Option B: This is more critical because:
Many organizations outsource key business processes (e.g., payroll, customer service, supply chain logistics).
Excluding them leads to blind spots in continuity and risk planning.
The organization may assume resilience where none exists and fail to account for vendor downtime, SLA breaches, or data unavailability.
This creates a systemic risk that cannot be easily corrected later, especially if vendors are not contractually obligated to meet the organization’s recovery needs.
Given the choice between the two options, I would choose B. Outsourced business processes are excluded from the scope of the BIA.
This is because outsourced processes can be vital to the functioning of an organization. Excluding them means not considering a potentially significant portion of the business operations, which can lead to a substantial gap in understanding the full impact of a disruption. In today's interconnected business world, the failure to include these outsourced processes could render the BIA incomplete and potentially jeopardize the entire continuity plan.
The MOST concerning observation for an IS auditor reviewing an organization's business impact analysis (BIA) practices would be:
C. Resource dependencies for critical processes are not determined.
D. Identifying recovery objectives without conducting risk assessments is a concern, but it's not as critical as failing to determine resource dependencies. Risk assessments help identify potential threats and vulnerabilities, which inform the establishment of recovery objectives. While this is important, understanding resource dependencies is fundamental to the BIA process as it helps identify critical components that must be protected and recovered to ensure business continuity.
In summary, option C is the most concerning because it represents a fundamental gap in the BIA process, potentially leading to an inadequate understanding of what resources are critical for the organization's operations and how they might be impacted during a disruption.
This section is not available anymore. Please use the main Exam Page.CISA Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
saado9
Highly Voted 1Â year, 9Â months agoSwallows
9Â months, 1Â week agomaxson69
Most Recent 1Â week, 2Â days agoSwallows
9Â months, 2Â weeks agoKAP2HURUF
12Â months agoSuperMax
1Â year, 3Â months agoJONESKA
1Â year, 5Â months ago