ISACA Certified Information Systems Auditor (CISA) ExamDomain 4: Information Systems Operations and Business ResilienceEasy

An IS auditor is reviewing an organization's disaster recovery plan (DRP). The auditor notes that the DRP includes detailed procedures for restoring critical IT systems and data, but it lacks specific guidance for communicating with external stakeholders (e.g., customers, suppliers, regulators) during and after a disaster. What is the MOST significant risk associated with this omission?

  1. AIncreased workload for the IT recovery team during the disaster.
  2. BInability to accurately assess the financial impact of the disaster.
  3. CDelay in restoring IT systems to full operation.
  4. DLoss of customer confidence and potential regulatory sanctions.
Show answer & explanation

Correct answer: D. Loss of customer confidence and potential regulatory sanctions.

Failing to communicate effectively with external stakeholders during a disaster can lead to a loss of trust from customers and suppliers, and potential non-compliance with regulatory disclosure requirements, resulting in sanctions. This directly impacts the organization's reputation and legal standing.

Why the other options are wrong

  • A. While it might shift workload, the primary risk is not internal workload but rather external relationship damage and legal exposure.
  • B. Financial assessment is internal and typically occurs after initial recovery, not directly impacted by external communication procedures.
  • C. System restoration is an internal IT process; external communication, while important, doesn't directly delay the technical recovery itself.

Disaster Recovery Communication Plan

A component of the DRP that outlines how an organization will communicate with all relevant internal and external stakeholders during and after a disaster event.

  • Ensures timely and accurate information dissemination.
  • Maintains stakeholder confidence.
  • Addresses legal and regulatory disclosure requirements.

Memory trick: Silence in a storm sinks the ship of trust.

More Domain 4: Information Systems Operations and Business Resilience questions