CRISC - Information Technology and Security (20% of the exam) - Section 4.4

Apply business continuity management and disaster recovery management to sustain and restore critical services.

Apply business continuity management and disaster recovery management to sustain critical services during disruption and restore them within defined targets. Use recovery time objective (RTO) and recovery point objective (RPO) to set and validate the acceptable limits of downtime and data loss for each critical system.

Business continuity managementDisaster recoveryRecovery time objectiveRecovery point objective

Practice question for this objective

Free sampleInformation Technology and Securitymedium

During a disaster recovery review, a risk practitioner finds that the recovery objectives for a trading platform are documented only as a single number of hours. The practitioner needs to confirm how much transaction data the business can afford to lose if the platform fails, so that backup arrangements can be checked against it. Which recovery objective expresses the maximum acceptable amount of data loss?

  • AThe recovery time objective, because it sets the maximum period the trading platform may remain unavailable before the loss to the business becomes unacceptable to senior management.
  • BThe maximum tolerable downtime, because it captures the outer limit of disruption that the business can absorb before the consequences of losing the platform turn severe.
  • CThe service delivery objective, because it states the reduced level of processing the trading platform must sustain while operating in its alternate recovery mode after a disruption.
  • DThe recovery point objective, because it defines the maximum period of data that may be lost, fixing how far back the platform must be recoverable from the moment of disruption. Correct
Distinguish the recovery point objective as the measure of tolerable data loss, separate from objectives that measure outage duration. The recovery point objective expresses how much data the business can afford to lose by fixing the point in time to which systems must be recoverable, whereas the recovery time objective and maximum tolerable downtime both measure outage duration rather than data volume.

Why A is wrong: This is tempting because both objectives are measured in time, but the recovery time objective governs how long restoration may take, not the volume of data that may be lost in a failure.

Why B is wrong: This is plausible because it bounds disruption, but maximum tolerable downtime concerns the duration of an outage rather than the quantity of data that can be lost when the platform fails.

Why C is wrong: This is attractive because it sounds like a recovery target, but the service delivery objective describes a degraded service level during recovery, not the amount of data the business may lose.

Why D is correct: The recovery point objective sets the tolerable data loss by defining the point in time to which data must be restored, so it is the objective the practitioner should check against the backup arrangements.

See more CRISC practice questions, answers explained.

Exam traps in Information Technology and Security

Answers that look right on this material and are not. Each one is a distractor from a different question in the CRISC bank for this domain.

  • A cold site, because the empty conditioned facility avoids the cost of standing equipment while staff install and configure servers once a disaster has been formally declared.

    Why it is wrong: This is tempting because a cold site is the cheapest option, but procuring and configuring equipment after a declaration takes far longer than two hours, so it cannot meet the objective.

  • Retain the nightly full backup but move the offsite tapes to a closer vault so that the media can be retrieved and restored more quickly after a disruption.

    Why it is wrong: This is tempting because faster retrieval helps restoration, but shortening retrieval time addresses recovery duration and still leaves up to a day of data exposed, breaching the objective.

  • It forces the organisation to invest in a hot site even though a warm site would comfortably recover the admissions system inside the agreed six-hour window

    Why it is wrong: Site selection follows from the recovery time objective, but this answer assumes a conclusion about cost rather than addressing the flaw of leaving no buffer below the maximum tolerable downtime.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.