ExamGecko
Question list
Search
Search

Question 342 - CISM discussion

Report
Export

Which of the following should an information security manager do FIRST when creating an organization's disaster recovery plan (DRP)?

A.
Conduct a business impact analysis (BIA)
Answers
A.
Conduct a business impact analysis (BIA)
B.
Identify the response and recovery learns.
Answers
B.
Identify the response and recovery learns.
C.
Review the communications plan.
Answers
C.
Review the communications plan.
D.
Develop response and recovery strategies.
Answers
D.
Develop response and recovery strategies.
Suggested answer: A

Explanation:

Conducting a business impact analysis (BIA) is the first step when creating an organization's disaster recovery plan (DRP) because it helps to identify and prioritize the critical business functions or processes that need to be restored after a disruption, and determine their recovery time objectives (RTOs) and recovery point objectives (RPOs)2. Identifying the response and recovery teams is not the first step, but rather a subsequent step that involves assigning roles and responsibilities for executing the DRP. Reviewing the communications plan is not the first step, but rather a subsequent step that involves defining the communication channels and protocols for notifying and updating the stakeholders during and after a disruption.Developing response and recovery strategies is not the first step, but rather a subsequent step that involves selecting and implementing the appropriate solutions and procedures for restoring the critical business functions or processes.

Reference:2https://www.isaca.org/resources/isaca-journal/issues/2018/volume-3/business-impact-analysis-bia-and-disaster-recovery-planning-drp

asked 01/10/2024
Pieter Louw
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first