ExamGecko
Question list
Search
Search

Related questions











Question 574 - CISA discussion

Report
Export

An organization outsourced its IS functions to meet its responsibility for disaster recovery, the organization should:

A.
discontinue maintenance of the disaster recovery plan (DRP>
Answers
A.
discontinue maintenance of the disaster recovery plan (DRP>
B.
coordinate disaster recovery administration with the outsourcing vendor
Answers
B.
coordinate disaster recovery administration with the outsourcing vendor
C.
delegate evaluation of disaster recovery to a third party
Answers
C.
delegate evaluation of disaster recovery to a third party
D.
delegate evaluation of disaster recovery to internal audit
Answers
D.
delegate evaluation of disaster recovery to internal audit
Suggested answer: B

Explanation:

An organization outsourced its IS functions. To meet its responsibility for disaster recovery, the organization should coordinate disaster recovery administration with the outsourcing vendor. This is because the organization remains accountable for ensuring the continuity and availability of its IS functions, even if they are outsourced to a third party. The organization should establish clear roles and responsibilities, communication channels, testing procedures, and escalation processes with the outsourcing vendor for disaster recovery purposes. The organization should not discontinue maintenance of the disaster recovery plan (DRP), as it still needs to have a documented and updated plan for restoring its IS functions in case of a disaster. The organization should not delegate evaluation of disaster recovery to a third party or internal audit, as it still needs to monitor and review the performance and compliance of the outsourcing vendor with respect to disaster recovery objectives and standards.Reference:CISA Review Manual (Digital Version), [ISACA Auditing Standards]

asked 18/09/2024
Penny Chang
47 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first