This simulation tests your strategic understanding of enterprise resilience governance. You will evaluate the distinct boundaries between different organizational survival plans during a physical catastrophe.

CCISO (712-50) Executive Decision Simulation

Executive Briefing

A global financial trading firm headquartered in a highly seismically active region has just concluded a tabletop exercise simulating a 7.5 magnitude earthquake. The simulation revealed a critical failure in governance: when the primary datacenter was "destroyed," the IT and business teams clashed over who was responsible for taking immediate, tactical actions to bring critical trading platforms back online.

Business Context

The firm has a Maximum Tolerable Downtime (MTD) of 4 hours. Regulatory bodies mandate strict Recovery Time Objectives (RTOs). The Board of Directors is alarmed by the tabletop failure and demands that the CISO clearly delineate the organizational plans to ensure millions of dollars are not lost to inter-departmental confusion during a real crisis.

Key Constraint: The Board needs to know precisely which document contains the actionable, technical steps to rebuild and restore the IT infrastructure, separate from the broader plan that handles displaced personnel and manual business workarounds.

Decision Scenario

During the executive debriefing, the Chief Operating Officer (COO) asks you, the CISO, to clarify the hierarchy of resilience documentation. They need to know exactly which plan the data center engineers should open to begin the step-by-step restoration of the server arrays and network routing to regain operational normalcy after the facility is physically compromised.

Question

Step-by-step procedures to regain normalcy in the event of a major earthquake is PRIMARILY covered by which of the following plans?
Strategic Hint: Think about the difference between "strategy" and "tactics". Which plan is highly technical and provides the exact IT blueprints to recover systems from a smoking crater, as opposed to the overarching strategy of keeping the business breathing?

Strategic Analysis

1. What is the Real Problem

During a crisis, cognitive load is immense. If executives and engineers do not share a common understanding of resilience governance, response efforts paralyze. The core issue here is distinguishing between the strategic goal of surviving a disaster and the tactical execution of rebuilding the technology stack.

2. Business vs. Security Perspective

From a business perspective, the primary concern is fulfilling client obligations and maintaining revenue (Business Continuity). From an IT/Security perspective, the immediate concern is bare-metal restoration, failing over to alternate sites, and restoring data from backups (Disaster Recovery).

3. Risk and Impact Analysis

If the step-by-step technical procedures are mistakenly buried inside a massive, 500-page Business Continuity document, engineers will waste precious hours searching for technical configuration details. This directly threatens the 4-hour Maximum Tolerable Downtime (MTD), risking severe regulatory fines and catastrophic financial loss.

4. Why the Correct Answer is BEST (B)

The Disaster Recovery Plan (DRP) is the BEST answer because it is specifically designed to be the tactical, technical blueprint. It contains the exact, step-by-step IT procedures required to restore systems, networks, and data to a state of normalcy after a catastrophic event like an earthquake.

5. Why Other Options are Weaker

C. Business Continuity Plan (BCP): The BCP is the overarching strategic umbrella. It dictates what business processes must be saved and how to operate manually without IT, but it does not contain the step-by-step technical server restoration steps.

D. Incident Response Plan (IRP): The IRP is focused on acute, primarily logical security events (e.g., stopping a ransomware spread or evicting a hacker). It is not designed to rebuild infrastructure destroyed by a natural disaster.

A. Damage control plan: This is generally a facilities or PR-centric subset of emergency management, focusing on immediate physical safety or reputation, not IT system normalcy.

MINI LESSON: The Resilience Governance Hierarchy

A CISO must ensure clear boundaries in resilience planning:

  • BCP (The Strategy): Focuses on the *Business*. Keeps operations running during the outage (e.g., relocating staff, paper-based processing).
  • DRP (The Tactics): Focuses on the *Technology*. Rebuilds the IT infrastructure to end the outage (e.g., restoring database backups to a hot site).
  • IRP (The Defense): Focuses on the *Threat*. Neutralizes active cyber attacks before they become full-blown disasters.
EXECUTIVE TAKEAWAY: True enterprise resilience requires separating the overarching business survival strategy (BCP) from the precise, tactical engineering steps needed to restore IT systems (DRP).

Ready to refine your executive leadership skills?

Master strategic decision-making with more CCISO scenarios.

Explore More CCISO Simulations