ISACA Certified Information Systems Auditor (CISA) ExamDomain 1: Information System Auditing ProcessHard

An IS auditor is reviewing an organization's business continuity plan (BCP) and disaster recovery plan (DRP). The organization has recently migrated critical applications to a new cloud provider. What is the MOST important aspect for the IS auditor to verify regarding the updated BCP/DRP?

  1. AThat all data backups are encrypted and stored in a different geographical region.
  2. BThat the organization has purchased additional cyber insurance coverage for cloud services.
  3. CThat the new cloud provider's service level agreement (SLA) guarantees 99.999% uptime.
  4. DThat the BCP/DRP incorporates the cloud provider's responsibilities and capabilities for recovery.
Show answer & explanation

Correct answer: D. That the BCP/DRP incorporates the cloud provider's responsibilities and capabilities for recovery.

When migrating to the cloud, the organization's BCP/DRP must be updated to reflect the shared responsibility model. It is crucial to verify that the plan clearly defines the cloud provider's role in recovery (e.g., infrastructure recovery, data center availability) and how the organization's internal recovery procedures integrate with the provider's capabilities. Without this integration, the plan may be ineffective.

Why the other options are wrong

  • A. Encryption and offsite backups are important security and recovery measures, but they are components, not the overarching integration needed for a cloud-based BCP/DRP.
  • B. Cyber insurance is a risk transfer mechanism, not a part of the operational recovery plan itself.
  • C. While high uptime is desirable, an SLA alone doesn't guarantee recovery or define the organizational response when an outage occurs.

BCP/DRP in Cloud Environments

In cloud environments, business continuity and disaster recovery plans must be explicitly updated to articulate the shared responsibility model, integrating the cloud provider's recovery capabilities with the organization's own recovery strategies and processes.

  • Cloud introduces a shared responsibility model for security and recovery.
  • BCP/DRP must address provider's RTO/RPO and recovery mechanisms.
  • Testing is crucial to validate integrated plans.

Memory trick: Cloud Co-op: Coordinate, Communicate, Confirm.

More Domain 1: Information System Auditing Process questions