Certified Information Security Manager (CISM)Incident ManagementMedium

An organization is conducting a disaster recovery (DR) exercise. During the exercise, it is discovered that several critical applications, while technically restored at the DR site, are unable to communicate with their backend databases due to incorrect network configurations. Which of the following aspects of DR planning was MOST likely overlooked?

  1. ARecovery Point Objective (RPO) validation.
  2. BPhysical security of the disaster recovery site.
  3. CBusiness Impact Analysis (BIA) completeness.
  4. DInter-application dependency mapping and testing.
Show answer & explanation

Correct answer: D. Inter-application dependency mapping and testing.

The inability of applications to communicate with their databases points directly to a failure in understanding and configuring the relationships and communication pathways between different components. This indicates that inter-application dependencies were not properly mapped or tested during DR planning.

Why the other options are wrong

  • A. RPO validation checks data loss, not connectivity between restored applications and databases.
  • B. Physical security is important but unrelated to software communication issues.
  • C. A BIA identifies criticality but doesn't detail the technical configurations required for inter-application communication.

Inter-Application Dependency Mapping

The process of identifying and documenting the relationships and communication requirements between different software applications and their underlying infrastructure components.

  • Crucial for successful disaster recovery and business continuity.
  • Ensures all necessary connections and configurations are restored.
  • Prevents 'silent failures' where applications appear up but are not functional.

Memory trick: Applications need to talk; map their conversations.

More Incident Management questions