Organizations dependenue;
communications;
safety;
customer services;
logistics;
regulatory obligations;
critical business processes.
Eventually, something will fail.
The failure may result from:
ransomware;
hardware failure;
power loss;
fire;
flood;
human error;
software corruption;
telecommunications failure;
cloud outage;
supply-chain disruption;
natural disaster;
malicious attack.
Security therefore cannot focus only on:
preventing disruption.
It must also answer:
How will the organization continue critical operations and recover when disruption occurs?
That requires several related but distinct disciplines:
BACKUP
β
RECOVERY
β
DISASTER RECOVERY
β
BUSINESS CONTINUITY
β
ORGANIZATIONAL RESILIENCE
The current CISSP Examination Outline places this lesson primarily under Domain 7 β Security Operations, Objectives 7.10 through 7.13.
Including:
backup storage strategies such as cloud, onsite, and offsite;
recovery-site strategies such as cold and hot sites and resource-capacity agreements;
multiple processing sites;
system resilience;
high availability;
Quality of Service;
fault tolerance.
Including:
response;
personnel;
communications;
assessment;
restoration;
training and awareness;
lessons learned.
Including:
read-through/tabletop;
walkthrough;
simulation;
parallel;
full interruption;
stakeholder, test-status, and regulator communications.
NIST continues to list SP 800-34 Rev. 1, Contingency Planning Guide for Federal Information Systems, as its final contingency-planning guide. It connects contingency planning with the Business Impact Analysis, preventive controls, recovery strategies, plan development, testing/training/exercises, and plan maintenance.
NIST SP 800-184 further emphasizes recovery planning, resource prioritization, realistic recovery exercises, recovery playbooks, and continual improvement after cybersecurity events.
The central Lesson Twenty-Seven question is:
How should an organization design, implement, test, and continuously improve backup, recovery, disaster-recovery, and business-continuity capabilities so critical operations can survive disruption and return to a trusted state within defined business requirements?
| Lesson Topic | Primary Alignment |
|---|---|
| Recovery strategies | 7.10 |
| Backup strategy | 7.10 |
| Cloud backup | 7.10 |
| Onsite backup | 7.10 |
| Offsite backup | 7.10 |
| Offline backup | 7.10 supporting concept |
| Immutable backup | 7.10 supporting concept |
| Backup testing | 7.10 / 7.12 |
| Recovery sites | 7.10 |
| Cold site | 7.10 |
| Warm site | 7.10 supporting concept |
| Hot site | 7.10 |
| Resource-capacity agreement | 7.10 |
| Multiple processing sites | 7.10 |
| High availability | 7.10 |
| Fault tolerance | 7.10 |
| QoS | 7.10 |
| Redundancy | 7.10 |
| Failover | 7.10 |
| Replication | 7.10 |
| RTO | 7.10 / BIA bridge |
| RPO | 7.10 / BIA bridge |
| Disaster Recovery | 7.11 |
| DR activation | 7.11 |
| Personnel | 7.11 |
| DR communications | 7.11 |
| Damage assessment | 7.11 |
| Restoration | 7.11 |
| Recovery validation | 7.11 |
| Failback | 7.11 |
| DR training | 7.11 |
| Lessons learned | 7.11 |
| Read-through/tabletop | 7.12 |
| Walkthrough | 7.12 |
| Simulation | 7.12 |
| Parallel test | 7.12 |
| Full interruption | 7.12 |
| DR test communications | 7.12 |
| Business Continuity | 7.13 |
| Manual workarounds | 7.13 |
| Alternate staffing | 7.13 |
| Critical suppliers | 7.13 |
| Alternate facilities | 7.13 |
| BC exercises | 7.13 |
| Organizational resilience | 7.10β7.13 |
After completing this lesson, you should be able to:
Define resilience.
Distinguish backup, recovery, DR, and BC.
Explain the relationship between the BIA and recovery strategy.
Define RTO.
Define RPO.
Explain maximum tolerable downtime conceptually.
Explain recovery priorities.
Define a backup.
Explain full backups.
Explain incremental backups.
Explain differential backups.
Compare incremental and differential restoration.
Explain snapshots.
Explain replication.
Distinguish replication from backup.
Explain onsite backup.
Explain offsite backup.
Explain cloud backup.
Explain online backup.
Explain offline backup.
Explain immutable backup.
Explain air-gapped backup conceptually.
Explain the 3-2-1 backup concept.
Explain backup encryption.
Explain backup-key protection.
Explain backup integrity.
Explain restoration testing.
Explain why backup-job success does not prove recoverability.
Explain backup retention.
Explain backup accounts and least privilege.
Explain ransomware-resistant backup design.
Explain recovery sites.
Define a cold site.
Define a warm site.
Define a hot site.
Compare recovery-site cost and recovery speed.
Explain reciprocal agreements.
Explain resource-capacity agreements.
Explain multiple processing sites.
Explain active-active architecture.
Explain active-passive architecture.
Explain failover.
Explain failback.
Explain high availability.
Explain fault tolerance.
Distinguish HA from fault tolerance.
Explain redundancy.
Explain common-mode failure.
Explain geographic diversity.
Explain QoS.
Explain DR-plan activation.
Explain damage assessment.
Explain personnel requirements.
Explain emergency communications.
Explain restoration priorities.
Explain system dependencies.
Explain clean recovery.
Explain recovery validation.
Explain DR training.
Explain lessons learned.
Explain DR read-through/tabletop testing.
Explain walkthrough testing.
Explain simulation testing.
Explain parallel testing.
Explain full-interruption testing.
Compare DR testing risk and realism.
Explain DR-test communications.
Explain BC.
Distinguish BC from DR.
Distinguish Incident Response from DR.
Explain manual business workarounds.
Explain alternate staffing.
Explain supplier continuity.
Explain business-process dependencies.
Apply CISSP FIRST/BEST/MOST reasoning to recovery scenarios.
Resilience is the ability of an organization or system to:
withstand disruption;
continue essential functions;
recover;
adapt.
An organization can invest heavily in prevention and still experience disruption.
Therefore:
PREVENTION
+
DETECTION
+
RESPONSE
+
RECOVERY
=
RESILIENCE
A backup is a retained copy of information or system state intended to support restoration.
Recovery restores:
information;
applications;
systems;
services
after disruption.
Disaster Recovery focuses primarily on restoring:
information technology capabilities and supporting infrastructure after a significant disruption.
Business Continuity focuses on:
continuing critical business functions during and after disruption.
BACKUP
"Do we have recoverable copies?"
RECOVERY
"Can we restore?"
DR
"Can technology operations be restored?"
BC
"Can critical business operations continue?"
A hurricane destroys the primary office.
IT successfully activates systems in another region.
But:
staff cannot work;
supplier cannot deliver;
customer call center is unavailable.
Technology recovered.
Business continuity did not.
Incident response focuses on:
detecting;
containing;
investigating;
remediating
security incidents.
DR focuses on:
restoring disrupted technology capability.
SECURITY INCIDENT
β
INCIDENT RESPONSE
β
MAJOR SERVICE DISRUPTION?
βββ NO β Normal remediation
βββ YES
β
DISASTER RECOVERY
β
BUSINESS CONTINUITY
Do not begin DR planning by asking:
βWhich server is technically most powerful?β
Ask:
Which business functions are most critical?
The Business Impact Analysis helps determine:
critical processes;
dependencies;
acceptable disruption;
recovery priorities.
BUSINESS PROCESS
β
BIA
β
RECOVERY REQUIREMENTS
β
RTO / RPO
β
RECOVERY STRATEGY
β
TECHNOLOGY
NIST defines the Recovery Time Objective as the overall length of time system components can remain in the recovery phase before negatively affecting organizational mission or business processes.
Simplified CISSP memory:
How quickly must the service be recovered?
RTO:
4 hours.
The organization designs recovery capability intended to restore the required service within that target.
NIST defines RPO as:
the point in time to which data must be recovered after an outage.
Simplified exam memory:
How much data loss in time can the organization tolerate?
RPO:
30 minutes.
Recovery should ideally restore information to no more than approximately 30 minutes before the disruption, subject to the defined strategy.
| Objective | Main Question |
|---|---|
| RTO | How long can recovery take? |
| RPO | How far back can recovered data go? |
FAILURE OCCURS
β
ββββββ RPO βββββΊ Previous recoverable point
β
βββββββΊ RTO ββββββΊ Service restored
RPO:
15 minutes.
RTO:
8 hours.
The organization may tolerate only 15 minutes of data loss while accepting up to eight hours to restore the service.
Organizations may use terms such as:
Maximum Tolerable Downtime;
Maximum Allowable Downtime.
Terminology can vary.
Conceptually:
At what point does the outage create unacceptable harm to the business?
The recovery design should ensure:
RTO does not exceed the organization's maximum tolerable outage requirement.
The system administrator should not independently decide:
βRTO is 10 minutes.β
Recovery objectives should originate from:
business need;
BIA;
risk;
management.
LONGER RTO
Lower-cost recovery may be acceptable
β
VERY SHORT RTO
Higher-cost resilience may be required
Backups protect against:
accidental deletion;
corruption;
ransomware;
hardware failure;
disaster.
You have a perfect backup.
Production database fails.
Restore time:
16 hours.
If the business requires:
5-minute availability,
backup alone is insufficient.
You may need:
replication;
clustering;
fault tolerance;
HA.
A full backup copies the complete defined backup set.
simple restoration;
fewer backup sets required during recovery.
Typically requires:
more storage;
more backup time.
Copies data changed since the most recent backup of the relevant sequence, whether full or incremental.
SUNDAY
Full
MONDAY
Changes since Sunday
TUESDAY
Changes since Monday
WEDNESDAY
Changes since Tuesday
To restore Wednesday:
SUNDAY FULL
+
MONDAY INCREMENTAL
+
TUESDAY INCREMENTAL
+
WEDNESDAY INCREMENTAL
Generally:
smaller/faster daily backup operations.
Recovery can be:
more complex and potentially slower.
Copies data changed since the most recent full backup.
SUNDAY
FULL
MONDAY
Changes since Sunday
TUESDAY
All changes since Sunday
WEDNESDAY
All changes since Sunday
Requires:
SUNDAY FULL
+
WEDNESDAY DIFFERENTIAL
| Incremental | Differential |
|---|---|
| Changes since latest backup | Changes since latest full |
| Smaller daily backup | Grows during cycle |
| More restore sets | Fewer restore sets |
| Restore can be slower | Restore often simpler |
Incremental:
full + all required incrementals.
Differential:
full + latest differential.
A snapshot captures a point-in-time state of a storage or computing resource.
Can support:
rapid rollback;
quick recovery;
testing.
If a snapshot depends on the same:
storage system;
administrator;
cloud account
as production, compromise of that environment may affect both.
Replication maintains copies of data or services across multiple locations or systems.
recovery time;
service interruption.
Suppose ransomware encrypts:
Production Database A.
Real-time replication may faithfully replicate:
encrypted/corrupted data
to Database B.
Replication improves:
availability.
Backup provides:
recoverable historical copies.
Stored near or within the primary facility.
Advantages:
fast access;
potentially rapid restoration.
A single event could affect:
production;
onsite backup.
Examples:
fire;
flood;
theft;
ransomware.
Stored geographically separate from production.
Helps reduce:
common-site disaster risk.
Current CISSP Objective 7.10 explicitly includes cloud backup/storage strategies.
Benefits may include:
geographic separation;
scalability;
managed storage.
shared responsibility;
cloud identity compromise;
provider availability;
vendor dependence;
deletion privileges;
recovery bandwidth.
Continuously or routinely accessible through the operating environment or network.
Advantage:
convenient recovery.
Risk:
attackers may reach it.
Not continuously accessible from production.
This can reduce exposure to ransomware.
CISA recommends maintaining offline, encrypted backups of critical data and regularly testing backup availability and integrity during disaster-recovery scenarios.
An immutable backup is designed so stored backup data cannot be altered or deleted during the defined retention period.
This may reduce the attacker's ability to:
encrypt;
delete;
modify
recovery data.
CISA ransomware guidance also emphasizes encrypted, protected, and where appropriate immutable backup capabilities.
misconfiguration;
compromised administrative controls;
corrupted source data;
insufficient retention.
An air gap creates strong separation between:
backup resources
and:
production systems.
This may be:
physical;
logical,
depending on architecture.
PRODUCTION
β
X
β
PROTECTED BACKUP
The objective is to prevent the same attacker or failure from easily compromising both environments.
A commonly referenced resilience strategy is:
3 copies of data;
2 different media/storage forms;
1 copy offsite.
CISA advisories have referenced the 3-2-1 approach through allied cyber-security guidance.
Do not treat 3-2-1 as:
the only valid CISSP recovery architecture.
The exam principle is:
eliminate single points of failure and protect recovery copies from the same event that compromises production.
offline copy;
immutable copy;
geographic separation;
separate administrative credentials;
tested restoration.
A backup can contain:
sensitive customer records;
passwords or hashes;
intellectual property;
regulated data.
Protect confidentiality appropriately.
Encrypted backup with lost encryption key:
unusable backup.
BACKUP DATA
+
DECRYPTION KEY
+
RESTORE SOFTWARE
+
DOCUMENTATION
If the same compromised administrator account can:
modify production;
delete backup;
alter retention,
ransomware impact can increase.
Use:
least privilege;
separate roles;
strong authentication;
protected administrative paths.
A backup may contain:
corrupted data;
malware;
incomplete application state.
BACKUP
β
VERIFY CREATION
β
VERIFY INTEGRITY
β
RESTORE TEST
β
VALIDATE APPLICATION / DATA
Not:
βDid backup software say success?β
But:
Can the organization actually restore the required service and data?
CISA specifically recommends regular testing of backup procedures and backup availability/integrity.
restore single file;
restore database;
restore server;
rebuild critical service;
recover complete environment.
A backup may restore successfully but:
take too long;
contain data too old.
Therefore test:
restoration and business recovery objectives.
Determines how long recovery versions remain available.
Factors include:
recovery needs;
regulation;
legal requirements;
ransomware dwell time;
storage cost.
Attacker gains persistence:
January 1.
Ransomware activates:
March 1.
If backups retain only:
seven days,
all retained images might already contain attacker persistence.
Multiple generations can help recover from:
delayed discovery;
corruption;
ransomware.
job failures;
missed assets;
deletion attempts;
administrative changes;
capacity.
Not only user files.
Potentially:
configuration;
databases;
system images;
encryption-related information;
application binaries;
infrastructure definitions;
critical documentation.
CISA's ransomware guidance recommends maintaining golden images and protected copies of critical rebuilding resources, including infrastructure-as-code templates where applicable.
Do not assume teams can access:
documentation stored only on the failed network.
Maintain appropriate protected copies.
A recovery site provides facilities or resources for restoring operations when the primary site is unavailable.
Typically provides:
physical facility;
power;
basic environmental capability;
communications potential.
But limited preinstalled operational systems.
lower recurring cost.
longer recovery time;
equipment/configuration must be established.
Typically represents an intermediate option.
May include:
some equipment;
connectivity;
partial configuration.
COLD
Low cost / Slow recovery
WARM
Medium cost / Medium recovery
HOT
High cost / Fast recovery
Provides a highly prepared alternate environment with:
hardware;
network connectivity;
system capability;
supporting infrastructure.
Can support:
much faster recovery.
Typically:
significantly more expensive.
| Site | Readiness | Cost | Recovery Speed |
|---|---|---|---|
| Cold | Low | Lower | Slow |
| Warm | Moderate | Medium | Medium |
| Hot | High | Higher | Fast |
Exact designs vary.
Teams may still need to:
synchronize data;
validate systems;
redirect users;
test applications.
Two organizations agree to provide recovery capability to each other.
Can reduce:
cost.
Questions include:
Do systems have compatible capacity?
What if both experience the same disaster?
Will resources actually be available?
Is the agreement tested?
Current Objective 7.10 specifically lists resource capacity agreements as a recovery-site strategy.
A contractual arrangement ensures defined processing or infrastructure resources can be made available during a recovery event.
Provider has recovery facility.
But contract guarantees only:
20 virtual machines.
Organization requires:
The site exists.
The required recovery capability does not.
Objective 7.10 explicitly includes multiple processing sites.
Multiple locations actively process production workloads.
SITE A ββββββΊ SITE B
Both serving production
Can provide:
rapid failover;
load distribution;
high availability.
One site handles production while another is prepared to assume service.
SITE A
ACTIVE
β
βββ replication
βΌ
SITE B
PASSIVE / STANDBY
Movement of service from:
failed or degraded component
to:
alternate component or site.
Automatic:
faster;
more complex;
poor detection logic can cause unnecessary failover.
Manual:
slower;
more operator control.
Moving operations from the alternate environment back to the repaired/preferred environment.
It may require:
data synchronization;
downtime;
validation;
careful sequencing.
High availability attempts to minimize service interruption through:
redundancy;
clustering;
failover;
resilient design.
COMPONENT FAILURE
β
ALTERNATE CAPACITY
β
SERVICE CONTINUES
Fault tolerance allows a system to continue operating despite failure of one or more components within its design tolerance.
High Availability:
minimize downtime.
Fault Tolerance:
continue operation through certain failures, often with little or no service interruption.
HA:
Server fails β cluster fails over after brief interruption.
Fault tolerance:
Component fails β redundant component immediately continues operation without meaningful loss of service.
Provides additional components such as:
power supplies;
network paths;
servers;
storage.
Two redundant systems may depend on the same:
power source;
network carrier;
building;
cloud region;
administrator account.
One event can then affect both.
PRIMARY SITE
β
POWER A
CARRIER A
REGION A
ALTERNATE SITE
β
POWER B
CARRIER B
REGION B
where business requirements justify that level of diversity.
Alternate environments located too close together may both be affected by:
hurricane;
earthquake;
regional outage;
civil emergency.
Too close:
common disaster risk.
Too far:
latency, staffing, cost, data-replication challenges.
Quality of Service mechanisms prioritize network/service resources according to defined requirements.
Current Objective 7.10 explicitly includes QoS as a resilience concept.
During reduced recovery capacity:
emergency voice traffic;
critical database replication;
business-critical applications
may receive priority over:
streaming;
nonessential transfers.
QoS prioritizes available resources.
It does not magically create:
unlimited capacity.
Current CISSP Objective 7.11 specifically includes:
response;
personnel;
communications;
assessment;
restoration;
training/awareness;
lessons learned.
The DR plan should identify:
when and by whom it may be activated.
Single workstation failure:
normal support process.
Entire primary data center unavailable:
possible DR activation.
Declaring a disaster can trigger:
contracts;
alternate facilities;
major spending;
communications.
Authority should be defined in advance.
DISRUPTION
β
ASSESS
β
DECLARE / ACTIVATE?
β
MOBILIZE
β
RECOVER
Plans should define:
roles;
alternates;
decision authority;
contact information.
What happens if the primary recovery manager is:
unavailable?
Assign:
backups;
alternates;
succession.
After major disasters:
people may be injured, displaced, or unable to work.
Human safety precedes equipment recovery.
Current Objective 7.11 explicitly includes communications.
Who contacts staff?
How?
What if email is down?
Who contacts suppliers?
Who informs customers?
Possible methods:
mobile;
alternate messaging;
emergency notification platform;
phone trees.
Avoid relying on:
the system that is currently unavailable.
An emergency list containing:
former employees
can delay response.
Determine:
what failed;
extent of damage;
expected duration;
recovery options.
TECHNICAL:
What systems are down?
BUSINESS:
What critical processes are affected?
Both matter.
Restore systems according to:
approved recovery priority.
You restore:
employee cafeteria application
before:
enterprise identity service.
The cafeteria application still cannot operate.
Dependency planning matters.
BUSINESS APPLICATION
β
DATABASE
β
IDENTITY
β
DNS
β
NETWORK
β
POWER
Recovery order must respect dependencies.
Depending on environment:
power;
network;
DNS;
authentication;
storage;
time services;
databases.
The most technically expensive system is not necessarily:
the most important system to restore first.
Recovery from ransomware must consider:
reinfection.
CISA recommends restoring from protected offline backups based on critical-service priority and ensuring clean systems are not reconnected to contaminated recovery environments.
CLEAN RECOVERY VLAN
β
βββ Validated system A
βββ Validated system B
βββ Validated system C
COMPROMISED SYSTEMS
X
If identity infrastructure was compromised, recovery may require:
privileged credential reset;
token revocation;
certificate/key review;
administrative trust rebuilding.
Confirm:
security baseline;
patch state;
application integrity;
authentication;
monitoring;
data consistency.
RESTORE FILES
β
VALIDATE DATA
β
VALIDATE SYSTEM
β
VALIDATE SECURITY
β
VALIDATE BUSINESS PROCESS
DR processes explicitly include training and awareness.
A perfect plan that nobody understands is:
operationally weak.
where to report;
what authority they have;
alternate communication paths;
required procedures.
Ask:
Did RTO hold?
Did RPO hold?
Did communications work?
Were contact details accurate?
Were dependencies correct?
Did backups restore?
DISASTER
β
RECOVERY
β
REVIEW
β
LESSONS
β
UPDATE PLAN
β
RETEST
NIST SP 800-184 emphasizes learning from recovery events and tests to continually improve recovery planning and organizational resilience.
A DR plan that has never been tested is:
an assumption.
read-through/tabletop;
walkthrough;
simulation;
parallel;
full interruption.
LOW OPERATIONAL RISK
β
READ-THROUGH / TABLETOP
β
WALKTHROUGH
β
SIMULATION
β
PARALLEL
β
FULL INTERRUPTION
β
HIGHER REALISM / RISK
Participants review:
the DR plan and procedures.
Goal:
identify missing;
outdated;
contradictory
information.
Participants discuss their response to a scenario.
Example:
Primary data center is unavailable for 72 hours.
low operational disruption;
exercises decision making;
reveals role confusion.
Participants saying:
βWe would restore the databaseβ
does not prove:
they can actually restore it.
Personnel walk through recovery procedures, locations, systems, or steps with greater operational detail.
Team:
travels to recovery location;
identifies equipment;
reviews connections;
confirms procedural steps.
Participants respond to a simulated disaster scenario with more realistic activities while avoiding actual production interruption.
Scenario:
Primary site is declared unavailable.
Teams execute:
communications;
coordination;
recovery decisions
without actually shutting production down.
Recovery systems are activated and tested while:
normal production continues.
PRODUCTION
Still operating
+
RECOVERY SITE
Restores copies and processes test workload
Provides stronger technical evidence without intentionally interrupting production.
Does not fully prove:
production can be cut over to the alternate environment during a real disaster.
Actual production operations are interrupted and recovery capability assumes the workload.
This provides powerful evidence.
But also:
highest operational risk.
If recovery fails:
the test itself can create a real outage.
| Test | Production Impact | Realism |
|---|---|---|
| Read-through | Very Low | Low |
| Tabletop | Very Low | Low/Moderate |
| Walkthrough | Low | Moderate |
| Simulation | Low/Moderate | Moderate |
| Parallel | Moderate | High |
| Full Interruption | High | Highest |
There is no universal:
βalways perform full interruption.β
Choose according to:
criticality;
risk;
maturity;
business tolerance;
regulatory needs.
An organization may progress from:
TABLETOP
β
WALKTHROUGH
β
SIMULATION
β
PARALLEL
β
FULL INTERRUPTION
as confidence and requirements justify.
Communications during DR testing may include:
stakeholders;
test status;
regulators.
Monitoring teams may see:
failovers;
unusual traffic;
systems going offline.
They should know:
this is an authorized exercise.
Some participants may intentionally receive:
limited advance information
to test real response behavior.
Management still needs appropriate authorization.
Define:
what is being tested;
expected recovery time;
expected data recovery;
required functionality.
Test objective:
Restore payroll application within four hours using offsite backup and process a validated test payroll transaction.
This is stronger than:
βTest DR.β
If recovery target:
4 hours
actual result:
6 hours
the test did not meet the RTO.
Required RPO:
1 hour.
Recovered data:
5 hours old.
The recovery technically worked.
The business requirement failed.
start time;
completion time;
systems restored;
failures;
dependencies;
decisions;
corrective actions.
backup cannot be restored
during:
controlled testing
than during:
ransomware recovery.
TEST
β
FAILURE
β
ROOT CAUSE
β
CORRECT
β
RETEST
Current CISSP Domain 7 requires candidates to participate in Business Continuity planning and exercises.
How will the organization continue delivering critical services despite disruption?
Online ordering platform unavailable.
Temporary BC procedure:
accept orders through a controlled manual process.
Technology remains unavailable.
Business continues at reduced capacity.
Temporary human process used when automated capability is unavailable.
Electronic badge system fails.
Approved emergency procedure may use:
guard verification;
manual visitor log.
Manual processes can create:
errors;
fraud;
security bypass.
They require:
procedures;
authorization;
reconciliation afterward.
people;
technology;
facilities;
communications;
suppliers;
records;
utilities.
Only one employee knows how to execute a critical recovery procedure.
That is:
a key-person dependency.
Use:
documentation;
training;
alternates;
succession.
Potential approaches:
alternate site;
remote work;
distributed workforce.
Consider:
Internet;
voice;
mobile;
alternate carriers.
A company may recover its systems but still fail because:
critical supplier is unavailable.
Does supplier have BC/DR?
Does contract define recovery capability?
Are alternates available?
Is geographic concentration understood?
Cloud platforms can also experience:
region failure;
identity outage;
provider incident.
Can reduce:
regional single points of failure.
But increases:
complexity;
cost;
data-management challenges.
May reduce some provider concentration risks.
But it can create:
operational complexity;
inconsistent controls;
skill requirements.
CISA's ransomware guidance notes that multi-cloud approaches may be considered for certain backup-resilience scenarios, while also emphasizing careful design.
Production:
Cloud Account A.
Snapshots:
same Cloud Account A.
Attacker compromises account and deletes both.
The backups were logically separate objects.
They were not:
administratively independent.
PRODUCTION ADMIN
X
β
BACKUP ADMIN
SEPARATE CREDENTIALS
SEPARATE POLICY
SEPARATE DELETION AUTHORITY
Do not discover during disaster that:
recovery credential expired;
MFA device unavailable;
emergency vault cannot be opened.
May be necessary for:
identity outage;
cloud lockout;
major infrastructure failure.
Protect and test them carefully.
A backup may contain malware that was present before detection.
Recovery teams may need:
validation;
scanning;
known-clean recovery points.
CISA recommends maintaining updated golden images of critical systems to support rapid rebuilding after ransomware incidents.
In cloud environments:
VERSION-CONTROLLED IaC
β
NEW CLEAN ENVIRONMENT
β
RESTORE VALIDATED DATA
β
TEST
This can support rapid clean recovery when templates themselves are trusted.
You may also need:
software;
licenses;
installation media;
keys;
documentation.
Backup created from old platform.
Replacement hardware does not support:
old operating system.
Recovery fails due to compatibility.
Recovery documentation exists.
Only administrator who knows encryption key process is:
unreachable.
This is a continuity failure.
Application restored successfully.
Users cannot access it because:
DNS recovery was omitted.
CRITICAL SERVICE
β
βββ PEOPLE
βββ APPLICATION
βββ DATABASE
βββ IDENTITY
βββ NETWORK
βββ DNS
βββ POWER
βββ SUPPLIERS
Three copies stored on:
three disks in same building.
Fire destroys building.
You had:
multiple copies,
but not sufficient:
risk diversity.
Primary and backup both depend on:
same region;
same identity tenant;
same administrator.
That can create:
hidden common dependencies.
HA handles certain:
component/service failures.
DR addresses:
significant disruptive events.
Two servers in one data center:
high availability.
Building burns down:
both unavailable.
HA did not provide adequate site-level DR.
Having tapes stored offsite does not mean:
the organization has a complete DR program.
You also need:
people;
procedures;
systems;
facilities;
communications;
testing.
DR may restore IT.
BC ensures critical business operation continues.
Business Continuity:
maintain critical processes.
Crisis management:
coordinate major organizational consequences and strategic decisions.
They can overlap.
Not:
βWhat is easiest to restore?β
But:
What business capability is most critical?
Even if payroll is critical, first restore:
identity;
databases;
network dependencies
if payroll depends on them.
TIER 0
Foundational infrastructure
TIER 1
Mission-critical services
TIER 2
Important business systems
TIER 3
Noncritical services
Exact tiers are organization-specific.
βServer is up.β
Business owner must confirm:
βBusiness function actually works.β
SERVER ONLINE
β
BUSINESS PROCESS RESTORED
Transactions processed manually during outage may need:
reconciliation
after automated systems return.
Treat it with:
planning;
testing;
synchronization;
authorization;
monitoring.
Primary site appears operational.
Moving back too soon may create:
another outage;
data inconsistency.
Need:
impact;
expected restoration;
decisions.
Need:
tasks;
dependencies;
status.
Need:
service status;
approved communications.
Some sectors may require:
notification;
evidence;
exercise participation.
Current CISSP Objective 7.12 explicitly recognizes regulator communications as a DR-test consideration.
Under pressure, teams may bypass:
MFA;
segmentation;
logging.
βSecurity can be turned off until systems come back.β
Recovery environments are attractive attacker targets.
Recovered environment should restore critical protections such as:
identity;
logging;
endpoint protection;
network segmentation;
backup protection.
Use BACKUP for backup-strategy questions.
RTO and RPO drive the design.
Avoid one storage location or common failure domain.
Protect backup credentials, data, and keys.
Use appropriate offsite, offline, or immutable capabilities.
Include applications, configurations, licenses, and documentation.
Test recovery instead of trusting job-success messages.
B
BUSINESS REQUIREMENTS
β
βΌ
A
ADD COPIES
β
βΌ
C
CONTROL ACCESS
β
βΌ
K
KEEP PROTECTED
β
βΌ
U
UNDERSTAND DEPENDENCIES
β
βΌ
P
PROVE RESTORATION
Use RESTORE for disaster-recovery questions.
Know RTO, RPO, and business priorities.
Sites, people, communications, and capacity.
Restore foundational capabilities in the correct order.
Move from discussion-based exercises toward stronger validation where appropriate.
Restore services in a trusted state.
Plan failback and reconciliation.
Capture lessons and update the plan.
R
RECOVERY REQUIREMENTS
β
βΌ
E
ESTABLISH ALTERNATIVES
β
βΌ
S
SEQUENCE DEPENDENCIES
β
βΌ
T
TEST
β
βΌ
O
OPERATE RECOVERY
β
βΌ
R
RETURN / FAILBACK
β
βΌ
E
EVALUATE
Use CONTINUE for Business Continuity scenarios.
Identify what must continue.
Assign responsible personnel and backups.
Technology, people, facilities, suppliers, records.
Prepare alternate processes.
Understand internal and external dependencies.
Maintain alternate communications.
Practice BC procedures.
Update plans after tests and events.
A critical application must return to service within four hours after an outage.
Which recovery measurement does this MOST directly establish?
A. RTO
B. RPO
C. ALE
D. SLE
A
Management determines that no more than 30 minutes of transaction data can be lost.
Which requirement is this?
A. RPO
B. RTO
C. MTTD
D. MTBF
A
A company performs a full backup Sunday and incremental backups each day.
To restore Thursday's state, what is generally required?
A. Sunday's full backup and each applicable incremental through Thursday.
B. Thursday incremental only.
C. Sunday's full only.
D. Latest differential.
A
A full backup was completed Sunday and differential backups run daily.
What is generally needed to restore Wednesday?
A. Sunday full plus Wednesday differential.
B. Every differential from Monday through Wednesday.
C. Wednesday differential only.
D. Sunday full only.
A
A ransomware infection encrypts data on the primary server and the encrypted files immediately replicate to the secondary server.
What principle is MOST clearly demonstrated?
A. Replication is not a substitute for backup.
B. Replication always prevents ransomware.
C. Secondary servers cannot be corrupted.
D. Backup is unnecessary with HA.
A
The organization wants recovery copies that ransomware cannot easily reach from the compromised production network.
Which approach MOST directly helps?
A. Properly protected offline backup.
B. Only another writable network share.
C. Same-account snapshot only.
D. Browser cache.
A
Backup software shows 100% success for six months, but nobody has attempted a restore.
What is the MOST important concern?
A. Recoverability has not been demonstrated.
B. Backup testing is unnecessary.
C. Successful jobs guarantee RTO.
D. RPO automatically equals zero.
A
The organization has encrypted offsite backups, but the only copy of the decryption key was destroyed with the primary data center.
What failed?
A. Recovery key-management planning.
B. Backup confidentiality.
C. Fire suppression.
D. QoS.
A
Management wants the lowest-cost alternate facility and accepts a long recovery time.
Which recovery-site strategy is MOST appropriate?
A. Cold site.
B. Hot site.
C. Active-active.
D. Fault-tolerant cluster.
A
A financial service requires very rapid restoration and is willing to pay substantially for a highly prepared alternate environment.
Which is MOST appropriate?
A. Hot site.
B. Cold site.
C. Empty warehouse.
D. File archive.
A
Two redundant data centers rely on the same electrical substation and telecommunications conduit.
What is the PRIMARY concern?
A. Common-mode failure.
B. Too much geographic diversity.
C. Excessive fault tolerance.
D. Data classification.
A
An application uses two clustered servers in the same building.
What is the MOST accurate conclusion?
A. This can improve availability but does not necessarily provide site-level disaster recovery.
B. It guarantees disaster recovery.
C. Backups are no longer required.
D. The building cannot fail.
A
The organization starts recovery systems and processes test workloads while production continues normally.
Which DR test is this?
A. Parallel test.
B. Full interruption.
C. Read-through.
D. Cold-site declaration.
A
Management deliberately shuts down primary production and requires the alternate site to assume the real workload.
Which test is this?
A. Full interruption.
B. Tabletop.
C. Walkthrough.
D. Documentation review.
A
Managers and technical personnel discuss how they would respond to a simulated data-center fire without actually moving production.
Which test is this?
A. Tabletop.
B. Full interruption.
C. Parallel.
D. Failback.
A
A DR test fails to restore the database within its required RTO.
What should happen NEXT?
A. Analyze the cause, correct the recovery capability, and retest.
B. Change the test result to pass.
C. Ignore it because production was unaffected.
D. Eliminate the RTO.
A
A cyberattack disables the order-management platform. Staff use a documented manual procedure to continue accepting high-priority orders.
What is MOST clearly demonstrated?
A. Business Continuity.
B. Disk sanitization.
C. Penetration testing.
D. Configuration baselining.
A
Only one administrator knows how to restore the organization's encrypted database.
What is the PRIMARY continuity concern?
A. Key-person dependency.
B. Too many backups.
C. High availability.
D. Excessive redundancy.
A
All internal systems recover successfully, but the business cannot operate because its only payment provider remains offline.
What did the plan fail to address?
A. External dependency/supplier continuity.
B. Local server configuration.
C. Disk encryption.
D. Media sanitization.
A
Production has been running at the alternate site for one week. The primary site is repaired.
What should happen before returning operations?
A. Plan and validate synchronization, security, dependencies, and controlled failback.
B. Immediately move systems without analysis.
C. Delete alternate-site data.
D. Disable monitoring.
A
No.
Backup is:
one component of recovery.
No.
DR primarily restores technology.
BC maintains critical business functions.
No.
IR handles the incident.
DR restores disrupted technology capability when necessary.
No.
That is primarily RPO.
RTO concerns:
recovery time.
No.
RPO concerns:
recoverable data point.
No.
Business requirements and the BIA should drive recovery objectives.
Not necessarily.
Backup architecture depends on:
recovery objectives;
storage;
performance;
operational requirements.
No.
Normally you need:
full + required incremental chain.
No.
Generally:
full + latest required differential.
No.
Snapshots can share the same failure and administrative domain as production.
No.
Replication may copy corruption or ransomware.
Not necessarily.
Examine:
region;
tenant;
account;
provider;
deletion authority.
No.
Incorrect configuration or corrupted input can still create problems.
False.
An offline backup can still be:
corrupted;
incomplete;
unusable.
No.
You must be able to recover:
the keys.
No.
Recovery actions and synchronization may still be required.
Not if the required RTO cannot be met.
Not if the additional cost cannot be justified by business recovery requirements.
They may share:
power;
network;
location;
administration.
They are related but not identical.
No.
HA may not protect against:
site failure;
ransomware;
large-scale disaster.
No.
QoS prioritizes available capacity.
No.
Dependencies matter.
Not necessarily.
Recovery priority is driven by:
business criticality and dependencies.
Not during long-dwell compromise.
No.
It primarily tests:
plans;
roles;
decisions.
Normally production continues while recovery capability is tested.
No.
It generally has the highest operational risk and realism.
No.
A controlled failure provides valuable improvement information.
No.
Business continuity involves:
people;
facilities;
suppliers;
technology;
communications;
business processes.
No.
Cloud dependencies can fail too.
What is the PRIMARY purpose of Business Continuity?
A. Maintain critical business operations during disruption.
B. Only restore servers.
C. Perform penetration tests.
D. Manage source code.
A
What is Disaster Recovery primarily concerned with?
A. Restoring technology capability after significant disruption.
B. Hiring employees.
C. Data classification only.
D. Software development.
A
What does RTO measure?
A. Required recovery time.
B. Acceptable data-loss point.
C. Vulnerability severity.
D. Password age.
A
What does RPO measure?
A. The point in time to which data must be recovered.
B. Restoration labor cost.
C. Service availability percentage.
D. Network throughput.
A
Which backup generally requires the longest restore chain?
A. Incremental.
B. Differential.
C. Full.
D. None.
A
Which generally requires full backup plus the latest differential?
A. Differential recovery.
B. Incremental recovery.
C. RAID recovery only.
D. Replication.
A
Why is replication not sufficient as the only backup strategy?
A. Corruption or malicious changes can replicate.
B. Replication always stores historical generations.
C. Replication is always offline.
D. Replication cannot copy data.
A
Why are offline backups valuable against ransomware?
A. They reduce continuous attacker access to recovery copies.
B. They guarantee zero data loss.
C. They eliminate restoration testing.
D. They replace access control.
A
What is an immutable backup designed to resist?
A. Unauthorized alteration or deletion during the retention period.
B. Power loss only.
C. Network latency.
D. User authentication.
A
Which site normally offers the fastest recovery?
A. Hot site.
B. Cold site.
C. Empty office.
D. Archive facility.
A
Which site generally has the lowest ongoing cost?
A. Cold site.
B. Hot site.
C. Active-active.
D. Fault-tolerant site.
A
What is failover?
A. Moving service to alternate capacity following failure.
B. Destroying backup media.
C. Changing data classification.
D. Ending an audit.
A
What is failback?
A. Returning service from alternate capacity to the preferred environment.
B. Deleting backup data.
C. Disabling DR.
D. Starting a tabletop.
A
What is the major purpose of fault tolerance?
A. Continue operation despite supported component failure.
B. Increase audit scope.
C. Increase data loss.
D. Replace BC.
A
What does QoS primarily do?
A. Prioritize available service/network resources.
B. Create unlimited bandwidth.
C. Encrypt backups.
D. Replace fault tolerance.
A
Which DR test runs recovery capability while production remains operational?
A. Parallel.
B. Full interruption.
C. Read-through.
D. None.
A
Which DR test normally creates the greatest production risk?
A. Full interruption.
B. Tabletop.
C. Read-through.
D. Documentation review.
A
What is a primary purpose of DR lessons learned?
A. Improve plans and future recovery capability.
B. Hide failures.
C. Eliminate testing.
D. Increase RTO automatically.
A
Which should determine system-restoration priorities?
A. Business criticality and dependencies.
B. Hardware price alone.
C. Server age alone.
D. Administrator preference.
A
Which statement is MOST accurate?
A. Resilience combines preparation, redundancy, recoverability, tested DR, and business continuity.
B. Backups alone guarantee resilience.
C. HA eliminates the need for DR.
D. BC is solely an IT responsibility.
A
A company's business impact analysis determines that its payment-processing application can be unavailable for no more than two hours and may lose no more than five minutes of transactions.
Which pair is correct?
A. RTO = 2 hours; RPO = 5 minutes.
B. RTO = 5 minutes; RPO = 2 hours.
C. Both are RTOs.
D. Both are RPOs.
A
A company maintains continuous replication of a database to another server in the same cloud account. A compromised administrator deletes both databases.
What is the BEST improvement?
A. Add recovery copies protected through separate failure and administrative boundaries.
B. Increase replication speed.
C. Eliminate backups.
D. Use the same administrator everywhere.
A
A backup is encrypted, stored offsite, and retained for one year. During a DR test, nobody can locate the required decryption key.
What is the PRIMARY lesson?
A. Backup strategy must include recoverable key-management procedures.
B. Encryption should never be used.
C. Offsite storage caused the failure.
D. Retention was too long.
A
An organization has a four-hour RTO but its cold site requires two days to acquire and configure hardware.
What is the BEST conclusion?
A. The recovery strategy cannot satisfy the business requirement.
B. Cold sites always meet every RTO.
C. Change the BIA to two days automatically.
D. RTO does not affect site selection.
A
Two active data centers are geographically separated but rely on the same identity-provider tenant. The identity service fails globally.
What risk was underestimated?
A. Common dependency/common-mode failure.
B. Excessive backup retention.
C. Physical media exposure.
D. Incremental backup complexity.
A
During a ransomware recovery, the organization discovers that all online backups were encrypted by the attacker.
Which prior control would have MOST directly reduced the impact?
A. Protected offline or appropriately immutable recovery copies.
B. Faster Internet service.
C. More local administrator accounts.
D. Shorter password length.
A
A DR team restores an application server before restoring its authentication and database services. The application remains unusable.
What planning issue is demonstrated?
A. Recovery dependencies were not sequenced correctly.
B. RPO was too low.
C. Backups should be removed.
D. QoS failed.
A
Management wants to validate the alternate processing site technically without deliberately taking down production.
Which DR test BEST fits?
A. Parallel test.
B. Full interruption.
C. Read-through only.
D. No testing.
A
An organization has never exercised its DR plan and management proposes beginning with a full-interruption test of the payment platform.
What is the BEST recommendation?
A. Use a risk-based progression of exercises before undertaking a high-impact full interruption unless requirements justify otherwise.
B. Full interruption is always the safest first test.
C. Do not test DR.
D. Only test after a real disaster.
A
During a BC exercise, a critical supplier says it cannot deliver for 30 days after a regional disaster.
What should the organization do?
A. Evaluate alternate suppliers and continuity strategies for that dependency.
B. Ignore external dependencies.
C. Increase backup frequency.
D. Replace the SIEM.
A
A business unit manually processes transactions during a six-hour system outage. After recovery, the transactions are not entered into the restored system.
What is the PRIMARY problem?
A. The BC workaround lacked reconciliation procedures.
B. The backup was too encrypted.
C. DR testing is unnecessary.
D. The RTO was too short.
A
A company successfully restores every server within the RTO but cannot perform customer transactions because an external API remains unavailable.
What is the BEST conclusion?
A. Technical recovery alone did not restore the complete business service.
B. DR is automatically successful whenever servers boot.
C. Supplier dependencies do not affect BC.
D. RPO eliminates third-party risk.
A
A DR test restores the database within two hours, but the required RTO is one hour.
How should the result be recorded?
A. The recovery worked technically but failed the required RTO.
B. Full success.
C. RTO is irrelevant after restoration.
D. Change the measured time to one hour.
A
A backup administrator can modify production systems, disable immutable retention, and delete all backup copies.
What security principle should be strengthened?
A. Separation of duties and least privilege.
B. QoS.
C. RPO.
D. Warm-site capacity.
A
A company uses a highly available cluster across two racks in one data center and believes a DR site is unnecessary.
What is the BEST response?
A. HA addresses certain failures, but site-level disasters can still require DR capability.
B. Clustering eliminates every disaster scenario.
C. Backups are no longer required.
D. Business Continuity becomes irrelevant.
A
| Concept | Question |
|---|---|
| RTO | How quickly must service return? |
| RPO | To what point must data be recovered? |
| MTD/MAD concept | How long before business impact becomes unacceptable? |
| Recovery Priority | What should be restored first? |
| Dependency | What must exist first for the service to work? |
| Backup Type | Captures | Restore Requirement |
|---|---|---|
| Full | Entire defined dataset | Full |
| Incremental | Changes since previous relevant backup | Full + all needed incrementals |
| Differential | Changes since last full | Full + latest differential |
| Snapshot | Point-in-time state | Platform dependent |
| Replication | Copy of current/near-current state | Alternate live/standby copy |
| Strategy | Main Benefit | Main Concern |
|---|---|---|
| Onsite | Fast access | Same-site disaster |
| Offsite | Geographic separation | Recovery logistics |
| Cloud | Scalability/geographic options | Provider/tenant dependency |
| Online | Convenient | Ransomware reachability |
| Offline | Isolation | Slower/manual access |
| Immutable | Resists alteration/deletion | Configuration and retention design |
| Air-gapped | Strong separation | Operational complexity |
| Site | Cost | Readiness | Typical Recovery |
|---|---|---|---|
| Cold | Lower | Low | Slow |
| Warm | Medium | Moderate | Moderate |
| Hot | Higher | High | Fast |
| Active-Active | Highest/complex | Operational | Very fast |
| Active-Passive | High/medium | Standby | Fast, depending design |
| Test | Production Interrupted? | Primary Value |
|---|---|---|
| Read-through | No | Document review |
| Tabletop | No | Decision/role testing |
| Walkthrough | Usually no | Procedure/facility validation |
| Simulation | Usually no | Realistic coordination |
| Parallel | No | Technical recovery validation |
| Full Interruption | Yes | Highest end-to-end realism |
| Resource | Continuity Question |
|---|---|
| People | Are trained alternates available? |
| Facility | Where will work occur? |
| Technology | Can systems be restored? |
| Data | Can required information be recovered? |
| Communications | How will teams coordinate? |
| Suppliers | Can dependencies continue? |
| Utilities | Are power/connectivity available? |
| Records | Can critical documentation be accessed? |
Copy of data or system information retained for restoration purposes.
Restoration of information, systems, or services following disruption.
Activities used to restore information-system capabilities following significant disruption.
Capability to continue critical business functions during disruption.
Ability to withstand, recover from, and adapt to disruption.
Time-related target describing how long recovery may take before unacceptable mission/business impact occurs.
Point in time to which data must be recovered after disruption.
Backup containing the entire defined backup dataset.
Backup of changes since the previous relevant backup.
Backup of changes since the latest full backup.
Point-in-time representation of system or storage state.
Maintenance of copies of data or services across systems or locations.
Backup not continuously accessible from production systems.
Backup protected against alteration or deletion during a defined retention period.
Separation intended to prevent direct access between production and protected recovery resources.
Alternate facility with limited preinstalled computing capability.
Partially equipped alternate facility.
Highly prepared alternate facility capable of comparatively rapid recovery.
Arrangement between organizations to provide recovery resources to one another.
Contractual arrangement reserving or providing processing/recovery capacity.
Transfer of workload to alternate capability after failure.
Controlled return from alternate capability to the primary/preferred environment.
Architecture intended to minimize service downtime.
Ability to continue operation through supported component failures.
Provision of additional components or paths to reduce single points of failure.
Single event or dependency capable of defeating multiple supposedly redundant components.
Mechanisms used to prioritize available network or service resources.
Documented strategy and procedures for recovering technology capability after disruptive events.
DR test in which recovery resources are activated while production remains operational.
DR test involving actual interruption of production and transition to recovery capability.
Temporary non-automated method used to continue a business process during technology unavailability.
Known system build or template used to rebuild systems into an approved state.
For recovery questions, use this sequence:
WHAT BUSINESS PROCESS MATTERS?
β
WHAT DOES THE BIA REQUIRE?
β
WHAT ARE RTO AND RPO?
β
WHAT DEPENDENCIES EXIST?
β
WHICH STRATEGY CAN MEET THEM?
β
IS THERE A COMMON FAILURE DOMAIN?
β
HAS RECOVERY BEEN TESTED?
β
CAN THE BUSINESS ACTUALLY OPERATE?
Remember:
Current CISSP Objective 7.10 includes cloud/onsite/offsite backup strategies, recovery sites, capacity agreements, multiple processing sites, resilience, HA, QoS, and fault tolerance.
Objective 7.11 covers DR response, personnel, communications, assessment, restoration, training, and lessons learned.
Objective 7.12 explicitly includes read-through/tabletop, walkthrough, simulation, parallel, full interruption, and communications.
Objective 7.13 covers participation in BC planning and exercises.
RTO is time to required recovery.
RPO is the required recovered-data point.
Business requirements drive RTO and RPO.
Faster recovery generally costs more.
Backup does not equal availability.
Backup does not equal DR.
DR does not equal BC.
Incremental recovery normally requires the full backup plus the required sequence of incrementals.
Differential recovery generally requires the full backup plus the latest required differential.
Snapshots are not automatically independent backups.
Replication can replicate corruption.
Replication improves availability but does not necessarily provide historical recoverability.
Offsite protection reduces same-location risk.
CISA recommends offline, encrypted backups and regular recovery testing as part of ransomware resilience.
Immutable storage can strengthen backup protection but must still be properly configured and tested.
Protected recovery copies should not share every administrative failure domain with production.
Encryption requires recoverable key management.
A successful backup job does not prove restoration capability.
Test actual restores.
CISA recommends restoring from protected offline backups according to critical-service priorities and avoiding reinfection during recovery.
Cold sites cost less but normally recover more slowly.
Hot sites cost more but support faster recovery.
Site selection should follow required recovery objectives rather than preference.
Multiple processing sites can support resilience but may still share hidden dependencies.
High availability does not automatically equal disaster recovery.
Fault tolerance and high availability are related but distinct.
Redundancy without diversity can leave common-mode failures.
QoS prioritizes available resources; it does not create unlimited resources.
DR restoration sequence must respect technical and business dependencies.
Recovery is not complete merely because a server boots.
Business owners should validate restored business functionality.
The newest backup may contain attacker persistence.
Recovery environments must remain secure.
DR testing should use measurable success criteria.
Tabletop testing provides low-risk plan validation but does not prove technical recovery.
Parallel testing provides stronger recovery evidence without intentionally interrupting production.
Full-interruption testing provides high realism at high operational risk.
Failed DR tests are opportunities for improvement.
BC includes people, facilities, technology, communications, suppliers, utilities, and critical information.
Manual workarounds require later reconciliation.
External suppliers and cloud services are part of continuity dependencies.
NIST SP 800-184 emphasizes recovery planning, prioritization, realistic testing, and continual improvement.
NIST continues to list SP 800-34 Rev. 1 as its final contingency-planning guide and provides BIA and contingency-plan resources with it.
Lesson Twenty-Seven connected the four layers of organizational recovery:
BACKUP
β
RECOVERY
β
DISASTER RECOVERY
β
BUSINESS CONTINUITY
You learned that effective recovery begins not with technology but with:
business requirements.
The BIA establishes criticality.
RTO establishes:
how quickly capability must return.
RPO establishes:
how far back recovered information may go.
NIST's current glossary defines RTO and RPO in these mission/business recovery terms.
You then examined the backup lifecycle:
IDENTIFY CRITICAL DATA
β
CREATE BACKUPS
β
PROTECT COPIES
β
SEPARATE FAILURE DOMAINS
β
VERIFY INTEGRITY
β
RESTORE TEST
β
MEASURE RTO / RPO
Modern ransomware resilience requires more than a second writable copy of production. CISA recommends offline, encrypted backups, regular restoration testing, protected golden images, and recovery practices designed to prevent reinfection.
You compared:
FULL
INCREMENTAL
DIFFERENTIAL
SNAPSHOT
REPLICATION
and learned the critical principle:
Replication is not automatically backup because replication may reproduce corruption or malicious changes.
You then examined alternate processing strategies:
COLD SITE
β
WARM SITE
β
HOT SITE
β
MULTIPLE PROCESSING SITES
β
HIGH AVAILABILITY / FAULT TOLERANCE
The correct solution is determined by:
business criticality;
RTO;
RPO;
cost;
risk;
dependencies.
You also studied the current CISSP disaster-recovery testing sequence:
READ-THROUGH / TABLETOP
β
WALKTHROUGH
β
SIMULATION
β
PARALLEL
β
FULL INTERRUPTION
with increasing realism generally accompanied by increasing operational exposure. The current CISSP outline explicitly lists these test approaches.
Finally, you distinguished technology restoration from actual business continuity:
SERVER RESTORED
β
APPLICATION RESTORED
β
DEPENDENCIES RESTORED
β
BUSINESS PROCESS VALIDATED
β
BUSINESS CONTINUITY ACHIEVED
The three SierraTec Secure models for this lesson are:
Base on business requirements β Add copies β Control access β Keep protected β Understand dependencies β Prove restoration
Recovery requirements β Establish alternatives β Sequence dependencies β Test β Operate recovery β Return β Evaluate
Critical processes β Owners β Necessary resources β Temporary workarounds β Interdependencies β Notify β Undertake exercises β Enhance
The central Lesson Twenty-Seven principle is:
Recovery capability is not proven by possessing backup files or writing a disaster-recovery plan. True resilience requires business-defined recovery objectives, independently protected and recoverable data, resilient processing capacity, dependency-aware restoration, trained personnel, alternate communications, repeated testing, validated business functionality, and continuous improvement based on evidence.
Before moving to Lesson Twenty-Eight, make sure you can explain without reviewing:
Backup versus recovery.
Recovery versus DR.
DR versus BC.
Incident Response versus DR.
Organizational resilience.
The relationship between the BIA and recovery design.
RTO.
RPO.
RTO versus RPO.
Maximum tolerable downtime conceptually.
Why faster recovery generally costs more.
What a full backup is.
What an incremental backup is.
What a differential backup is.
Incremental restore requirements.
Differential restore requirements.
What a snapshot is.
Why a snapshot may not be an independent backup.
What replication is.
Why replication does not replace backup.
Why ransomware corruption can replicate.
Onsite versus offsite backups.
Cloud backup considerations.
Online versus offline backup.
Why offline copies improve ransomware resilience.
What immutable storage means.
Why immutable does not mean invulnerable.
What an air gap represents.
What the 3-2-1 concept represents.
Why 3-2-1 is a strategy rather than a universal CISSP mandate.
Why backup encryption matters.
Why encryption-key recovery matters.
Why backup administrators should follow least privilege.
Why successful backup jobs do not prove recoverability.
Why restore testing matters.
Why backup retention matters during long-dwell compromise.
Why application/configuration/software recovery resources matter.
What a cold site is.
What a warm site is.
What a hot site is.
Cold versus warm versus hot tradeoffs.
What a reciprocal agreement is.
What a resource-capacity agreement is.
What multiple processing sites are.
Active-active versus active-passive.
What failover is.
What failback is.
Why failback requires planning.
What high availability means.
What fault tolerance means.
HA versus fault tolerance.
Why HA does not automatically equal DR.
What redundancy means.
What common-mode failure means.
Why geographic diversity matters.
Why diverse telecommunications/power may matter.
What QoS does.
Why QoS does not create bandwidth.
What triggers DR activation.
Why declaration authority should be defined.
Why personnel alternates are required.
Why life safety comes before technology recovery.
Why alternate communications matter.
What damage assessment means.
Why recovery priorities come from business requirements.
Why dependencies determine restoration order.
Why DNS, identity, network, and storage may be foundational.
What clean recovery means.
Why recovery from ransomware can reinfect systems.
Why credentials may need rebuilding during recovery.
What recovery validation means.
Why βserver onlineβ does not automatically mean βbusiness recovered.β
Why DR personnel need training.
What DR lessons learned should accomplish.
Read-through testing.
Tabletop testing.
Walkthrough testing.
Simulation testing.
Parallel testing.
Full-interruption testing.
Which DR tests have lower versus higher operational risk.
Why a parallel test does not intentionally interrupt production.
Why full interruption provides strong evidence but significant risk.
Why test success criteria should be established beforehand.
Why RTO and RPO should be measured during exercises.
Why failed exercises provide useful evidence.
What Business Continuity means.
What a manual workaround is.
Why manual work must be reconciled after recovery.
Why key-person dependencies matter.
Why supplier continuity matters.
Why cloud platforms do not eliminate continuity risk.
Why administrative separation can protect backups.
Why golden images and IaC can support clean recovery.
Why recovery documentation must remain accessible during a disaster.
Why business owners should validate restored services.
Lesson Twenty-Eight will complete the remaining major CISSP Domain 7 objectives by focusing primarily on:
Including:
perimeter security controls;
internal security controls.
Including:
travel;
security training and awareness;
insider threats;
social-media impacts;
two-factor/MFA fatigue;
emergency management;
duress.
The lesson will cover:
physical-security operations;
defense in depth;
site perimeter;
fencing;
gates;
bollards;
lighting;
CCTV;
guards;
access badges;
visitor management;
mantraps/access vestibules;
tailgating;
piggybacking;
secure areas;
server-room controls;
equipment security;
environmental monitoring;
fire;
water;
HVAC;
power;
physical intrusion detection;
key management;
badge lifecycle;
travel security;
laptop/mobile-device travel protections;
hotel/public-network risk;
international travel considerations;
insider threat;
behavioral reporting;
social-media exposure;
social engineering;
MFA fatigue;
emergency management;
evacuation;
shelter-in-place;
muster/accountability;
duress alarms;
panic mechanisms;
personnel safety;
original SierraTec operational-security models;
exam traps;
knowledge checks;
CISSP-style scenarios.
The central Lesson Twenty-Eight question will be:
How should organizations operate physical and personnel security controls so facilities, equipment, information, and people remain protected during normal operations, travel, emergencies, insider-threat situations, and physical-security incidents?
This lesson is independently developed educational material for the SierraTec Secure CISSP Certification Preparation Course.
CISSP is administered by ISC2. SierraTec Secure's course is independent certification-preparation material and should not be represented as official ISC2 training unless separately authorized.
The primary exam alignment was verified against the current official CISSP Certification Exam Outline. Objectives 7.10β7.13 currently address recovery strategies, DR implementation, DR testing, and BC planning/exercises.
NIST SP 800-34 Rev. 1 remains listed by NIST as its final contingency-planning guide and provides guidance connecting BIA, recovery strategies, contingency plans, testing/training/exercises, and plan maintenance.
Cyber-event recovery concepts were supplemented with NIST SP 800-184, which emphasizes recovery planning, resource prioritization, testing, playbooks, metrics, and continuous improvement.
Current ransomware-oriented backup practices were supplemented with CISA guidance recommending offline, encrypted backups, routine restore testing, protected golden images, and clean recovery processes designed to avoid reinfection.
The SierraTec Secure BACKUP, RESTORE, and CONTINUE frameworks, diagrams, examples, comparison tables, knowledge checks, and practice questions are original instructional material and are not actual, recalled, leaked, or official CISSP examination questions.