Certified Information Security Manager (CISM)Incident ManagementHard

An organization is conducting a disaster recovery (DR) exercise. The scenario involves the complete loss of a primary data center. After successfully restoring applications and data to the alternate site, the CISO observes that end-users are having difficulty performing their daily tasks due to unfamiliarity with the recovered system's interface and workflow changes. Which critical aspect of DR planning was MOST likely neglected?

  1. AInfrastructure scaling for peak loads
  2. BLegal and regulatory compliance review
  3. CRecovery Point Objective (RPO) validation
  4. DUser acceptance testing (UAT) at the recovery site
Show answer & explanation

Correct answer: D. User acceptance testing (UAT) at the recovery site

End-users struggling with the recovered system's interface and workflow points directly to a lack of user acceptance testing (UAT) at the recovery site. UAT ensures that the recovered systems are不仅 functional but also usable and acceptable to the end-users for performing their business processes.

Why the other options are wrong

  • A. Infrastructure scaling addresses performance under load, not user familiarity with interfaces or workflows.
  • B. Compliance review ensures legal adherence, not the usability of the recovered system for daily tasks.
  • C. RPO validation checks data loss, not user usability or workflow.

DR User Acceptance Testing (UAT)

A phase in disaster recovery testing where end-users validate that recovered systems and applications function correctly, meet business requirements, and are usable in the disaster recovery environment.

  • Focuses on user experience and business process functionality.
  • Identifies gaps between recovery and operational needs.
  • Ensures smooth transition for end-users post-recovery.

Memory trick: Users can't use it if they haven't tested it.

More Incident Management questions