Certified Information Security Manager (CISM)Incident ManagementHard
A CISO is developing a disaster recovery plan (DRP) for an organization that operates in a highly regulated industry. During the DRP development, it is identified that a key third-party cloud provider, hosting critical customer relations management (CRM) data, has an RTO of 24 hours, while the organization's RTO for the CRM system is 4 hours. Which of the following is the BEST initial action for the CISO to address this discrepancy?
- ADevelop an internal shadow IT solution to replicate the CRM data for faster recovery.
- BNegotiate a revised Service Level Agreement (SLA) with the current provider to meet the 4-hour RTO.
- CUpdate the organization's RTO to align with the cloud provider's 24-hour RTO.
- DImmediately switch to a different cloud provider with a lower RTO.
Show answer & explanationAnswer & explanation
Correct answer: B. Negotiate a revised Service Level Agreement (SLA) with the current provider to meet the 4-hour RTO.
The best initial action is to negotiate a revised SLA. This directly addresses the discrepancy by attempting to align the provider's capabilities with the organization's requirements, which is a standard and proper procedure before considering more drastic or costly measures. If negotiation fails, then other options may be explored.
Why the other options are wrong
- A. Developing an internal shadow IT solution is risky, potentially non-compliant, and undermines the purpose of using a cloud provider.
- C. Updating the organization's RTO to match the provider's is essentially accepting a higher risk tolerance without exploring better options, which is not ideal in a regulated industry.
- D. Switching providers immediately is a drastic and potentially costly step without first attempting to resolve the issue with the current provider.
Third-Party DR Alignment
Ensuring that the disaster recovery capabilities and objectives (e.g., RTOs, RPOs) of third-party vendors and cloud providers are aligned with, and capable of supporting, the organization's own DRP requirements.
- Critical for services hosted externally.
- Typically managed through Service Level Agreements (SLAs).
- Discrepancies can lead to significant recovery gaps.
Memory trick: Align your clocks with your partners, or be late.