Certified Information Security Manager (CISM)Incident ManagementHard

A CISO is reviewing the organization's business continuity plan (BCP) and identifies a critical dependency on a single third-party vendor for a key communication platform. A disruption to this vendor could severely impact the organization's ability to communicate with customers and employees during a crisis. Which of the following is the MOST effective strategy to mitigate this single point of failure within the BCP?

  1. AImplement service level agreements (SLAs) with the vendor for high availability and quick recovery.
  2. BDevelop an alternative communication strategy and relationship with a secondary vendor.
  3. CRequire the vendor to provide their own BCP document for review.
  4. DConduct annual penetration tests on the vendor's communication platform.
Show answer & explanation

Correct answer: B. Develop an alternative communication strategy and relationship with a secondary vendor.

To mitigate a single point of failure, especially for a critical dependency, establishing an alternative strategy with a secondary vendor provides true resilience. While SLAs and vendor BCPs offer assurance, they don't eliminate the risk of a single vendor failing entirely; a secondary option ensures continuity.

Why the other options are wrong

  • A. SLAs provide contractual remedies but don't prevent the disruption itself or guarantee continuity if the primary vendor is completely unavailable.
  • C. Reviewing the vendor's BCP provides insight but doesn't eliminate the single point of failure if that vendor still fails.
  • D. Penetration tests assess security, not the availability or resilience of the vendor's platform during a broad disaster.

Mitigating Single Point of Failure (BCP)

Strategies employed within a Business Continuity Plan to prevent a single component, system, or vendor from causing a complete disruption of critical business operations.

  • Involves redundancy, diversification, and alternative solutions.
  • Critical for high-impact dependencies.
  • Goes beyond contractual assurances to actual operational resilience.

Memory trick: SPOF mitigation needs 'D.R.A.F.T.': Diversify, Redundancy, Alternate vendors, Failover planning, and Testing alternatives.

More Incident Management questions