IS 監査人は、サードパーティ ベンダーによって割り当てられたハードウェアが不十分だったため、前年度の災害復旧テストが予定された時間枠内に完了しなかったことを指摘します。システムを正常に復旧するために十分なリソースが割り当てられていることを最もよく示す証拠は次のどれですか。
正解:A
The best evidence that adequate resources are now allocated to successfully recover the systems is a service level agreement (SLA). An SLA is a contract between a service provider and a customer that defines the scope, quality, and terms of the service delivery. An SLA should include measurable and verifiable indicators of the service performance, such as availability, reliability, capacity, security, and recovery. An SLA should also specify the roles, responsibilities, and expectations of both parties, as well as the remedies and penalties for non-compliance. An SLA can help to ensure that the third-party vendor has allocated sufficient hardware and other resources to meet the recovery objectives and requirements of the organization. References:
* CISA Review Manual (Digital Version)
* CISA Questions, Answers & Explanations Database