BCP/DRP Planning
What It Is and Why It Matters
Business Continuity Planning (BCP) and Disaster Recovery Planning (DRP) are complementary disciplines that ensure an organization can continue its critical operations during and after a disruptive event. BCP addresses the broader business perspective, focusing on maintaining essential business functions during a disruption. DRP focuses specifically on restoring IT systems and infrastructure after a disaster.
For the CISA exam, BCP/DRP is a high-priority topic because auditors must evaluate whether organizations have adequate plans to maintain operations and recover from disruptions. This includes verifying that plans are documented, tested regularly, maintained current, and aligned with the organization's risk profile and business requirements.
Key standards and guidelines that inform BCP/DRP practices include ISO 22301 (business continuity management systems), NIST SP 800-34 (contingency planning), and various industry-specific regulations that mandate continuity and recovery capabilities.
Key Concepts and Terminology
Business Impact Analysis (BIA)
The Business Impact Analysis is the foundation of all BCP/DRP efforts. It identifies critical business processes, determines the impact of their disruption over time, and establishes recovery priorities and timeframes. The BIA should quantify both financial and operational impacts and identify dependencies between business processes and supporting IT systems.
Recovery Objectives
- Recovery Time Objective (RTO): The maximum acceptable amount of time that a system or process can be down after a disruption before the impact becomes unacceptable. RTO drives decisions about recovery strategies and technologies.
- Recovery Point Objective (RPO): The maximum acceptable amount of data loss, measured in time. RPO determines how frequently data must be backed up. An RPO of four hours means the organization can tolerate losing up to four hours of data.
- Maximum Tolerable Downtime (MTD): The absolute maximum time a business function can be unavailable before the organization's viability is threatened. MTD is always greater than or equal to RTO.
Recovery Strategies
- Hot Site: A fully equipped, operational facility that can take over processing immediately or within hours. Hot sites are the most expensive but provide the fastest recovery.
- Warm Site: A partially equipped facility that has infrastructure in place but requires some configuration and data restoration before it can become operational. Recovery typically takes hours to days.
- Cold Site: A facility with basic infrastructure (power, networking) but no pre-installed systems. Recovery can take days to weeks, making it suitable only for noncritical functions.
- Cloud-Based Recovery: Using cloud services for recovery provides flexibility and scalability. Organizations can provision resources on demand, reducing the need for dedicated physical recovery sites.
- Reciprocal Agreements: Arrangements between two organizations to provide processing capabilities to each other in case of disaster. These are cost-effective but have limitations regarding capacity and compatibility.
BCP/DRP Testing Types
- Checklist Review (Desk Check): Plan holders review the plan for accuracy and completeness. This is the simplest form of testing.
- Tabletop Exercise (Structured Walkthrough): Key personnel walk through the plan's procedures in a conference-room setting, discussing roles and responses to a hypothetical scenario.
- Simulation Test: A realistic scenario is enacted, and participants perform their actual recovery roles without affecting production systems.
- Parallel Test: Recovery systems are activated and process real workloads alongside production systems to verify recovery capability without disrupting normal operations.
- Full Interruption Test: Production processing is actually shifted to the recovery site. This is the most comprehensive test but carries the highest risk, as it intentionally disrupts normal operations.
How This Appears on the CISA Exam
BCP/DRP questions on the CISA exam frequently test:
- The role of the BIA as the starting point for BCP/DRP (the BIA must be completed before recovery strategies can be selected).
- Definitions and relationships between RTO, RPO, and MTD.
- Selecting the appropriate recovery site type based on recovery requirements and budget constraints.
- Ordering testing types from least to most comprehensive (checklist, tabletop, simulation, parallel, full interruption).
- Identifying what should trigger a plan update (organizational changes, new systems, test results revealing gaps).
Study Tips
- Remember that the BIA is the first and most critical step in BCP/DRP development.
- Know the difference between RTO and RPO, and be able to apply these concepts to scenarios.
- Memorize the recovery site types (hot, warm, cold) and their trade-offs in terms of cost, recovery speed, and readiness.
- Understand the progression of testing types from least disruptive (checklist) to most disruptive (full interruption).
- Remember that BCP/DRP plans must be tested regularly and updated whenever significant changes occur in the organization.
Related Subtopics
- Backup and recovery strategies
- Incident management and response
- Crisis communication planning
- IT service continuity management
- Resilience and redundancy architectures
- Regulatory requirements for business continuity
Ready to Test Your Knowledge?
Practice exam questions on BCP/DRP Planning and other IS Operations & Resilience topics.
Start Practicing Free