Certified Information Security Manager (CISM)Incident ManagementHard

An organization is conducting a disaster recovery (DR) exercise. During the exercise, it is discovered that while primary applications are restored, critical inter-application dependencies are not correctly re-established, leading to downstream system failures and an extended recovery time. Which of the following activities should the CISO prioritize to prevent this issue in future DR scenarios?

  1. AUpgrading network infrastructure to support higher bandwidth for DR operations.
  2. BDeveloping and regularly validating an inter-application dependency map.
  3. CImplementing a comprehensive backup and restore strategy for all application databases.
  4. DConducting regular user acceptance testing (UAT) on individual restored applications.
Show answer & explanation

Correct answer: B. Developing and regularly validating an inter-application dependency map.

The core problem is 'critical inter-application dependencies are not correctly re-established'. Developing and regularly validating an inter-application dependency map directly addresses this by providing a clear understanding of how systems are interconnected, which is essential for ensuring their correct recovery order and configuration after a disaster.

Why the other options are wrong

  • A. Network bandwidth upgrades improve performance but do not solve the logical problem of understanding and re-establishing dependencies.
  • C. Backup and restore ensures data availability but doesn't guarantee the correct re-establishment of application connections.
  • D. UAT on individual applications confirms their functionality in isolation but fails to test their interactions with other systems.

Inter-Application Dependency Mapping

The process of identifying, documenting, and visualizing the relationships and dependencies between different software applications and systems.

  • Crucial for understanding the impact of failures and planning recovery.
  • Helps determine the correct order of recovery for interdependent systems.
  • Often involves discovering data flows, API calls, and shared services.

Memory trick: To fix the web, you need a map of its threads.

More Incident Management questions