nerdexam
EC-Council

712-50 · Question #38

A global retail organization is looking to implement a consistent Disaster Recovery and Business Continuity Process across all of its business units. Which of the following standards and guidelines…

The correct answer is A. International Organization for Standardizations ?22301 (ISO-22301). ISO-22301 is the internationally recognized standard specifically designed for Business Continuity Management Systems (BCMS). It provides a framework for planning, establishing, implementing, operating, monitoring, and continually improving a documented management system to…

Governance (Policy, Legal & Compliance)

Question

A global retail organization is looking to implement a consistent Disaster Recovery and Business Continuity Process across all of its business units. Which of the following standards and guidelines can BEST address this organization's need?

Options

  • AInternational Organization for Standardizations ?22301 (ISO-22301)
  • BInformation Technology Infrastructure Library (ITIL)
  • CPayment Card Industry Data Security Standards (PCI-DSS)
  • DInternational Organization for Standardizations ?27005 (ISO-27005)

How the community answered

(32 responses)
  • A
    72% (23)
  • B
    16% (5)
  • C
    6% (2)
  • D
    6% (2)

Explanation

ISO-22301 is the internationally recognized standard specifically designed for Business Continuity Management Systems (BCMS). It provides a framework for planning, establishing, implementing, operating, monitoring, and continually improving a documented management system to protect against, reduce the likelihood of, and ensure recovery from disruptive incidents - making it a perfect fit for a global organization needing consistent DR/BCP across all business units.

Why the distractors are wrong:

  • B (ITIL): ITIL is an IT service management framework focused on aligning IT services with business needs. While it touches on continuity in its "Service Design" module, it is not a dedicated BCP/DR standard.
  • C (PCI-DSS): PCI-DSS is a security compliance standard specifically for organizations that handle payment card data. It addresses data security, not broad business continuity.
  • D (ISO-27005): ISO-27005 focuses on information security risk management, not business continuity or disaster recovery planning.

Memory tip: Think of ISO-22301 as the "22 = continuity" standard - the number 22 can remind you of "to keep the business going to-22301." Alternatively, associate "BC" (Business Continuity) with the letters near the number: Business Continuity = 22301. Any time a question mentions organization-wide BCP or DR framework, ISO-22301 is almost always the answer.

Topics

#Business Continuity#Disaster Recovery#ISO-22301#Organizational Standards

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice