nerdexam
(ISC)2

CISSP · Question #1338

Which of the following events prompts a review of the disaster recovery plan (DRP)?

The correct answer is D. Organizational merger. A Disaster Recovery Plan must be reviewed whenever significant organizational or infrastructure changes occur that could affect recovery objectives, responsibilities, or critical systems.

Submitted by certguy· Mar 5, 2026Security Operations

Question

Which of the following events prompts a review of the disaster recovery plan (DRP)?

Options

  • ANew members added to the steering committee
  • BCompletion of the security policy review
  • CChange in senior management
  • DOrganizational merger

How the community answered

(45 responses)
  • A
    2% (1)
  • B
    4% (2)
  • C
    9% (4)
  • D
    84% (38)

Why each option

A Disaster Recovery Plan must be reviewed whenever significant organizational or infrastructure changes occur that could affect recovery objectives, responsibilities, or critical systems.

ANew members added to the steering committee

Adding members to a steering committee is an administrative governance change that does not alter the organization's critical systems, infrastructure, or recovery requirements that a DRP addresses.

BCompletion of the security policy review

Completion of a security policy review is a policy lifecycle event that updates security controls and standards but does not inherently change the systems, facilities, or processes that the DRP is designed to recover.

CChange in senior management

A change in senior management affects organizational leadership and decision-making authority but does not by itself alter the technical infrastructure, critical business functions, or recovery requirements documented in the DRP.

DOrganizational mergerCorrect

An organizational merger introduces new systems, personnel, facilities, infrastructure dependencies, and business processes that directly impact recovery time objectives (RTOs), recovery point objectives (RPOs), and overall DRP scope. The merged entity may have entirely different critical assets and recovery requirements that render the existing DRP incomplete or invalid. This makes a full DRP review mandatory to ensure continuity coverage aligns with the new combined organization.

Concept tested: Triggers for disaster recovery plan review

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-34r1.pdf

Topics

#Disaster recovery plan#DRP review#Organizational change#Business continuity

Community Discussion

No community discussion yet for this question.

Full CISSP Practice