ISACA Certified Information Systems Auditor (CISA) ExamDomain 4: Information Systems Operations and Business ResilienceEasy
An IS auditor is evaluating an organization's information systems operations. The auditor observes that critical system backups are performed weekly, but the organization's Recovery Point Objective (RPO) for these systems is 24 hours. What is the MOST significant risk identified by the auditor?
- APotential for unauthorized access to backup data.
- BLack of proper backup media rotation.
- CInability to meet the defined Recovery Point Objective (RPO).
- DInsufficient offsite storage of backup media.
Show answer & explanationAnswer & explanation
Correct answer: C. Inability to meet the defined Recovery Point Objective (RPO).
The Recovery Point Objective (RPO) defines the maximum tolerable period in which data might be lost from an IT service due to a major incident. If backups are performed weekly but the RPO is 24 hours, the organization cannot recover to a point within 24 hours, meaning up to six days of data could be lost, directly violating the RPO.
Why the other options are wrong
- A. Unauthorized access is a security risk, not directly related to the ability to restore data within the defined RPO.
- B. While important, media rotation is a procedural aspect and not the most significant risk related to RPO non-compliance.
- D. Offsite storage protects against site-specific disasters but does not address the frequency of data capture relative to the RPO.
Recovery Point Objective (RPO)
The Recovery Point Objective (RPO) is the maximum tolerable period in which data might be lost from an IT service due to a major incident. It defines how much data loss is acceptable.
- Determined by business impact analysis.
- Dictates backup frequency.
- Measured in time (e.g., 1 hour, 24 hours).
Memory trick: RPO: How much 'past' data loss is 'OK'?