ISACA Certified Information Systems Auditor (CISA) ExamDomain 5: Protection of Information AssetsEasy
A CISA is reviewing an organization's data backup and recovery strategy. The organization performs daily full backups to tape, which are stored offsite. The CISA learns that the organization has never performed a full restoration test of its critical systems from these offsite tapes. What is the MOST significant risk associated with this finding?
- ANon-compliance with data retention regulations.
- BIncreased recovery time objectives (RTO) for business operations.
- CInability to recover critical data and systems during a disaster.
- DHigher storage costs due to tape media usage.
Show answer & explanationAnswer & explanation
Correct answer: C. Inability to recover critical data and systems during a disaster.
Without performing restoration tests, there is no assurance that the backups are viable or that the recovery process will work as expected. This directly translates to an inability to recover critical data and systems when a disaster strikes, rendering the entire backup strategy ineffective.
Why the other options are wrong
- A. Data retention is about keeping data for a certain period, not necessarily about the ability to restore it from backup, though they are related.
- B. While an untested recovery process might lead to increased RTO, the more fundamental risk is the complete failure of recovery, not just its speed.
- D. While tape storage can have specific cost implications, it's not the primary security or operational risk of untested backups.
Backup Restoration Testing
The process of regularly verifying that backed-up data can be successfully restored and that systems can be brought back online using recovery procedures.
- Ensures the integrity and usability of backups.
- Identifies issues in backup media, software, or recovery procedures.
- Crucial for meeting RTO and RPO objectives.
Memory trick: Having a fire extinguisher is great, but does it actually work when you need it?