ISACA Certified Information Systems Auditor (CISA) ExamDomain 4: Information Systems Operations and Business ResilienceHard
An IS auditor is evaluating the organization's disaster recovery plan (DRP) and notes that while it includes recovery procedures for critical applications, it does not explicitly address the recovery of network connectivity to cloud-based services. What is the MOST significant risk this omission poses?
- AHigher costs associated with maintaining redundant network infrastructure.
- BIncreased complexity in managing hybrid cloud environments.
- CLack of clear ownership for cloud network recovery within the IT team.
- DInability to access critical cloud resources, rendering applications unusable.
Show answer & explanationAnswer & explanation
Correct answer: D. Inability to access critical cloud resources, rendering applications unusable.
Many organizations rely on cloud-based services. If the DRP does not address how to re-establish network connectivity to these services after a disaster, even if the on-premise applications are recovered, they will be unable to function or access necessary data, effectively making them unusable.
Why the other options are wrong
- A. Costs are a planning consideration, but the inability to recover is a more critical operational risk.
- B. Complexity is a general challenge, but the direct operational failure is more significant.
- C. Lack of ownership is a governance issue, but the direct operational consequence of unaddressed network recovery is the inability to function.
Cloud Connectivity Recovery
The process of restoring or re-establishing network connections to cloud-based services and resources as part of a disaster recovery plan.
- Crucial for hybrid and cloud-native environments.
- Involves DNS, VPNs, direct connect, and firewall configurations.
- Often overlooked in traditional DRPs focused on on-premise systems.
Memory trick: Recovering apps without cloud network is like having a phone with no signal.