ISACA Certified Information Systems Auditor (CISA) ExamDomain 4: Information Systems Operations and Business ResilienceMedium

An IS auditor is evaluating an organization's disaster recovery plan (DRP). The auditor observes that while the DRP outlines detailed technical recovery procedures for critical IT systems, it lacks specific instructions for coordinating with external emergency services and key vendors during a disaster. What is the MOST significant risk posed by this omission?

  1. AInability to effectively manage external dependencies, prolonging overall business recovery.
  2. BIncreased Recovery Time Objective (RTO) for critical systems due to technical delays.
  3. CFailure to meet regulatory compliance requirements for data privacy during an outage.
  4. DCompromise of data integrity and availability during the disaster recovery process.
Show answer & explanation

Correct answer: A. Inability to effectively manage external dependencies, prolonging overall business recovery.

The lack of coordination instructions for external emergency services and key vendors directly impacts the organization's ability to manage external dependencies. This can lead to significant delays in overall business recovery, even if internal technical systems are restored promptly, as critical external support or supplies may be unavailable.

Why the other options are wrong

  • B. While technical delays can increase RTO, this omission specifically addresses external coordination, which is a broader business recovery concern beyond just technical system restoration.
  • C. Regulatory compliance for data privacy is important, but the primary and most immediate risk of lacking external coordination in a DRP is the practical impediment to recovery operations, not necessarily a direct breach of data privacy.
  • D. Data integrity and availability are crucial, but the scenario describes a lack of coordination instructions, not a flaw in the technical data recovery procedures themselves that would directly compromise integrity or availability.

External Dependency Management (DRP)

The process within a Disaster Recovery Plan (DRP) that ensures the organization can effectively coordinate with and leverage external entities (e.g., emergency services, vendors, suppliers) essential for recovery.

  • Critical for comprehensive business recovery, not just IT system restoration.
  • Involves pre-planning communication, roles, and responsibilities with external partners.
  • Failure can lead to significant delays and complications in disaster response.

Memory trick: External hands help, or recovery stands still.

More Domain 4: Information Systems Operations and Business Resilience questions