Back to Questions
CISA
QUESTION #6827
Question 1
In evaluating an organization's business continuity plan, an auditor finds that Recovery Time Objective (RTO) is 4 hours but current recovery capabilities require 12 hours. What should be the auditor's PRIMARY recommendation?
Correct Answer Explanation
When a gap exists between required and actual recovery capabilities, the organization faces unmitigated risk. The auditor should highlight this gap and recommend analysis of whether to: improve capabilities to meet the 4-hour RTO, accept the risk of longer recovery, or adjust business requirements. Simply updating documentation without addressing the gap provides no risk reduction.
Sign in to join the conversation and share your thoughts.
Log In to Comment