Certified Information Security Manager (CISM)Incident ManagementHard
A CISO is reviewing the organization's disaster recovery plan (DRP) and notes that while individual application recovery procedures are well-documented, there is no formal process to verify that the recovered applications will collectively support critical business functions end-to-end. This leads to uncertainty about achieving the overall Recovery Time Objective (RTO). Which of the following activities should the CISO prioritize?
- APerforming User Acceptance Testing (UAT) on the recovered business processes.
- BInvesting in advanced data replication technologies for faster data recovery.
- CImplementing a comprehensive Business Impact Analysis (BIA) update.
- DConducting more frequent penetration tests on recovered applications.
Show answer & explanationAnswer & explanation
Correct answer: A. Performing User Acceptance Testing (UAT) on the recovered business processes.
The problem highlights that individual applications recover but there's no verification of 'collectively support critical business functions end-to-end'. User Acceptance Testing (UAT) specifically involves business users validating that the recovered systems and processes meet their functional requirements, ensuring the overall RTO for business functions can be met.
Why the other options are wrong
- B. Advanced data replication speeds up data recovery (RPO), but doesn't verify the functional correctness or integration of applications to support business processes.
- C. A BIA identifies critical functions and their RTO/RPO, but it doesn't *verify* the recovery. The plan already has individual application recovery procedures.
- D. Penetration tests focus on security vulnerabilities, not the functional integrity of recovered business processes.
DR User Acceptance Testing (UAT)
A formal testing phase in disaster recovery where end-users and business stakeholders validate that recovered systems and processes meet their functional requirements and support critical business operations.
- Ensures recovered systems are usable by the business.
- Validates end-to-end business process functionality.
- Crucial for confirming RTO achievement from a business perspective.
Memory trick: To know if DR works for the business, let the users test it.