712-50 Question 278
Single answerA global manufacturing company is modernizing its resilience program after a ransomware incident disrupted ERP, procurement, and plant scheduling systems for two days. The board has directed the CISO to ensure business continuity, disaster recovery, and contingency plans are aligned to enterprise objectives: maintain contractual delivery commitments, protect worker safety, and limit financial impact from downtime. During review, the CISO finds that IT has documented recovery procedures for major systems, but business units have not defined manual workarounds, recovery priorities differ across regions, and plan testing has focused only on data center failover. Which action should the CISO take FIRST to best align continuity and recovery planning with organizational goals?
- A
Initiate an enterprise business impact analysis (BIA) with business leaders to validate critical processes, dependencies, recovery time objectives (RTOs), recovery point objectives (RPOs), and acceptable workarounds before updating BC/DR plans
- B
Expand technical disaster recovery testing to include additional infrastructure components and increase backup frequency for all production systems
- C
Procure a secondary hot site for all critical applications to reduce recovery time regardless of current business process requirements
- D
Require each regional IT team to independently update its disaster recovery runbooks based on the lessons learned from the ransomware incident
Show answer and explanation
Correct answer: A
Explanation
The best first action is to conduct or refresh an enterprise BIA with business stakeholders and use it to drive continuity, recovery, and contingency planning. In mature resilience programs, business continuity planning starts with understanding critical business services, dependencies, maximum tolerable downtime, RTOs, RPOs, legal and contractual obligations, and alternative operating procedures. Only after these are defined should the organization finalize recovery strategies, technology investments, and testing scenarios. This approach aligns with widely accepted practices in ISO 22301 for business continuity management, NIST SP 800-34 for contingency planning, and general disaster recovery governance principles. In this scenario, the presence of technical recovery procedures alone is insufficient because the organization lacks validated business priorities, process-level contingencies, and enterprise consistency. A CISO should ensure resilience capabilities are business-led, risk-informed, and measurable against organizational objectives.
- A. Correct.
Correct. The core issue is misalignment between technical recovery activities and business objectives. A BIA is the foundational step for determining which business processes are most critical, the impact of disruption, interdependencies, and the recovery requirements that should drive continuity, contingency, and disaster recovery planning. By engaging business leadership, the CISO can ensure plans support contractual delivery, safety, and financial priorities rather than relying on IT assumptions. This also addresses the identified gaps in manual workarounds and inconsistent regional priorities.
- B. Incorrect.
Incorrect. Broader DR testing and stronger backup practices may improve technical resilience, but they do not resolve the more fundamental problem: the organization has not established business-driven priorities and acceptable process-level recovery strategies. Without validated RTOs, RPOs, and process dependencies, technical testing could optimize the wrong systems or recovery order.
- C. Incorrect.
Incorrect. A hot site may be appropriate for some workloads, but procuring one for all critical applications before understanding business process requirements is premature and potentially wasteful. CCISO-level leadership requires aligning resilience investment to risk appetite, business impact, and strategic objectives rather than defaulting to the most expensive recovery option.
- D. Incorrect.
Incorrect. Updating regional IT runbooks can improve local technical readiness, but independent updates risk increasing inconsistency across the enterprise. The scenario indicates that business priorities already differ across regions and that business units have not defined workarounds. The first step should be enterprise-level governance and impact analysis, not decentralized technical revision.