ExamGecko
Question list
Search
Search

Related questions

Question 120 - CISA discussion

Report
Export

What is BEST for an IS auditor to review when assessing the effectiveness of changes recently made to processes and tools related to an organization's business continuity plan (BCP)?

A.
Full test results
Answers
A.
Full test results
B.
Completed test plans
Answers
B.
Completed test plans
C.
Updated inventory of systems
Answers
C.
Updated inventory of systems
D.
Change management processes
Answers
D.
Change management processes
Suggested answer: A

Explanation:

The best way to assess the effectiveness of changes made to processes and tools related to an organization's BCP is to review the full test results of the BCP. Full test results can provide evidence of whether the changes have improved the BCP's objectives, such as recovery time objectives (RTOs), recovery point objectives (RPOs), and business impact analysis (BIA). The other options are not as effective as reviewing the full test results, as they do not demonstrate the actual performance of the BCP under simulated disaster scenarios. Completed test plans are only documents that outline the scope, objectives, and procedures of the BCP testing, but they do not show the outcomes or issues encountered during the testing. Updated inventory of systems is a component of the BCP that identifies the critical systems and resources required for business continuity, but it does not measure the effectiveness of the BCP changes. Change management processes are controls that ensure that changes to the BCP are authorized, documented, and communicated, but they do not evaluate the impact or benefit of the changes.Reference:CISA Review Manual (Digital Version), Chapter 4, Section 4.2.3

asked 18/09/2024
Mohamed Mohamed
48 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first