ExamGecko
Question list
Search
Search

Related questions











Question 482 - CISA discussion

Report
Export

A disaster recovery plan (DRP) should include steps for:

A.
assessing and quantifying risk.
Answers
A.
assessing and quantifying risk.
B.
negotiating contracts with disaster planning consultants.
Answers
B.
negotiating contracts with disaster planning consultants.
C.
identifying application control requirements.
Answers
C.
identifying application control requirements.
D.
obtaining replacement supplies.
Answers
D.
obtaining replacement supplies.
Suggested answer: D

Explanation:

A disaster recovery plan (DRP) is a set of detailed, documented guidelines that outline a business' critical assets and explain how the organization will respond to unplanned incidents.Unplanned incidents or disasters typically include cyberattacks, system failures, power outages, natural disasters, equipment failures, or infrastructure damage1. A DRP aims to minimize the impact of a disaster on the business continuity, data integrity, and service delivery of the organization. A DRP also helps the organization recover from a disaster as quickly and efficiently as possible.

A DRP should include steps for obtaining replacement supplies, as this is an essential part of restoring the normal operation of the organization after a disaster. Replacement supplies may include hardware, software, data, network components, office equipment, or other resources that are needed to resume the business functions and processes that were disrupted by the disaster. Obtaining replacement supplies may involve contacting vendors, suppliers, or partners; activating backup or alternative systems; or purchasing or renting new equipment. A DRP should identify the sources, locations, and costs of the replacement supplies, as well as the procedures and responsibilities for acquiring and installing them.

The other three options are not steps that a DRP should include, as they are either part of the pre-disaster planning process or not directly related to the disaster recovery objectives.Assessing and quantifying risk is a step that should be done before creating a DRP, as it helps identify the potential threats and vulnerabilities that could affect the organization and determine the likelihood and impact of each scenario2.Negotiating contracts with disaster planning consultants is also a pre-disaster activity that may help the organization design, implement, test, and maintain a DRP with external expertise and guidance3. Identifying application control requirements is not a step in a DRP, but rather a part of the application development and maintenance process that ensures the quality, security, and reliability of the software applications used by the organization.

Therefore, obtaining replacement supplies is the correct answer.

What is a Disaster Recovery Plan? + Complete Checklist

Risk Assessment - ISACA

Disaster Recovery Planning - ISACA

[Application Controls - ISACA]

asked 18/09/2024
Paula Delgado
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first