ExamGecko
Question list
Search
Search

Question 38 - CISM discussion

Report
Export

An organization is planning to outsource the execution of its disaster recovery activities. Which of the following would be MOST important to include in the outsourcing agreement?

A.
Definition of when a disaster should be declared
Answers
A.
Definition of when a disaster should be declared
B.
Requirements for regularly testing backups
Answers
B.
Requirements for regularly testing backups
C.
Recovery time objectives (RTOs)
Answers
C.
Recovery time objectives (RTOs)
D.
The disaster recovery communication plan
Answers
D.
The disaster recovery communication plan
Suggested answer: C

Explanation:

The most important thing to include in the outsourcing agreement for disaster recovery activities is the recovery time objectives (RTOs). RTOs are the maximum acceptable time frames within which the critical business processes and information systems must be restored after a disaster or disruption. RTOs are based on the business impact analysis (BIA) and the risk assessment, and they reflect the business continuity requirements and expectations of the organization. By including the RTOs in the outsourcing agreement, the organization can ensure that the service provider is aware of and committed to meeting the agreed service levels and minimizing the downtime and losses in the event of a disaster.The other options are not as important as the RTOs, although they may be relevant and useful to include in the outsourcing agreement depending on the scope and nature of the disaster recovery services.Reference= CISM Review Manual 15th Edition, page 2471; CISM Review Questions, Answers & Explanations Database - 12 Month Subscription, Question ID: 1033

asked 01/10/2024
Bob Xiong
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first