How to Answer Disaster Recovery Plan Questions
Your customer asked: “Do you maintain a disaster recovery plan?”
The short answer
A disaster recovery plan focuses on restoring technology, systems, and data after a serious disruption. A written plan is not proof that recovery has been tested or that recovery objectives have been achieved.
Educational guidance only. This page does not determine what is true about your company and does not create a security, compliance, testing, or certification claim.
What the customer is really asking
Understand the question before you answer it.
Customers use disaster-recovery questions to understand how your service could recover from significant technical disruption. They may later ask about recovery time, recovery point, testing, alternate infrastructure, and responsible personnel.
How to answer accurately
Start with the version that matches reality.
If a DR plan exists
Describe the scope and ownership at a high level. Only include recovery objectives or testing cadence when those values are documented and approved.
If you rely heavily on cloud services
Explain the recovery approach you actually use. Cloud hosting does not by itself mean your company has a disaster recovery plan.
If the plan has not been tested
Keep “plan exists” and “plan tested” separate. A truthful answer can state that a plan exists while testing remains outstanding.
A useful answer structure
Status → scope → current practice → supporting information. Start with the direct answer, narrow it to what you can verify, explain how the practice works, and reference evidence only when that evidence actually exists.
Evidence that may help
These are examples, not requirements and not proof that your company has the practice. Use only evidence that really exists and is appropriate to share.
- Disaster recovery plan
- Architecture or recovery procedure
- Recovery exercise record
- Backup and restoration evidence
What not to say
- That cloud hosting automatically provides disaster recovery for your application.
- That a written recovery-time objective has been achieved unless testing supports it.
- That the plan is tested simply because backups exist.
How Oredra handles this
Answer it once. Keep the truth behind the answer.
Oredra records the written plan, stated recovery practice, evidence, and testing separately so the questionnaire answer reflects the strongest supported level—no more.
Inside Oredra, a written policy, stated company practice, implemented control, available evidence, tested control, and independent certification remain distinct. Oredra uses approved information to draft future answers and flags questions that the approved profile cannot support.
Authoritative references
Oredra uses primary guidance where a technical or assurance concept benefits from verification. These references do not determine your company's answer.
Related questionnaire questions
Do you back up critical data?
First determine what your company considers critical data, where it is stored, and what recovery copies actually exist. High availability, file version history, replication, and backups can overlap, but they are not automatically the same thing.
Do you test backup restoration?
A successful backup job does not prove that data can be restored. Answer “yes” to restoration testing only when the company has actually performed a recovery or restore test and can describe what was tested.
Do you maintain a business continuity plan?
A business continuity plan describes how essential business operations can continue through a disruption. It is not automatically the same as a disaster recovery plan, an emergency contact list, or a backup process.