ExamGecko
Question list
Search
Search

Question 76 - CISM discussion

Report
Export

Which of the following is the MOST important reason to conduct interviews as part of the business impact analysis (BIA) process?

A.
To facilitate a qualitative risk assessment following the BIA
Answers
A.
To facilitate a qualitative risk assessment following the BIA
B.
To increase awareness of information security among key stakeholders
Answers
B.
To increase awareness of information security among key stakeholders
C.
To ensure the stakeholders providing input own the related risk
Answers
C.
To ensure the stakeholders providing input own the related risk
D.
To obtain input from as many relevant stakeholders as possible
Answers
D.
To obtain input from as many relevant stakeholders as possible
Suggested answer: D

Explanation:

The most important reason to conduct interviews as part of the business impact analysis (BIA) process is to obtain input from as many relevant stakeholders as possible. A BIA is a process of identifying and analyzing the potential effects of disruptive events on the organization's critical business functions, processes, and resources. A BIA helps to determine the recovery priorities, objectives, and strategies for the organization's continuity planning. Interviews are one of the methods to collect data and information for the BIA, and they involve direct and interactive communication with the stakeholders who are involved in or affected by the business functions, processes, and resources. By conducting interviews, the information security manager can obtain input from as many relevant stakeholders as possible, such as business owners, managers, users, customers, suppliers, regulators, and partners. This can help to ensure that the BIA covers the full scope and complexity of the organization's business activities, and that the BIA reflects the accurate, current, and comprehensive views and expectations of the stakeholders. Interviews can also help to validate, clarify, and supplement the data and information obtained from other sources, such as surveys, questionnaires, documents, or systems. Interviews can also help to build rapport, trust, and collaboration among the stakeholders, and to increase their awareness, involvement, and commitment to the information security and continuity planning.

Reference= CISM Review Manual, 16th Edition, Chapter 3: Information Security Program Development and Management, Section: Business Impact Analysis (BIA), pages 178-1801; CISM Review Questions, Answers & Explanations Manual, 10th Edition, Question 65, page 602.

asked 01/10/2024
TREVOR COLLEDGE
45 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first