ExamGecko
Question list
Search
Search

Related questions











Question 708 - CISA discussion

Report
Export

Which of the following should be the GREATEST concern for an IS auditor assessing an organization's disaster recovery plan (DRP)?

A.
The DRP was developed by the IT department.
Answers
A.
The DRP was developed by the IT department.
B.
The DRP has not been tested during the past three years.
Answers
B.
The DRP has not been tested during the past three years.
C.
The DRP has not been updated for two years.
Answers
C.
The DRP has not been updated for two years.
D.
The DRP does not include the recovery the time objective (RTO) for a key system.
Answers
D.
The DRP does not include the recovery the time objective (RTO) for a key system.
Suggested answer: B

Explanation:

The DRP is a set of procedures and resources that enable an organization to restore its critical IT functions and operations in the event of a disaster or disruption. The DRP should be tested regularly to ensure its effectiveness, validity, and readiness. Testing the DRP can help to identify and resolve any gaps, issues, or weaknesses in the plan, as well as to evaluate the performance and capability of the recovery team and resources. If the DRP has not been tested during the past three years, it may not reflect the current IT environment, business requirements, or recovery objectives, and it may fail to meet the expectations and needs of the stakeholders.

Reference

ISACA CISA Review Manual, 27th Edition, page 255

Disaster Recovery Plan Testing: The Ultimate Checklist

What is a Disaster Recovery Plan (DRP) and How Do You Write One?

asked 18/09/2024
Miroslav Burzinskij
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first