CISA - Information Systems Operations and Business Resilience - Section 4.2

Assess data backup, storage and restoration, business continuity plans and disaster recovery plans.

Describe data backup strategies - including full, incremental and offsite storage - and the controls that verify restoration integrity. Assess business continuity plans and disaster recovery plans to confirm they are tested, current and capable of meeting the organisation's RTO and RPO commitments.

data backupstorage and restorationbusiness continuity plandisaster recovery plan

Practice question for this objective

Free sampleInformation Systems Operations and Business Resiliencemedium

Which statement BEST describes the difference between a business continuity plan and a disaster recovery plan?

  • AThe business continuity plan addresses sustaining critical business functions during and after disruption, while the disaster recovery plan addresses restoring information technology services that support those functions. Correct
  • BThe business continuity plan focuses on restoring information technology infrastructure, while the disaster recovery plan focuses on sustaining critical business functions through manual workarounds.
  • CThe business continuity plan is invoked only for cyber incidents, while the disaster recovery plan is invoked only for physical incidents such as fire or flood.
  • DThe business continuity plan is owned by the chief information officer, while the disaster recovery plan is owned by the chief risk officer, with no shared scope between them.
Differentiate the business continuity plan from the disaster recovery plan by the scope of what each protects and restores. BCP keeps critical processes operational using a mix of people, premises, technology and third parties, and may rely on manual workarounds while systems are unavailable. DRP is the technology subset that restores applications, data and infrastructure to support those processes. The DRP is therefore one input to a complete BCP, not a substitute for it.

Why A is correct: This is the correct relationship: BCP is process-centred and broader, DRP is technology-centred and is invoked as a subset of BCP for IT recovery.

Why B is wrong: This swaps the focus of the two plans, which is the most common candidate confusion between BCP and DRP.

Why C is wrong: Trigger type does not determine which plan applies; both plans address a range of disruption causes and can be invoked together.

Why D is wrong: Ownership is inverted in many organisations and not a defining distinction; the substantive distinction is the scope of what each plan protects.

See more CISA practice questions, answers explained.

More in this domain

Back to all Information Systems Operations and Business Resilience objectives, or the CISA cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.