An organization's business impact analysis shows that a payment processing system has a recovery time objective of two hours and a recovery point objective of fifteen minutes. The current disaster recovery strategy restores the system from nightly tape backups at an alternate site, with an observed restoration time of eight hours and up to twenty-four hours of data loss. Which action should the IS auditor recommend FIRST?
The current strategy cannot meet either objective, so the auditor's first action is to communicate the gap and recommend a solution whose capabilities match the requirements. Technologies such as synchronous or asynchronous replication and continuous data protection can deliver a fifteen-minute recovery point and support a two-hour recovery time. Recommending a capability-aligned strategy addresses the root problem rather than adjusting targets or marginally improving an inadequate method.
Why this answer
The recovery strategy must be capable of meeting the stated objectives. Nightly tape restoration fails both the two-hour recovery time objective and the fifteen-minute recovery point objective, so the auditor should report the shortfall and recommend a design such as replication or continuous data protection that can achieve those targets. Changing the objectives or merely testing more often leaves the business exposure intact.
Exam trap
The trap here is proposing a tactical tweak, such as more frequent backups or more testing, when the architecture itself cannot satisfy the recovery objectives and requires a different recovery technology.