712-50 Question 280
Single answerDirect contingency planning, operations, and programs to manage riskA global manufacturer has expanded through acquisition and now operates multiple ERP, warehouse, and customer support platforms across three regions. During a recent ransomware incident at a newly acquired subsidiary, executives discovered that recovery priorities differed by region, backup restoration steps were inconsistent, and several critical third-party dependencies were missing from the recovery documentation. The board has asked the CISO to direct a contingency planning program that reduces enterprise risk and improves resilience without unnecessarily delaying business operations. Which action should the CISO take FIRST?
- A
Standardize on a single backup technology across all regions and require each IT team to migrate within the current quarter
- B
Conduct an enterprise business impact analysis (BIA) to define critical processes, recovery time objectives, recovery point objectives, and interdependencies, then align contingency plans to those priorities
- C
Purchase cyber insurance with higher ransomware coverage limits before making changes to existing recovery processes
- D
Schedule annual tabletop exercises for regional IT managers using the current recovery procedures to identify documentation gaps
Show answer and explanation
Correct answer: B
Explanation
The scenario points to a classic contingency planning governance problem: the organization lacks a unified, business-driven basis for recovery. In a mature resilience program, the CISO should first ensure that contingency planning is anchored in a business impact analysis. Industry guidance such as NIST SP 800-34 Rev. 1 emphasizes the BIA as a key step in contingency planning because it identifies critical functions, recovery priorities, resource requirements, and recovery objectives. This also aligns with broader business continuity practices reflected in ISO 22301, where understanding organizational context, business processes, dependencies, and impact criteria is essential before selecting and testing continuity strategies. After the BIA, the CISO can direct strategy decisions such as backup architecture, third-party recovery obligations, runbook standardization, and exercise planning. In short, effective risk-based contingency planning starts with understanding business impact and dependency-driven recovery requirements, not with tools, insurance, or testing alone.
- A. Incorrect.
This is not the best first action. Standardizing backup technology may eventually improve operational consistency, but it addresses a technical control before establishing business-driven recovery priorities. In contingency planning, the CISO should first determine what is most critical to recover, in what order, and within what tolerances. Forcing rapid technology migration without a validated BIA could disrupt operations, overlook regional requirements, and misallocate resources.
- B. Correct.
This is the best answer. A business impact analysis is the foundational step for an enterprise contingency planning program because it identifies critical business services, acceptable downtime, data loss tolerances, upstream and downstream dependencies, and supporting third parties. Once recovery time objectives (RTOs), recovery point objectives (RPOs), and process criticality are defined and approved, the CISO can direct consistent business continuity, disaster recovery, and incident recovery plans that are aligned to enterprise risk and business priorities.
- C. Incorrect.
This is incorrect because cyber insurance is a financial risk transfer mechanism, not a substitute for operational resilience. Higher coverage limits may help offset some losses, but they do not resolve the immediate governance and planning weaknesses revealed by the incident, such as inconsistent recovery priorities and undocumented dependencies. A CISO focused on contingency planning should first strengthen the organization's capability to continue and recover operations.
- D. Incorrect.
This is a useful activity, but not the first one. Tabletop exercises help validate plans and expose gaps, yet exercising weak or misaligned plans before defining enterprise recovery priorities can produce limited value. The organization first needs a common risk-based framework for prioritization and dependency mapping; then exercises can effectively test whether those plans are practical and complete.