ISACA Certified Information Systems Auditor (CISA) ExamDomain 3: Information Systems Acquisition, Development and ImplementationHard
An IS auditor is evaluating the organization's disaster recovery plan (DRP) for its critical financial system. The DRP outlines detailed procedures for restoring the system at an alternate site. However, the auditor finds no evidence of the DRP having been tested in the last two years. Which of the following is the MOST significant risk associated with this finding?
- AThe DRP documentation may be outdated and not reflect current system configurations.
- BKey personnel may not be familiar with their roles and responsibilities during a disaster.
- CThe alternate site infrastructure may not be capable of supporting the critical system.
- DThe organization may not be able to recover its critical financial system within its recovery time objective (RTO).
Show answer & explanationAnswer & explanation
Correct answer: D. The organization may not be able to recover its critical financial system within its recovery time objective (RTO).
The ultimate purpose of a DRP is to enable recovery within defined RTOs and RPOs. Untested DRPs carry the highest risk that the recovery process will fail or be significantly delayed, directly impacting the organization's ability to resume critical operations within acceptable timeframes.
Why the other options are wrong
- A. Outdated documentation is a consequence of not testing, but the primary risk is operational failure, not just documentation.
- B. Lack of personnel familiarity is a significant risk that contributes to recovery failure, but it's a component of the broader risk of not meeting RTO.
- C. Infrastructure capability is a risk, but it's a specific aspect that would be uncovered during a test; the failure to test means this, and other, crucial issues might prevent actual recovery.
Disaster Recovery Plan (DRP) Testing
DRP testing involves simulating a disaster scenario to validate the effectiveness of the disaster recovery plan and identify any weaknesses or gaps.
- Essential for ensuring business continuity.
- Types include walkthroughs, simulations, and full interruptions.
- Should be conducted regularly and documented.
Memory trick: No Drill, No Recovery, No Time.