ExamGecko
Question list
Search
Search

Question 526 - CISM discussion

Report
Export

Which of the following should be the GREATEST concern for an information security manager when an annual audit reveals the organization's business continuity plan (BCP) has not been reviewed or updated in more than a year?

A.
An outdated BCP may result in less efficient recovery if an actual incident occurs.
Answers
A.
An outdated BCP may result in less efficient recovery if an actual incident occurs.
B.
The organization may suffer reputational damage for not following industry best practices.
Answers
B.
The organization may suffer reputational damage for not following industry best practices.
C.
The audit finding may impact the overall risk rating of the organization.
Answers
C.
The audit finding may impact the overall risk rating of the organization.
D.
The lack of updates to the BCP may result in noncompliance with internal policies.
Answers
D.
The lack of updates to the BCP may result in noncompliance with internal policies.
Suggested answer: A

Explanation:

A BCP is a document that outlines the processes and procedures to maintain or resume critical business functions and minimize the impact of a disruption on the organization's objectives, customers, and stakeholders. A BCP should be reviewed and updated regularly to reflect the changes in the organization's environment, risks, resources, and requirements. An outdated BCP may result in less efficient recovery if an actual incident occurs, as it may not account for the current situation, dependencies, priorities, or recovery strategies. This may lead to increased downtime, losses, or damages for the organization.

Reference= CISM Review Manual 2022, page 3101; CISM Exam Content Outline, Domain 4, Knowledge Statement 4.82; CISM 2020: Business Continuity3; Part Two: Business Continuity and Disaster Recovery Plans

asked 01/10/2024
Christopher Scott
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first