D4: Information Systems Operations and Business Resilience
CISA (ISACA) study guide
CISA D4: Information Systems Operations and Business Resilience
Domain 4 (26% weight, tied for the largest) covers running IT day to day and keeping the business going when something breaks: IT operations, job scheduling, asset and configuration management, incident and problem management, change and patch management, capacity planning, backups, business impact analysis, business continuity, and disaster recovery. Many topics overlap with CISSP Domain 7 and CISM Domain 4. The CISA angle is whether each process exists, is documented, is tested, and produces evidence that it works.
IT service management
Operations should run on defined processes for incidents, problems, changes, releases, and service levels, with SLAs agreed with the business and measured. Auditors check that SLA performance is actually reported and that misses lead to action.
Operations logs and job scheduling
Automated job scheduling reduces operator error, and changes to schedules go through change management. Operations logs and exception reports should be reviewed by someone other than the operator who generated them.
Backup strategy
Backup frequency is driven by the RPO; restore capability is driven by the RTO. Backups should be stored offsite or in a separate region, protected with the same controls as the source data, and periodically test-restored. An untested backup is an audit finding, no matter how reliable the backup job looks.
Business Impact Analysis (BIA)
Identifies critical business processes, the impact of their disruption over time, and the resulting RTO, RPO, and recovery priorities. The BIA comes before choosing recovery strategies, and business process owners, not IT, are the best source of its inputs.
Recovery site options
Hot site: fully equipped, ready within hours. Warm site: partially equipped, ready in days. Cold site: space and utilities only, ready in weeks. Mobile sites and reciprocal agreements are cheaper; reciprocal agreements are the weakest because they are hard to enforce and rarely tested. A shorter RTO requires a more expensive site.
Testing DR and BC plans
From least to most disruptive: checklist review, tabletop or walkthrough, simulation, parallel test, and full interruption. Results should be documented and gaps fed back into the plan. The auditor's core question: has the plan been tested recently, and were the issues found actually resolved?
Incident management vs. problem management
Incident management restores normal service as quickly as possible, and a workaround is fine. Problem management finds and removes the root cause so the incidents stop recurring. Repeated incidents with no problem record opened is a classic audit finding.
Incremental vs. differential backups
An incremental backup copies changes since the last backup of any kind: fastest to create, slowest to restore (the full plus every incremental since). A differential copies all changes since the last full backup: it grows each day, but a restore needs only the full plus the latest differential.
RTO vs. RPO
RTO is how long a process can be down before the impact becomes unacceptable (time to recover). RPO is how much data loss is acceptable, measured backward from the incident, and it drives backup or replication frequency. A 4-hour RPO says nothing about how fast you must be back up.
Sources: ; ;
CISA practice exams are in development. Get every CISA domain in one printable guide, free with an account.
Get the Complete Guide