CISA - Information Systems Operations and Business Resilience (26% of the exam) - Section 4.2

Assess data backup, storage and restoration, business continuity plans and disaster recovery plans.

Describe data backup strategies - including full, incremental and offsite storage - and the controls that verify restoration integrity. Assess business continuity plans and disaster recovery plans to confirm they are tested, current and capable of meeting the organisation's RTO and RPO commitments.

data backupstorage and restorationbusiness continuity plandisaster recovery plan

Practice question for this objective

Free sampleInformation Systems Operations and Business Resiliencemedium

Which statement BEST describes the difference between a business continuity plan and a disaster recovery plan?

  • AThe business continuity plan addresses sustaining critical business functions during and after disruption, while the disaster recovery plan addresses restoring information technology services that support those functions. Correct
  • BThe business continuity plan focuses on restoring information technology infrastructure, while the disaster recovery plan focuses on sustaining critical business functions through manual workarounds.
  • CThe business continuity plan is invoked only for cyber incidents, while the disaster recovery plan is invoked only for physical incidents such as fire or flood.
  • DThe business continuity plan is owned by the chief information officer, while the disaster recovery plan is owned by the chief risk officer, with no shared scope between them.
Differentiate the business continuity plan from the disaster recovery plan by the scope of what each protects and restores. BCP keeps critical processes operational using a mix of people, premises, technology and third parties, and may rely on manual workarounds while systems are unavailable. DRP is the technology subset that restores applications, data and infrastructure to support those processes. The DRP is therefore one input to a complete BCP, not a substitute for it.

Why A is correct: This is the correct relationship: BCP is process-centred and broader, DRP is technology-centred and is invoked as a subset of BCP for IT recovery.

Why B is wrong: This swaps the focus of the two plans, which is the most common candidate confusion between BCP and DRP.

Why C is wrong: Trigger type does not determine which plan applies; both plans address a range of disruption causes and can be invoked together.

Why D is wrong: Ownership is inverted in many organisations and not a defining distinction; the substantive distinction is the scope of what each plan protects.

See more CISA practice questions, answers explained.

Exam traps in Information Systems Operations and Business Resilience

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISA bank for this domain.

  • A cold site, which provides environmental infrastructure such as power and cooling but no pre-installed hardware or current data, and is the most economical recovery option.

    Why it is wrong: Cold sites lack hardware and current data, so they cannot meet a minutes-scale recovery; this option correctly defines the wrong site type.

  • The tabletop walkthrough is acceptable evidence of plan exercise because the team identified a meaningful gap in scope, demonstrating that the exercise programme is functioning as intended.

    Why it is wrong: Identifying a missing component is useful, but a walkthrough alone does not prove the technical recovery would succeed. Acceptability of the testing depth is the question, and a tabletop cannot answer it for a critical dependency.

  • Recommend that management formally accept the residual risk in writing, because the vendor's track record of uptime over the past two years materially reduces the probability of breaching the tier-one objectives.

    Why it is wrong: Past availability does not change a contractual RPO of 24 hours when the business needs 15 minutes; accepting the gap on track record alone is not informed risk acceptance and provides no remediation pathway.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.