CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 577


An IS auditor is reviewing an organization's business continuity plan (BCP) following a change in organizational structure with significant impact to business processes. Which of the following findings should be the auditor's GREATEST concern?

Show Answer
Correct Answer: BC

When an organization undergoes significant changes in its structure affecting business processes, it is crucial to update the business impact analysis (BIA) promptly. The BIA identifies critical business processes and the potential impact of disruptions. Conducting the BIA two years before the reorganization means that the analysis may no longer reflect the current organizational requirements, vulnerabilities, and priorities. An outdated BIA can lead to an ineffective or misaligned business continuity plan, which should be the auditor's greatest concern.

Discussion

10 comments
Sign in to comment
DeeplaxmiOption: C
Sep 18, 2022

BCP should be reevaluated where significant impact is found (Since significant imapct is found on critical business process, we assume BIA has been done). If test plans are older (before reorg) that means that no testing has been done even after the reorg.. So c could be right

AlizadeOption: B
May 6, 2023

B. The most recent business impact analysis (BIA) was performed two years before the reorganization.

MunaMOption: A
Sep 7, 2022

Answer could be A

ziutek_Option: B
Dec 17, 2022

I would go with B

shiowbahOption: D
Oct 29, 2023

D. Key business process end users did not participate in the business impact analysis (BIA)

shiowbah
Nov 19, 2023

B. The most recent business impact analysis (BIA) was performed two years before the reorganization

[Removed]Option: C
Dec 8, 2023

BCP testing would determine if the current BCP is still relevant, if not then update should be performed on the BCP which will then involve additional BIA within the process

[Removed]
Dec 8, 2023

Ignore above, it says test plan, not actual testing. So the correct answer is B. BIA should be performed after significant change in business process as a result of reorganization to help determine if current critical business processes.

takuanismOption: B
Jan 14, 2024

I chose B

SwallowsOption: A
May 20, 2024

During a change in organizational structure with significant impacts on business processes, it's essential to ensure that all relevant personnel have access to the updated BCP. Failure to distribute the plan to new business unit end users could result in a lack of awareness of their roles and responsibilities during disruptions, potentially leading to confusion and inefficiencies during recovery efforts.

InfysenthilOption: D
Jul 6, 2024

I choose D. Option B - BCP still be relevant to some extent, Option D - makes the BCP not relevant, adequate and complete which is a greatest risk. Option C - BCP plan may be adequate to some extent.

RS66Option: B
Jul 10, 2024

B is correct