ExamGecko
Question list
Search
Search

Question 216 - CISM discussion

Report
Export

When performing a business impact analysis (BIA), who should be responsible for determining the initial recovery time objective (RTO)?

A.
External consultant
Answers
A.
External consultant
B.
Information owners
Answers
B.
Information owners
C.
Information security manager
Answers
C.
Information security manager
D.
Business continuity coordinator
Answers
D.
Business continuity coordinator
Suggested answer: B

Explanation:

Information owners are responsible for determining the initial recovery time objective (RTO) for their information assets and processes, as they are the ones who understand the business requirements and impact of a disruption. An external consultant may assist in conducting the business impact analysis (BIA), but does not have the authority to decide the RTO. An information security manager may provide input on the security aspects of the RTO, but does not have the business perspective to determine the RTO. A business continuity coordinator may facilitate the BIA process and ensure the alignment of the RTO with the business continuity plan, but does not have the ownership of the information assets and processes.Reference= CISM Review Manual 15th Edition, page 202.

When performing a business impact analysis (BIA), it is the responsibility of the business continuity coordinator to determine the initial recovery time objective (RTO). The RTO is a critical component of the BIA and should be determined in cooperation with the information owners. The RTO should reflect the maximum tolerable period of disruption (MTPD) and should be used to guide the development of the recovery strategy.

asked 01/10/2024
G C
48 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first