712-50 Question 279
Single answerA global manufacturing company is consolidating its business continuity and disaster recovery capabilities after experiencing several regional disruptions. The board has approved aggressive revenue growth targets and has stated that order fulfillment and supplier connectivity must remain available during disruptive events. During a review, the CISO finds that IT recovery plans are organized by technology towers, recovery exercises focus mainly on restoring infrastructure, and business unit leaders have not formally approved recovery priorities. Which action should the CISO take FIRST to ensure continuity and recovery planning are aligned with organizational goals and objectives?
- A
Require each infrastructure team to increase recovery testing frequency and report monthly restoration times to the security office
- B
Conduct or refresh a business impact analysis with executive and business process owners to define critical services, recovery priorities, RTOs, RPOs, and dependencies
- C
Acquire an additional hot site for the ERP environment so that production systems can fail over during any regional outage
- D
Mandate that all applications meet the same enterprise recovery objective to simplify governance and audit reporting
Show answer and explanation
Correct answer: B
Explanation
The core issue in this scenario is not a lack of technical recovery activity, but a lack of business alignment and governance. In mature resilience programs, business continuity planning (BCP), disaster recovery (DR), contingency planning, and business recovery are driven by organizational objectives and validated through a business impact analysis. A BIA identifies critical business functions and services, maximum tolerable downtime, recovery time objectives (RTOs), recovery point objectives (RPOs), process dependencies, third-party requirements, and the financial and operational impact of disruption. This supports executive decision-making and ensures technology recovery strategies are proportionate to business risk.
Best practice sources such as ISO 22301 emphasize understanding the organization and determining business continuity requirements before selecting and implementing continuity strategies. NIST SP 800-34 Rev. 1 also supports identifying mission-essential functions and recovery requirements as a prerequisite to developing effective contingency plans. From a CCISO perspective, the leader's responsibility is to ensure resilience capabilities are risk-based, business-approved, and measurable against enterprise objectives rather than driven solely by IT convenience or infrastructure preferences.
- A. Incorrect.
This is not the best first action. Increasing technical testing frequency may improve operational readiness, but it does not resolve the underlying governance problem: recovery priorities are not formally driven by business needs. Without validated business requirements, infrastructure teams may optimize for the wrong systems or metrics. This option reflects a common mistake of treating business continuity and disaster recovery as purely technical exercises.
- B. Correct.
This is the best answer. A business impact analysis (BIA), validated by executive leadership and business process owners, is the foundational step for aligning business continuity, disaster recovery, and contingency planning with organizational goals. It identifies critical business services, tolerable downtime, data loss tolerance, upstream and downstream dependencies, staffing requirements, third-party dependencies, and recovery priorities. From this, the organization can define risk-based RTOs and RPOs and ensure plans support revenue, customer commitments, and operational resilience objectives.
- C. Incorrect.
This is a plausible but premature action. A hot site may be appropriate for some workloads, but purchasing additional recovery capability before validating business requirements can lead to overspending or protecting the wrong systems. The scenario indicates that current plans are not aligned with business-approved priorities, so the first step should be to establish those priorities through governance and business analysis, not immediately buy infrastructure.
- D. Incorrect.
This is incorrect because it imposes a uniform recovery target across all applications, which is rarely aligned with business reality. Different services have different criticality, tolerable downtime, and acceptable data loss thresholds. Standardizing all systems to the same recovery objective can create unnecessary cost for low-priority systems and insufficient protection for truly critical services. This option represents a common misconception that simplicity in governance should override business risk differentiation.