712-50 Question 282
Single answerDesign documentation process as part of the continuity of operations programA newly appointed CISO is formalizing the design documentation process for the organization's continuity of operations program (COOP). During a recent regional outage, business unit leaders used different versions of recovery procedures, recovery priorities were inconsistent with business impact analysis results, and several critical vendor contacts were outdated. The CISO wants to reduce this risk by establishing a documentation process that supports governance, accuracy, and execution during a disruption. Which action should the CISO prioritize FIRST when designing the documentation process?
- A
Create a centralized, version-controlled COOP documentation repository with defined ownership, review intervals, approval workflow, and distribution of controlled copies for critical teams
- B
Require each business unit to maintain its own continuity procedures independently so local managers can update documents without waiting for enterprise approval
- C
Focus initial documentation efforts on collecting all technical recovery runbooks, since infrastructure restoration is the primary dependency for all business services
- D
Publish a single annual COOP manual after executive approval and restrict interim updates to avoid confusion caused by frequent document changes
Show answer and explanation
Correct answer: A
Explanation
The best first step is to design a controlled documentation governance process before expanding or rewriting individual continuity artifacts. In this scenario, the root problem is not merely missing content; it is the absence of document lifecycle management. Effective continuity of operations documentation should be centralized enough to ensure version control, ownership, review cadence, approval, and availability, while still allowing business units and technical teams to maintain their respective content under a common standard. Best practices in continuity planning and operational resilience emphasize that plans must be current, aligned with BIA-driven priorities, synchronized with disaster recovery and crisis management documentation, and regularly reviewed after organizational or technology changes, tests, and incidents. A robust documentation process typically includes document taxonomy, ownership assignment, update triggers, retention rules, secure but accessible storage, and mechanisms for distributing current approved copies to personnel who need them during a disruption.
- A. Correct.
This is correct because the scenario highlights core documentation governance failures: multiple versions, inconsistent priorities, and outdated contact data. A centralized, version-controlled repository with document owners, scheduled reviews, approval workflows, and controlled distribution directly addresses document integrity, accountability, and accessibility. In a mature continuity program, documentation must be governed as a living set of records aligned to the business impact analysis (BIA), recovery strategies, and plan maintenance processes. This approach also supports auditability and ensures responders can rely on the current approved procedures during an incident.
- B. Incorrect.
This is incorrect because decentralized maintenance without enterprise control is likely to worsen the exact problems described in the scenario. While business units should contribute content and maintain subject-matter accuracy, independent document management often leads to version sprawl, inconsistent recovery assumptions, and weak alignment to enterprise priorities. Someone might choose this option because local ownership can improve responsiveness, but without centralized governance and common standards, the organization increases operational and compliance risk.
- C. Incorrect.
This is incorrect because technical runbooks are only one component of continuity documentation. The scenario involves broader continuity failures, including recovery priorities and vendor contacts, which require integrated business, operational, and third-party documentation. A COOP documentation process should cover governance, activation criteria, roles, communications, dependencies, alternate work arrangements, external contacts, and restoration sequencing, not just IT recovery steps. This option reflects a common misconception that continuity documentation is mainly an IT disaster recovery exercise.
- D. Incorrect.
This is incorrect because annual publication alone is insufficient for continuity documentation, especially for volatile information such as contact lists, escalation paths, vendor dependencies, and system recovery requirements. Restricting interim updates in the name of stability creates a high risk that teams will rely on obsolete information during a disruption. Someone might choose this because document control is important, but good document control does not mean infrequent updates; it means controlled, traceable, and timely updates.