ISACA Certified Information Systems Auditor (CISA) ExamDomain 5: Protection of Information AssetsMedium

A CISA is reviewing an organization's business continuity plan (BCP) and disaster recovery plan (DRP). The organization has defined a Recovery Time Objective (RTO) of 4 hours and a Recovery Point Objective (RPO) of 1 hour for its critical financial application. The CISA discovers that backups for this application are performed daily at midnight, and the restoration process typically takes 3 hours. What is the MOST critical finding for the CISA to report?

  1. AThe BCP and DRP are not integrated with the security incident response plan.
  2. BThe RTO of 4 hours is too aggressive for the application's criticality.
  3. CThe restoration time of 3 hours does not meet the RTO requirement.
  4. DThe daily backup schedule does not meet the RPO requirement.
Show answer & explanation

Correct answer: D. The daily backup schedule does not meet the RPO requirement.

The RPO (Recovery Point Objective) defines the maximum acceptable amount of data loss, in this case, 1 hour. Daily backups at midnight mean that in a disaster, up to 24 hours of data could be lost, which far exceeds the 1-hour RPO. This is the most critical finding as it directly violates a key recovery objective.

Why the other options are wrong

  • A. Integration is important, but the question focuses on meeting RTO/RPO; the direct violation of RPO is a more immediate and critical finding.
  • B. The CISA's role is to evaluate against defined objectives, not to question their aggressiveness without further context.
  • C. While a 3-hour restoration time for a 4-hour RTO leaves only 1 hour of buffer, it *technically* meets the RTO, albeit with minimal margin. The RPO violation is more severe.

Recovery Point Objective (RPO)

The maximum acceptable amount of data loss measured in time, representing the age of files that must be recovered from backup storage for normal operations to resume.

  • Determines how frequently data must be backed up.
  • Expressed in terms of time (e.g., 1 hour, 24 hours).
  • A key metric for disaster recovery planning.

Memory trick: RPO is how much data you can lose; daily backups are losing too much for a 1-hour limit.

More Domain 5: Protection of Information Assets questions