Certified Information Security Manager (CISM)Incident ManagementMedium

A CISO is developing a disaster recovery plan (DRP) for an organization that relies heavily on a single, aging data center. The CISO identifies the data center as a significant single point of failure. Which of the following strategies BEST mitigates this risk while ensuring business continuity?

  1. AUpgrading the existing data center infrastructure with redundant power and cooling systems.
  2. BNegotiating a contract with a third-party vendor for on-demand cloud computing resources.
  3. CImplementing a rigorous backup schedule for all data and systems to an offsite tape library.
  4. DEstablishing a geographically separate hot site with real-time data replication for critical systems.
Show answer & explanation

Correct answer: D. Establishing a geographically separate hot site with real-time data replication for critical systems.

A geographically separate hot site with real-time data replication provides the highest level of resilience against a single data center failure, allowing for near-instantaneous failover and minimal data loss, thus best ensuring business continuity.

Why the other options are wrong

  • A. Upgrading the existing data center only protects against internal component failures, not against a site-wide disaster like a fire or natural disaster.
  • B. On-demand cloud resources might be slow to provision and configure for complex systems, potentially impacting RTO/RPO.
  • C. Offsite tape backups are good for data recovery but do not provide rapid system recovery or continuity in case of a data center failure.

Hot Site

A fully equipped, offsite data center that can be operational within hours, often with mirrored or real-time replicated data from the primary site.

  • Provides the quickest recovery time (lowest RTO).
  • Minimizes data loss (lowest RPO) through continuous replication.
  • Most expensive recovery option due to ongoing operational costs.

Memory trick: Hot sites are like having a twin data center ready to jump in.

More Incident Management questions