IS Operations & Resilience: Exam Tips
IT Asset Management Tracks the Full Lifecycle
IT asset management covers procurement, deployment, maintenance, and disposal of hardware and software. An accurate asset inventory is foundational for license compliance, vulnerability management, and financial reporting.
Incident Management Follows a Defined Process
Incident management aims to restore normal service operation as quickly as possible. The process includes identification, logging, categorization, prioritization, investigation, resolution, and closure, with escalation procedures for complex or high-impact incidents.
Problem Management Addresses Root Causes
Unlike incident management (which focuses on restoration), problem management identifies and eliminates the underlying root cause to prevent recurrence. Known errors should be documented in a known-error database for faster future resolution.
BCP and DRP Require Regular Testing
Business continuity plans (BCP) address overall organizational resilience, while disaster recovery plans (DRP) focus specifically on IT system recovery. Plans should be tested at least annually using methods ranging from tabletop exercises to full interruption tests.
Know RTO, RPO, and Related Recovery Metrics
Recovery time objective (RTO) defines the maximum acceptable downtime. Recovery point objective (RPO) defines the maximum acceptable data loss measured in time. These metrics drive decisions about backup frequency, replication strategies, and recovery site requirements.
Backup Strategies Must Align With RPO
Full, incremental, and differential backup strategies each have trade-offs in storage, time, and recovery complexity. Backups should be regularly tested through restoration exercises to verify data integrity and recovery procedures.
SLA Monitoring Ensures Service Delivery Commitments
Service level agreements define measurable targets for availability, performance, and support response. The IS auditor should verify that SLAs include penalties for non-compliance, regular reporting mechanisms, and periodic review processes.
Job Scheduling Controls Prevent Processing Errors
Automated job scheduling should include controls for job dependencies, error handling, and restart procedures. The IS auditor should verify that job schedules are authorized, monitored, and that failures trigger appropriate alerts and escalation.
Capacity Planning Prevents Performance Degradation
Capacity planning ensures that IT resources can meet current and projected demand. Monitoring trends in CPU, memory, storage, and network utilization helps predict when upgrades or scaling actions will be needed.
Resilience Requires Redundancy at Multiple Layers
System resilience is achieved through redundancy in hardware (clustering, failover), data (replication, mirroring), network (diverse paths, load balancing), and facilities (alternate processing sites). The level of redundancy should be proportional to the criticality of the system.