ExamGecko
Question list
Search
Search

Related questions











Question 578 - CISA discussion

Report
Export

An IS auditor is reviewing an organization's business continuity plan (BCP) following a change in organizational structure with significant impact to business processes. Which of the following findings should be the auditor's GREATEST concern?

A.
Key business process end users did not participate in the business impact ' analysis (BIA)
Answers
A.
Key business process end users did not participate in the business impact ' analysis (BIA)
B.
Copies of the BCP have not been distributed to new business unit end users sjnce the reorganization
Answers
B.
Copies of the BCP have not been distributed to new business unit end users sjnce the reorganization
C.
A test plan for the BCP has not been completed during the last two years
Answers
C.
A test plan for the BCP has not been completed during the last two years
Suggested answer: C

Explanation:

A test plan for the BCP is essential to ensure that the plan is effective, updated and aligned with the current business needs and objectives. A change in organizational structure with significant impact to business processes may require a revision of the BCP and a new test plan to validate its adequacy. The lack of a test plan for the BCP for two years indicates a high risk of failure in the event of a disaster or disruption. Therefore, this should be the auditor's greatest concern among the given options.Reference:

ISACA, IT Control Objectives for Sarbanes-Oxley, 4th Edition, section 5.3.21

ISACA, CISA Review Manual, 27th Edition, chapter 5, section 5.42

asked 18/09/2024
Ehsan Ali
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first