Skip to content

CMA Final · Cost and Management Audit · Information Systems Security Audit

An auditor reviewing a company's disaster recovery plan finds that backups are taken daily but have never been restored in a test. Which conclusion is most appropriate?

The auditor should conclude that the plan has a weakness, because backups that have never been test-restored give no assurance of recoverability. Regular restoration testing confirms that data is usable and that recovery times are acceptable, so frequency of backup alone is insufficient evidence.

  1. AThe plan is adequate because daily backups prove recoverability
  2. BThe plan has a weakness because the ability to recover from backups has not been validatedCorrect
  3. CThe plan is deficient only because backups should be taken hourly
  4. DThe plan is outside the scope of an information systems audit

Explanation

Taking backups does not prove they can be restored; recovery testing is needed to confirm usability and recovery time. Backup frequency is a separate matter that depends on the acceptable data loss, and disaster recovery is clearly within IS audit scope.

Did you get it right without looking?

One question tells you little. A timed set on Information Systems Security Audit shows your real accuracy, how long you take and where you lose marks.

More Information Systems Security Audit questions