Certified Information Security Manager (CISM)Incident ManagementMedium

A CISO is reviewing the organization's disaster recovery plan (DRP) and notes that while it outlines detailed procedures for restoring IT systems, it lacks specific guidance for the business units to validate the functionality and data integrity of their applications after recovery. Which critical aspect of disaster recovery is missing?

  1. AA comprehensive communication plan for stakeholders.
  2. BThe definition of Recovery Time Objective (RTO).
  3. CProcedures for user acceptance testing (UAT) and business sign-off.
  4. DThe establishment of a warm standby recovery site.
Show answer & explanation

Correct answer: C. Procedures for user acceptance testing (UAT) and business sign-off.

The absence of specific guidance for business units to validate application functionality and data integrity after recovery points to a missing user acceptance testing (UAT) and business sign-off process. This is crucial to ensure that restored systems meet business requirements and are fully operational from an end-user perspective.

Why the other options are wrong

  • A. A communication plan informs stakeholders, but doesn't validate application functionality.
  • B. RTO defines *when* systems should be recovered, not *how* business units validate them.
  • D. This is a recovery strategy, not a validation process for business functionality.

DRP User Acceptance Testing (UAT)

A critical phase in disaster recovery planning where business users validate the functionality, performance, and data integrity of restored applications and systems.

  • Ensures restored systems meet business requirements.
  • Identifies issues before full production resumption.
  • Requires active participation from business unit representatives.

Memory trick: Restoring systems is like baking a cake; UAT is the taste test to ensure it's actually edible for the business.

More Incident Management questions