You are on page 1of 1

Section 3

APPENDIX 3: SAMPLE OF BCP AUDIT FINDING


Max Infotech should have an alternate disaster recovery site and documented procedures and
policies for disaster recovery.

Observation

Max Infotech does not have an alternate disaster recovery site. Also documented Disaster
Recovery Plan (DRP) and business continuity plan are not there.

Exposure

The DRP is a key plan ensuring availability of resources critical to the business operations. In
the absence of documented procedures and policies for the same, it may be difficult to recover
from a disaster resulting in non-availability of data and applications to the users for unacceptable
period of time thereby interrupting business processes and impacting the business.

Cause

This is due to lack of documented Disaster Recovery Plan (DRP).

Recommendation

Ensure that the Max Infotech has an alternate disaster recovery site and a documented
procedures and policies for disaster recovery. This document should include:

• Provision for back up and restoration of resources identified as critical to


recovery;
• Provision for back up and off-site location of non-critical application software,
data files and system software to facilitate their restoration following the recovery
of critical application;
• Frequency of back up and off-site rotation and number of generations
maintained, of production data files including databases;
• Back up and off-site copies of system software, updated or replaced with each
upgrade or revision;
• Off-site copies of systems, program, user and operations documentation updated
to reflect system revision;
• Instructions on how to restore from back-up copies of program and data files.

You might also like