ISACA Certified Information Systems Auditor (CISA) ExamDomain 4: Information Systems Operations and Business ResilienceHard

An IS auditor is assessing an organization's business continuity capabilities. The organization relies heavily on a third-party cloud provider for its critical applications. The auditor notes that while the organization has a DRP for its on-premise infrastructure, it has not formally reviewed the cloud provider's disaster recovery capabilities or their Service Level Agreements (SLAs) for recovery. What is the MOST significant risk in this scenario?

  1. ALack of clarity regarding data ownership in the cloud environment.
  2. BUnderestimation of the organization's overall recovery time objective (RTO).
  3. CNon-compliance with internal IT policies on vendor management.
  4. DIncreased cost for cloud services due to unnegotiated recovery clauses.
Show answer & explanation

Correct answer: B. Underestimation of the organization's overall recovery time objective (RTO).

If critical applications reside in the cloud and the organization hasn't reviewed the provider's DRP or SLAs, it cannot accurately determine how quickly those applications can be restored. This leads to an underestimation of the true RTO for critical business functions, creating a false sense of security and potentially catastrophic delays during a real disaster.

Why the other options are wrong

  • A. Data ownership is a separate, albeit important, cloud governance issue, not directly related to disaster recovery capabilities.
  • C. Non-compliance is a consequence, but the operational risk of a failed recovery due to RTO misalignment is more critical.
  • D. While cost is a factor, the primary risk for business continuity is the actual ability to recover, not just the financial aspect.

Cloud DRP Alignment Risk

The danger of assuming a cloud provider's inherent resilience without formally reviewing their disaster recovery capabilities and SLAs, leading to misaligned RTOs and potential business continuity failures.

  • Shared responsibility model applies to cloud DR.
  • Requires due diligence on provider's DRP and SLAs.
  • Misalignment can lead to prolonged outages for critical services.

Memory trick: Outsourcing your umbrella but not checking if it's waterproof.

More Domain 4: Information Systems Operations and Business Resilience questions