CISM - Incident Management (30% of the exam) - Section 4.4

Develop and maintain a disaster recovery plan (DRP) to restore IT systems and data following a significant incident.

Develop and maintain a disaster recovery plan (DRP) that specifies procedures for restoring IT systems and data following a significant incident, with backup and restore processes designed to meet the recovery time objective. Distinguish the DRP's focus on IT system restoration from the BCP's broader concern with sustaining business operations.

Disaster recoveryDRPRecovery time objectiveBackup and restore

Practice question for this objective

Free sampleIncident Managementmedium

A bank's newly drafted disaster recovery plan documents detailed restoration procedures for its core banking platform. During a review, the information security manager wants to confirm the plan reflects the recovery objectives the business actually agreed, rather than what is technically convenient. Which input should the recovery procedures in the disaster recovery plan be designed to satisfy?

  • AThe vendor's published maximum supported restore throughput for the backup appliance, since the technology's stated capability sets the realistic ceiling for any recovery procedure.
  • BThe recovery time and recovery point objectives agreed for the platform, since these define the maximum tolerable outage and data loss the recovery procedures must be built to achieve. Correct
  • CThe mean time between failures reported for the platform's hardware, since a lower failure rate justifies lighter recovery procedures and reduces the cost of maintaining the plan.
  • DThe preferences expressed by responders during the most recent tabletop exercise, since the people who execute the procedures are best placed to decide the recovery targets they can meet.
Disaster recovery procedures must be designed to satisfy the business-agreed recovery time and recovery point objectives, not the convenience of current tooling or responders. RTO and RPO translate the business's tolerance for outage and data loss into measurable targets. The DRP's restoration procedures exist to meet those objectives, so the procedures are validated against RTO and RPO; where tooling cannot meet them, the shortfall is a gap to remediate, not the design target.

Why A is wrong: Tempting because tooling does constrain what is achievable, but designing the plan around vendor throughput puts the technology's convenience ahead of the business need; if the capability cannot meet the objective, that is a gap to close, not the target.

Why B is correct: Correct. RTO and RPO express the business-agreed limits on outage duration and data loss, so the DRP's restoration procedures must be designed to meet these objectives rather than whatever the current tooling happens to deliver.

Why C is wrong: Tempting because reliability data informs risk, but MTBF describes how often failure occurs, not how quickly recovery must happen; it cannot tell the manager what outage or data loss the business will tolerate.

Why D is wrong: Tempting because responder feedback improves procedures, but letting executors set the recovery targets risks defining objectives around what is comfortable to deliver rather than what the business can tolerate losing.

See more CISM practice questions, answers explained.

Exam traps in Incident Management

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISM bank for this domain.

  • It defines how the organisation maintains essential business functions overall during a disruption, including premises, people, and manual processes when systems are unavailable.

    Why it is wrong: Tempting because it sounds like the whole recovery story, but this describes the broader business continuity plan; the DRP is the narrower technology-recovery component that sits underneath it.

  • On the replacement cost and current book value of each system's hardware and licences, so that the most financially valuable technology assets receive the strongest recovery provisions.

    Why it is wrong: Tempting because expensive assets feel worth protecting, but the cost of the technology does not reflect the business harm of its downtime; a cheap system can be far more critical to operations than an expensive one.

  • Distribute the completed plan to all recovery team members and ask them to confirm by email that they have read it.

    Why it is wrong: Acknowledging that a plan has been read is useful for awareness, but reading does not reveal whether the documented steps and dependencies actually function under disaster conditions.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.