Certified Information Security Manager (CISM)Incident ManagementHard

A CISO is developing a disaster recovery plan (DRP) for an organization that operates in a highly regulated industry. During the DRP development, it is identified that a key third-party cloud provider, hosting critical customer relations management (CRM) data, has an RTO of 24 hours, while the organization's RTO for the CRM system is 4 hours. Which of the following is the BEST initial action for the CISO to address this discrepancy?

  1. ADevelop an internal shadow IT solution to replicate the CRM data for faster recovery.
  2. BNegotiate a revised Service Level Agreement (SLA) with the current provider to meet the 4-hour RTO.
  3. CUpdate the organization's RTO to align with the cloud provider's 24-hour RTO.
  4. DImmediately switch to a different cloud provider with a lower RTO.
Show answer & explanation

Correct answer: B. Negotiate a revised Service Level Agreement (SLA) with the current provider to meet the 4-hour RTO.

The best initial action is to negotiate a revised SLA. This directly addresses the discrepancy by attempting to align the provider's capabilities with the organization's requirements, which is a standard and proper procedure before considering more drastic or costly measures. If negotiation fails, then other options may be explored.

Why the other options are wrong

  • A. Developing an internal shadow IT solution is risky, potentially non-compliant, and undermines the purpose of using a cloud provider.
  • C. Updating the organization's RTO to match the provider's is essentially accepting a higher risk tolerance without exploring better options, which is not ideal in a regulated industry.
  • D. Switching providers immediately is a drastic and potentially costly step without first attempting to resolve the issue with the current provider.

Third-Party DR Alignment

Ensuring that the disaster recovery capabilities and objectives (e.g., RTOs, RPOs) of third-party vendors and cloud providers are aligned with, and capable of supporting, the organization's own DRP requirements.

  • Critical for services hosted externally.
  • Typically managed through Service Level Agreements (SLAs).
  • Discrepancies can lead to significant recovery gaps.

Memory trick: Align your clocks with your partners, or be late.

More Incident Management questions