In this video, we walk through 5 ISC practice questions on business resiliency, disaster recovery, and BCP. These questions are from ISC content area 1 on the AICPA CPA exam blueprints: Information Systems and Data Management.
The best way to use this video is to pause each time we get to a new question in the video, and then make your own attempt at the question before watching us go through it.
Business Resiliency, Disaster Recovery, and BCP
Business resiliency, disaster recovery, and business continuity are three related ideas that often get treated as one. They’re not the same. Resiliency is a company-wide capability, business continuity is a plan for keeping the business running, and disaster recovery is a narrower plan for restoring technology. Understanding how they fit together makes each one easier to recognize.
Business Resiliency
Business resiliency is an organization’s overall ability to keep operating during and after a disruptive event. It isn’t a document you can pull off a shelf. It’s a holistic approach covering every facet of the business: people, processes, technology, facilities, and outside partners.
Resiliency is built through three types of measures. Proactive measures are the steps taken before anything goes wrong, such as regular data backups, multi-factor authentication, and infrastructure redundancies. Reactive measures are the strategies in place to respond quickly once a disruption occurs. Adaptive measures come afterward, when the organization reviews what happened and evolves based on what it learned.
A manufacturer that requires multi-factor authentication for remote access, has a response team ready to shift production to a second plant, and revises its supplier contracts after a storm is demonstrating all three.
Disaster Recovery
A disaster recovery plan is much narrower. It covers only the IT systems that support critical business functions, through policies and procedures for restoring hardware, applications, and data. Its purpose is to return the IT infrastructure to normal operating status after a disaster.
Key considerations include backing up data regularly in multiple locations, including off-site or cloud storage, so a single event can’t destroy both the original and the copy. System redundancy means duplicating systems so one can take over if the other fails. And the plan has to be tested periodically, since a backup that won’t restore or a recovery process that takes three days leaves the company exposed no matter how good the plan looks on paper.
RTO and RPO
Two objectives drive most disaster recovery decisions, and they’re easy to confuse.
The recovery time objective is the targeted duration within which a business process must be restored after a disaster. It looks forward from the failure and measures how long the company can be without the system.
The recovery point objective is the maximum acceptable amount of data loss, expressed in time. It looks backward from the failure to the last good copy of the data, which means it determines how often backups need to run. A company that can only afford to lose four hours of transactions needs backups at least every four hours.
The short version: RPO is how much data is lost, RTO is how long the system is down.
Business Continuity
A business continuity plan is broader than disaster recovery. It addresses the continued performance of critical business functions during and after a disruption, covering both IT and non-IT aspects. Its purpose is to prevent interruptions to mission-critical services and re-establish full functionality as swiftly and smoothly as possible.
Disaster recovery sits inside this broader effort. A company that restores its servers but has no plan for employee safety, customer communication, or alternate suppliers has handled the technology and left the rest of the business without a roadmap.
Building the Plan
Creating a business continuity plan starts with a business impact analysis. The BIA identifies the critical business functions that must keep running, measures what a disruption would cost each one and how that cost grows over time, and points to recovery strategies. The results determine what the plan prioritizes, since a function that loses money quickly needs faster recovery and more resources than one that can wait a week.
From there, the plan addresses prioritizing those critical functions, communicating with internal stakeholders and external partners, handling supply chain and partner disruptions, protecting employee safety during emergencies, and testing and updating the plan as business conditions change.










