ISACA Certified Information Systems Auditor (CISA) ExamDomain 5: Protection of Information AssetsMedium

A CISA is reviewing an organization's data backup and recovery strategy. The organization uses tape backups, which are stored off-site. The CISA discovers that while backups are performed nightly, a full restoration test has not been conducted in over two years. What is the MOST significant risk this presents to the organization's information assets?

  1. ANon-compliance with regulatory requirements for data recoverability.
  2. BInability to reliably recover critical data in the event of a disaster or data loss event.
  3. CPotential for backup media degradation, rendering the data unrecoverable.
  4. DIncreased recovery time objective (RTO) due to the age of the last successful test.
Show answer & explanation

Correct answer: B. Inability to reliably recover critical data in the event of a disaster or data loss event.

The primary purpose of backups is to ensure critical data can be reliably recovered. Without regular full restoration tests, there is no assurance that the backup process is functioning correctly, that the data is intact, or that the recovery procedures are effective. This directly leads to the most significant risk: the potential complete inability to recover critical data when needed, which could be catastrophic for the organization.

Why the other options are wrong

  • A. Non-compliance is a serious issue, but it is a legal/regulatory risk. The 'most significant risk to information assets' directly relates to the usability and integrity of the data itself.
  • C. Media degradation is a possibility, but the lack of testing means the organization wouldn't even know if degradation has occurred until a disaster, making the inability to recover the overarching risk.
  • D. While an outdated test might impact RTO, the more fundamental and significant risk is the *certainty* of recovery itself, not just the speed.

Backup Restoration Testing

The process of periodically verifying that backed-up data can be successfully restored and is usable, ensuring the effectiveness of the backup strategy.

  • Essential for confirming data integrity and recovery procedures.
  • Should be conducted regularly, not just after incidents.
  • Reveals issues with backup software, media, or recovery documentation.

Memory trick: Don't just 'BACKUP', 'TEST' if it's really there.

More Domain 5: Protection of Information Assets questions