ISACA Certified Information Systems Auditor (CISA) ExamDomain 2: Governance and Management of ITMedium

An organization's disaster recovery plan (DRP) has not been reviewed or tested in three years. During this period, several critical systems have been upgraded, and new applications have been deployed. What is the PRIMARY concern for a CISA auditing this DRP?

  1. AThe cost of maintaining an untested DRP is an inefficient use of resources.
  2. BThe DRP may not comply with current industry best practices.
  3. CThe recovery time objectives (RTOs) and recovery point objectives (RPOs) are likely outdated.
  4. DThe DRP may not effectively support the recovery of current critical business functions.
Show answer & explanation

Correct answer: D. The DRP may not effectively support the recovery of current critical business functions.

The primary concern is that a DRP that hasn't been updated or tested for three years, especially with significant system changes, is highly unlikely to be effective in recovering the organization's current critical business functions. This renders the plan potentially useless when disaster strikes.

Why the other options are wrong

  • A. Cost inefficiency is a concern, but the inability to recover from a disaster is a far more critical risk to the organization's survival.
  • B. While compliance with best practices is important, the direct operational failure of the DRP is a more pressing concern.
  • C. Outdated RTOs/RPOs are a symptom of the larger problem that the plan itself is not current or effective.

DRP Maintenance and Testing

Regular review, update, and testing of the Disaster Recovery Plan (DRP) to ensure its continued relevance, accuracy, and effectiveness in recovering IT systems and data after a disruptive event.

  • DRP is a living document, not static.
  • Changes in IT environment necessitate updates.
  • Testing validates assumptions and identifies gaps.

Memory trick: Old plan, new systems, big problems.

More Domain 2: Governance and Management of IT questions