ISACA Certified Information Systems Auditor (CISA) ExamDomain 1: Information System Auditing ProcessMedium

An IS auditor is conducting a post-implementation review of a newly deployed customer relationship management (CRM) system. The project was completed on time and within budget, and initial user feedback is generally positive. However, during the review, the auditor discovers that the system's data backup and recovery procedures were not formally tested prior to going live. What should be the IS auditor's PRIMARY concern?

  1. AThe impact on project budget and timeline if testing is performed now.
  2. BThe potential for significant business disruption and data loss.
  3. CThe non-compliance with internal IT project management policies.
  4. DThe lack of user training on backup and recovery procedures.
Show answer & explanation

Correct answer: B. The potential for significant business disruption and data loss.

Untested backup and recovery procedures for a critical system like CRM pose a direct and significant risk of business disruption and irreversible data loss in the event of a system failure. While other options are concerns, the potential for operational impact and data loss is the most critical.

Why the other options are wrong

  • A. Budget and timeline impacts are secondary to the operational risks associated with untested recovery.
  • C. Non-compliance is a finding, but the 'primary concern' relates to the risk consequence of that non-compliance.
  • D. User training is important, but the fundamental issue is the untested procedures themselves.

Business Continuity Risk

The potential for significant disruption to business operations and loss of data due to system failures or disasters, especially when recovery mechanisms are unproven.

  • Impacts operational resilience.
  • Can lead to financial and reputational damage.
  • Mitigated by tested DRP/BCP.

Memory trick: Untested recovery is like a parachute you've never opened: a huge risk when you need it most.

More Domain 1: Information System Auditing Process questions