When auditing disaster recovery how does an auditor draw the line between incident response and disaster recovery when scoping the project? What audit steps or work falls under incident response and what falls under disaster recovery? Some of the tasks are clear, but there is some areas that cross-over, no? Thank you.