ExamGecko
Question list
Search
Search

Related questions

Question 1045 - CISA discussion

Report
Export

Which of the following would be an IS auditor's GREATEST concern when reviewing the organization's business continuity plan (BCP)?

A.
The recovery plan does not contain the process and application dependencies.
Answers
A.
The recovery plan does not contain the process and application dependencies.
B.
The duration of tabletop exercises is longer than the recovery point objective (RPO).
Answers
B.
The duration of tabletop exercises is longer than the recovery point objective (RPO).
C.
The duration of tabletop exercises is longer than the recovery time objective (RTO).
Answers
C.
The duration of tabletop exercises is longer than the recovery time objective (RTO).
D.
The recovery point objective (RPO) and recovery time objective (R TO) are not the same.
Answers
D.
The recovery point objective (RPO) and recovery time objective (R TO) are not the same.
Suggested answer: A

Explanation:

A business continuity plan (BCP) is a document that outlines how an organization will continue its critical functions in the event of a disruption or disaster.A BCP should include the following elements1:

Business impact analysis: This is the process of identifying and prioritizing the key business processes and assets that are essential for the organization's survival and recovery.

Risk assessment: This is the process of identifying and evaluating the potential threats and vulnerabilities that could affect the organization's business continuity.

Recovery strategies: These are the actions and procedures that the organization will implement to restore its normal operations as quickly and effectively as possible after a disruption or disaster.

Recovery objectives: These are the metrics that define the acceptable level of recovery for the organization's business processes and assets. The two main recovery objectives are:

Recovery point objective (RPO): This is the maximum amount of data loss that the organization can tolerate in terms of time. For example, an RPO of one hour means that the organization can afford to lose up to one hour's worth of data after a disruption or disaster.

Recovery time objective (RTO): This is the maximum amount of time that the organization can tolerate to restore its normal operations after a disruption or disaster. For example, an RTO of four hours means that the organization must resume its normal operations within four hours after a disruption or disaster.

Testing and validation: This is the process of verifying and evaluating the effectiveness and efficiency of the BCP and its components. Testing and validation can include various methods, such as:

Tabletop exercises: These are discussion-based sessions where team members meet in an informal setting to review and discuss their roles and responsibilities during a disruption or disaster scenario.A facilitator guides participants through a discussion of one or more scenarios2.

Simulation exercises: These are more realistic and interactive sessions where team members perform their roles and responsibilities during a simulated disruption or disaster scenario.A facilitator controls and monitors the simulation and injects events and challenges3.

Full-scale exercises: These are the most complex and realistic sessions where team members perform their roles and responsibilities during a real-life disruption or disaster scenario.A facilitator coordinates and evaluates the exercise with external stakeholders, such as emergency services, media, or customers4.

As an IS auditor, your greatest concern when reviewing the organization's BCP would be A. The recovery plan does not contain the process and application dependencies.

asked 18/09/2024
Mark Anthony Mondonedo
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first