go-live until the DRP has been fully tested and validated for the new system.
For a 'critical financial system,' an untested DRP represents a significant unmitigated risk. While functional readiness is important, the ability to recover from a disaster is equally, if not more, critical for such systems. Proceeding without a validated DRP exposes the organization to unacceptable business continuity risks.
Why the other options are wrong
- A. Accepting this risk for a critical financial system is generally not an acceptable position for an IS auditor due to potential severe business impact.
- C. Scheduling DRP testing post-implementation leaves the system vulnerable during its initial critical operational period.
- D. Manual workarounds are typically insufficient for critical financial systems and may introduce new risks or delays during an actual disaster.
Go-Live DRP Readiness
The state where a new critical system's disaster recovery plan has been fully tested and validated, ensuring the organization can recover operations within defined RTO/RPO objectives before the system goes live.
- Crucial for critical systems.
- Mitigates business continuity risks.
- Ensures recovery objectives are achievable.
Memory trick: Don't go live if your 'RECOVERY' plan isn't alive!