712-50 Question 286
Single answerUnderstand the importance of integration of IA requirements into the Continuity of Operations Plan (COOP)A global financial services company is updating its Continuity of Operations Plan (COOP) after a ransomware incident revealed that critical trading and payment operations could be restored at an alternate site, but key security controls were missing during failover. At the recovery site, administrators used shared emergency accounts, audit logs were not centrally collected, and replicated customer data was accessible without the normal encryption key management process. The CEO asks the CISO to ensure that future continuity planning preserves essential information assurance (IA) requirements without delaying recovery beyond business-approved recovery time objectives (RTOs). Which action should the CISO prioritize?
- A
Integrate security baseline requirements for alternate processing, including identity and access control, logging, encryption/key management, and incident escalation, directly into COOP recovery procedures and exercises
- B
Reduce security controls at the alternate site during emergencies and document that compensating controls will be implemented after business operations are restored
- C
Move responsibility for continuity security decisions entirely to IT operations, since COOP execution is primarily an availability function
- D
Focus the COOP only on restoring the most critical applications quickly, and address confidentiality and integrity requirements in a separate long-term security improvement plan
Show answer and explanation
Correct answer: A
Explanation
The core lesson is that COOP is not just an availability exercise; it must incorporate information assurance requirements so that essential operations continue securely during disruption. In practice, this means defining and testing minimum security baselines for alternate sites and emergency operating modes, including access control, privileged access management, audit logging, encryption, key management, monitoring, and incident response escalation. For a CISO, the priority is to ensure these requirements are integrated into business continuity and disaster recovery processes rather than treated as separate security tasks.
This aligns with widely recognized guidance such as NIST SP 800-34 (Contingency Planning Guide for Federal Information Systems), which emphasizes coordinating recovery procedures with security controls, and NIST SP 800-53 contingency planning and system/information integrity control families. ISO 22301 also supports embedding information security and operational requirements into business continuity arrangements. In regulated sectors like financial services, failing over to an insecure recovery environment can create legal, regulatory, fraud, and reputational consequences even if RTOs are met. Therefore, the most effective CISO action is to integrate IA requirements directly into COOP design, recovery runbooks, and testing.
- A. Correct.
Correct. The scenario shows that availability was restored, but core IA requirements, confidentiality, integrity, authentication, accountability, and controlled key management, were not preserved. The best response is to embed these security requirements into COOP procedures for failover, alternate processing, and reconstitution, and to validate them through testing. This approach aligns continuity objectives with security requirements so recovery does not create unacceptable risk or compliance exposure.
- B. Incorrect.
Incorrect. This is a common but flawed emergency-response mindset. While temporary compensating controls may occasionally be necessary, deliberately planning to lower critical security controls during continuity operations creates material risk, especially in a regulated financial environment. COOP should define minimum acceptable security controls during disruption, not defer them until after restoration.
- C. Incorrect.
Incorrect. COOP execution involves operations, but information assurance requirements remain a governance and risk responsibility that must be coordinated by security leadership. Delegating all continuity security decisions to IT operations can lead to recovery choices that meet uptime goals but violate regulatory, audit, or risk management requirements.
- D. Incorrect.
Incorrect. This option reflects the misconception that continuity is only about availability. Effective COOP planning must preserve confidentiality, integrity, and accountability as well as availability. Separating these concerns into a later project would repeat the failure described in the scenario and leave the organization exposed during the period when systems are running in contingency mode.