← CISA: audit IT, controls, and resilience
06 / 8 · 30 MIN

Resilience and recovery evidence

Assess objectives, dependencies, and tests against the event the service must withstand.

Concept and mechanism

Resilience requires understanding impact and dependencies. The BIA helps ground recovery priorities and needs. Copying another system’s RTO does not prove business suitability even with similar technology. Two servers may protect against an individual failure while sharing a site failure domain. Shutting down one VM does not demonstrate recovery after losing everything at the site. Identify the location of data, copies, identity, network, keys, and required people. Each relevant dependency needs to enter the design and assessment scenario or be clearly identified as a limitation.

Guided application

Created backup and usable restoration are different evidence. A controlled exercise should demonstrate service and data against agreed criteria without requiring production replacement for every test. Distinguish RTO, time to accepted recovery, from RPO, the required data recovery point. Stopping at 10:00, validation at 10:40, and data through 09:52 meet a 45-minute RTO, but the eight-minute gap exceeds a five-minute RPO. Also examine administrative access to copies: one identity able to destroy production and every recovery option is a common dependency. Audit reports the scenario and exposure without claiming destruction has occurred.

IN PRACTICE

Login works but partner connectivity is missing: the application exercise may pass while process recovery remains unproven.

Common pitfalls

VM count as independence; green backup as recoverability; partial scope as complete process.

Related topics: Identity, data, and protection boundaries · Detection, testing, and incident evidence

Take this idea with you

Test and report the event and outcome that actually matter to the service.

Create account

Reference: Contingency Planning Guide · CISA outline effective August 1, 2024