DRI Regulations, Standards, and Compliance 3 — Questions and Answers
Question 1: Which element is NOT a required component of an ISO 22301 BCMS policy statement?
- Commitment to satisfy applicable requirements
- Commitment to continual improvement of the BCMS
- Specific RTO and RPO targets for critical processes (Correct answer)
- Commitment to protecting the organization against disruptions
Correct answer: Specific RTO and RPO targets for critical processes
ISO 22301 requires the BC policy to include commitments to requirements, continual improvement, and protection against disruptions, but specific RTO/RPO values belong in BIA and strategy documents, not the high-level policy.
Question 2: The Payment Card Industry Data Security Standard (PCI DSS) Requirement 12.10 specifically addresses:
- Encryption of cardholder data at rest
- Incident response plan implementation and testing (Correct answer)
- Physical security of data center environments
- Vendor and third-party service provider management
Correct answer: Incident response plan implementation and testing
PCI DSS Requirement 12.10 requires entities to implement an incident response plan and test it at least annually, ensuring readiness to respond to security events affecting cardholder data.
Question 3: A BC manager discovers that a critical vendor's SLA does not align with the organization's RTO. Under ISO 22301, the MOST appropriate first action is:
- Terminate the vendor contract immediately
- Document the gap in the risk register and assess impact through the BIA (Correct answer)
- Notify regulators of the compliance gap
- Implement a manual workaround without further analysis
Correct answer: Document the gap in the risk register and assess impact through the BIA
ISO 22301 requires organizations to evaluate and address risks from interested parties (including suppliers); documenting the gap and assessing its impact through the BIA ensures a risk-based, evidence-based response.
Question 4: The Basel III framework influences BC/DR planning for banks primarily through its requirements for:
- Consumer data privacy protections
- Operational risk capital adequacy and resilience standards (Correct answer)
- Anti-money laundering transaction monitoring
- Cross-border data transfer restrictions
Correct answer: Operational risk capital adequacy and resilience standards
Basel III's Pillar 2 operational risk framework requires banks to hold adequate capital against operational risks, including those arising from disruptions, and to demonstrate robust operational resilience.
Question 5: NIST SP 800-34 Rev. 1 defines the Continuity of Operations Plan (COOP) as distinct from a Disaster Recovery Plan primarily because:
- COOP focuses on IT system recovery while DRP focuses on business functions
- COOP addresses continuity of essential government functions, while DRP focuses on IT system recovery (Correct answer)
- COOP is voluntary while DRP compliance is mandatory
- COOP is tested annually while DRP is tested monthly
Correct answer: COOP addresses continuity of essential government functions, while DRP focuses on IT system recovery
NIST SP 800-34 defines COOP as planning for continuity of an organization's essential functions during and after emergencies, whereas the DRP focuses specifically on recovering IT systems and infrastructure.
Question 6: Which U.S. federal law requires continuity planning for critical infrastructure sectors and designates sector-specific agencies to coordinate resilience efforts?
- The Stafford Act
- Presidential Policy Directive 21 (PPD-21) (Correct answer)
- The Computer Fraud and Abuse Act
- The Federal Information Security Modernization Act (FISMA)
Correct answer: Presidential Policy Directive 21 (PPD-21)
PPD-21 establishes national policy on critical infrastructure security and resilience, designates 16 critical infrastructure sectors, and assigns sector-specific agencies responsible for coordinating protective efforts.
Question 7: When an organization certified to ISO 22301 undergoes a surveillance audit, the auditor finds that the organization has not tested its BC plan in 18 months. This would typically result in:
- Immediate revocation of certification
- A major nonconformity finding requiring corrective action (Correct answer)
- A minor observation with no follow-up required
- A certificate suspension pending root cause analysis
Correct answer: A major nonconformity finding requiring corrective action
Failure to exercise and test BC plans as required by ISO 22301 Clause 8.5 is a major nonconformity because it directly violates a mandatory shall requirement, triggering a corrective action process.
Which element is NOT a required component of an ISO 22301 BCMS policy statement?