Certified Information Security Manager (CISM)Incident ManagementMedium

An organization is conducting a disaster recovery (DR) exercise. The scenario involves the loss of its primary data center. During the exercise, the CISO observes that while all systems are technically restored at the recovery site, several key business applications fail to communicate with each other due to incorrect network configurations and outdated firewall rules at the new location. Which aspect of the DR exercise was inadequately tested?

  1. AThe restoration of individual system backups.
  2. BThe physical security of the recovery site.
  3. CInter-application dependencies and network connectivity.
  4. DRecovery Point Objective (RPO) attainment.
Show answer & explanation

Correct answer: C. Inter-application dependencies and network connectivity.

The failure of applications to communicate due to network configurations and firewall rules indicates that the testing did not adequately address inter-application dependencies and network connectivity at the recovery site. Successful DR requires not just individual system restoration but also ensuring the entire ecosystem functions together.

Why the other options are wrong

  • A. Individual system backups were likely restored if the systems were 'technically restored.' The issue is their interaction.
  • B. Physical security is important but unrelated to applications failing to communicate post-restoration.
  • D. RPO relates to data loss, not the communication between restored applications.

DR Inter-Application Dependency Testing

A critical component of disaster recovery testing that validates the proper communication, integration, and functionality of interdependent applications and services after recovery.

  • Ensures the entire business ecosystem functions.
  • Identifies network, firewall, and configuration issues.
  • Goes beyond individual system restoration.

Memory trick: Restoring apps is like putting puzzle pieces back, but dependency testing ensures they 'click' together.

More Incident Management questions