情報システム監査人は、サードパーティベンダーによって割り当てられたハードウェアが不十分なため、前年度のディザスタリカバリテストがスケジュールされた時間枠内に完了しなかったことを指摘します。システムを正常に回復するために適切なリソースが割り当てられていることを示す最良の証拠を提供するのは、次のうちどれですか?
正解:A
Explanation
The best evidence that adequate resources are now allocated to successfully recover the systems is a service level agreement (SLA). An SLA is a contract between a service provider and a customer that defines the scope, quality, and terms of the service delivery. An SLA should include measurable and verifiable indicators of the service performance, such as availability, reliability, capacity, security, and recovery. An SLA should also specify the roles, responsibilities, and expectations of both parties, as well as the remedies and penalties for non-compliance. An SLA can help to ensure that the third-party vendor has allocated sufficient hardware and other resources to meet the recovery objectives and requirements of the organization. References:
CISA Review Manual (Digital Version)
CISA Questions, Answers & Explanations Database