Certified Information Systems Auditor (CISA) — Question 158
An IS auditor notes that the previous year's disaster recovery test was not completed within the scheduled time frame due to insufficient hardware allocated by a third-party vendor. Which of the following provides the BEST evidence that adequate resources are now allocated to successfully recover the systems?
Answer options
- A. Hardware change management policy
- B. An up-to-date RACI chart
- C. Vendor memo indicating problem correction
- D. Service level agreement (SLA)
Correct answer: D
Explanation
The Service Level Agreement (SLA) establishes clear expectations and commitments regarding resource allocation, ensuring that adequate hardware is provided for disaster recovery. In contrast, the hardware change management policy and RACI chart do not directly address resource adequacy, and a vendor memo may not guarantee that the issues have been resolved or that future allocations will meet the necessary requirements.