SSCP: The Premier Security Administrator Certification

Which of the following statements regarding an off-site information processing facility is TRUE?

Prev Question Next Question

Question

Which of the following statements regarding an off-site information processing facility is TRUE?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

A.

It is very important that the offsite has the same restrictions in order to avoide misuse.

The following answers are incorrect because: It should be located in proximity to the originating site so that it can quickly be made operational is incorrect as the offsite is also subject to the same disaster as of the primary site.

It should be easily identified from the outside so in the event of an emergency it can be easily found is also incorrect as it should not be easily identified to prevent intentional sabotage.

Need not have the same level of environmental monitoring as the originating site since this would be cost prohibitive is also incorrect as it should be like its primary site.

Reference : Information Systems Audit and Control Association, Certified Information Systems Auditor 2002 review manual, chapter 5: Disaster Recovery and Business Continuity (page 265).

An off-site information processing facility is a location where an organization's critical information processing activities can be transferred to in the event of a disaster or other emergency that renders the primary processing site unusable. This allows the organization to maintain continuity of operations and minimize the impact of the disruption on business operations.

Regarding the given options, the statement that is TRUE is:

A. It should have the same amount of physical access restrictions as the primary processing site.

Explanation:

Physical access restrictions are used to limit access to critical areas and resources to authorized personnel only. This is an important aspect of security that helps prevent unauthorized access, theft, or damage to equipment and data. Therefore, the off-site information processing facility should have the same amount of physical access restrictions as the primary processing site to ensure the same level of security.

Option B is incorrect because the off-site facility does not necessarily have to be located in proximity to the originating site. It can be located in a different geographic location, as long as it provides the necessary resources and infrastructure required to support the organization's critical operations.

Option C is incorrect because the off-site facility should not be easily identified from the outside. This is to prevent potential attackers from identifying the location of the facility and targeting it for attack. Instead, the location should be kept confidential and only shared with authorized personnel who have a need to know.

Option D is incorrect because the off-site facility should have the same level of environmental monitoring as the originating site. Environmental monitoring includes temperature, humidity, and other factors that can affect the performance of the equipment and data storage. Failure to maintain the same level of environmental monitoring at the off-site facility can result in equipment failure or data loss, which can have a significant impact on the organization's operations.

In conclusion, the statement that is TRUE regarding an off-site information processing facility is that it should have the same amount of physical access restrictions as the primary processing site.