CISA Certified Information Systems Auditor – Question1719

Which of the following provides the BEST evidence of an organization's disaster recovery readiness?

A.
A disaster recovery plan
B. Customer references for the alternate site provider
C. Processes for maintaining the disaster recovery plan
D. Results of tests and drills

Correct Answer: D

Explanation:

Explanation:
Plans are important, but mere plans do not provide reasonable assurance unless tested. References for the alternate site provider and the existence and maintenance of a disaster recovery plan are important, but only tests and drills demonstrate the adequacy of the plans and provide reasonable assurance of an organization’s disaster recovery readiness.