ExamGecko
Question list
Search
Search

Question 452 - CISM discussion

Report
Export

A business impact analysis (BIA) should be periodically executed PRIMARILY to:

A.
validate vulnerabilities on environmental changes.
Answers
A.
validate vulnerabilities on environmental changes.
B.
analyze the importance of assets.
Answers
B.
analyze the importance of assets.
C.
check compliance with regulations.
Answers
C.
check compliance with regulations.
D.
verify the effectiveness of controls.
Answers
D.
verify the effectiveness of controls.
Suggested answer: D

Explanation:

A business impact analysis (BIA) is a process that helps identify and evaluate the potential effects of disruptions or incidents on the organization's mission, objectives, and operations.A BIA should be periodically executed to verify the effectiveness of the controls that are implemented to prevent, mitigate, or recover from such disruptions or incidents12.

According to the CISM Manual, a BIA should be performed at least annually for critical systems and processes, and more frequently for non-critical ones3.A BIA should also be updated whenever there are significant changes in the organization's environment, such as new regulations, technologies, business models, or stakeholder expectations3. A BIA should not be used to validate vulnerabilities on environmental changes (A), analyze the importance of assets (B), or check compliance with regulations , as these are not the primary purposes of a BIA.

asked 01/10/2024
jitendra makwana
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first