DRI Continuous Improvement & Auditing 3 β Questions and Answers
Question 1: Under ISO 22301, what is the term for systematic activities to determine whether BC activities comply with planned arrangements?
- Management review
- Internal audit (Correct answer)
- Risk assessment
- Business impact analysis
Correct answer: Internal audit
ISO 22301 defines internal audit as the systematic process of determining whether BC activities and results comply with planned arrangements.
Question 2: A BC program scorecard shows RTO compliance at 62% during the last tabletop exercise. The most appropriate immediate response is to:
- Accept the result as a baseline and move on
- Analyze which processes failed to meet RTOs and develop targeted improvement plans (Correct answer)
- Increase staffing across all recovery teams
- Shorten all published RTOs to match actual performance
Correct answer: Analyze which processes failed to meet RTOs and develop targeted improvement plans
Analyzing specific failures and developing targeted improvement plans addresses root causes rather than masking the problem.
Question 3: Which of the following best describes a 'gap analysis' in BC program improvement?
- A financial analysis of BC program costs vs. budget
- A comparison of current program state against a desired target or standard (Correct answer)
- An inventory of gaps in physical security at recovery sites
- A review of staff absences during exercises
Correct answer: A comparison of current program state against a desired target or standard
A gap analysis compares the current program state to a desired standard or target state to identify areas requiring improvement.
Question 4: How often should a BC program undergo a comprehensive audit at minimum, according to good practice guidelines such as those from DRI International?
- Every five years
- Annually (Correct answer)
- Only after a major incident
- Every six months
Correct answer: Annually
Good practice and most standards recommend that a comprehensive BC program audit be conducted at least annually.
Question 5: When conducting a BC audit, an auditor uses a 'walk-through' technique. This means the auditor is:
- Physically walking through the facility to check infrastructure
- Following a transaction or scenario through the BC process step by step to test it (Correct answer)
- Reviewing all written plans without engaging staff
- Observing a live DR failover test
Correct answer: Following a transaction or scenario through the BC process step by step to test it
A walk-through involves tracing a scenario or process through each step to evaluate whether the procedure works as documented.
Question 6: Which principle ensures that the person who identifies a corrective action is not solely responsible for verifying its closure?
- Segregation of duties (Correct answer)
- Single point of accountability
- Peer review policy
- Management by exception
Correct answer: Segregation of duties
Segregation of duties ensures that the identification and verification of corrective actions are performed by different individuals to maintain objectivity.
Question 7: A BC program's continuous improvement plan includes a KPI for 'percentage of critical processes with tested and validated recovery procedures.' This KPI primarily measures:
- Financial investment in BC activities
- Program coverage and testing completeness (Correct answer)
- Staff proficiency in executing recovery tasks
- IT system uptime during recovery operations
Correct answer: Program coverage and testing completeness
This KPI directly measures how comprehensively the organization has tested and validated recovery procedures for its critical processes.
Under ISO 22301, what is the term for systematic activities to determine whether BC activities comply with planned arrangements?