Certified Information Security Manager (CISM)Incident ManagementMedium

An organization relies on a third-party cloud provider for its critical customer relationship management (CRM) system. The CISO is reviewing the disaster recovery capabilities for this system. Which of the following is the MOST effective way to ensure the cloud provider's disaster recovery plan (DRP) aligns with the organization's specific recovery time objectives (RTOs) and recovery point objectives (RPOs)?

  1. AImplement a redundant on-premises CRM system as a backup to the cloud service.
  2. BRely on the cloud provider's standard Service Level Agreement (SLA) for DR.
  3. CNegotiate a custom DRP addendum to the contract, detailing specific RTO/RPO commitments and testing requirements.
  4. DConduct regular third-party audits of the cloud provider's DR facilities and processes.
Show answer & explanation

Correct answer: C. Negotiate a custom DRP addendum to the contract, detailing specific RTO/RPO commitments and testing requirements.

Standard SLAs often provide generic recovery objectives that may not align with an organization's specific, business-driven RTO/RPO. Negotiating a custom DRP addendum ensures that the provider's commitments are explicitly tailored to the organization's needs and include validation through testing.

Why the other options are wrong

  • A. Implementing an on-premises redundant system is a costly and complex solution that negates many benefits of cloud, and doesn't ensure the *cloud provider's* DRP aligns with objectives.
  • B. Standard SLAs may not offer the granular RTO/RPO commitments required for specific critical systems.
  • D. Audits provide assurance but do not establish the contractual commitment to specific RTO/RPO targets or testing requirements tailored to the organization.

Third-Party DR Alignment

Ensuring that a third-party vendor's disaster recovery capabilities and commitments meet the specific RTOs and RPOs of the organization using their services.

  • Critical for cloud and outsourced services.
  • Requires clear contractual agreements and validation.
  • Standard SLAs may not be sufficient for critical systems.

Memory trick: Cloud DR needs 'C.O.N.T.R.A.C.T.S.': Custom RTOs, Operational testing, Negotiation, Terms, Reviews, Audits, Communication, and SLAs.

More Incident Management questions