Certified Information Security Manager (CISM) — Question 1145
Which of the following is the BEST indication of an effective disaster recovery planning process?
Answer options
- A. Recovery time objectives (RTOs) are shorter than recovery point objectives (RPOs)
- B. Hot sites are required for any declared disaster
- C. Post-incident reviews are conducted after each event
- D. Chain of custody is maintained throughout the disaster recovery process
Correct answer: C
Explanation
The correct answer is C because conducting post-incident reviews helps organizations learn from past events and improve future recovery efforts. Options A and B are not necessarily indicators of effective planning as they can vary based on organizational needs. Option D is important for evidence handling, but it does not directly reflect the overall effectiveness of the disaster recovery planning process.