CISSP Exam QuestionsBrowse all questions from this exam

CISSP Exam - Question 337


What is the MAIN purpose of conducting a business impact analysis (BIA)?

Show Answer
Correct Answer: D

The main purpose of conducting a business impact analysis (BIA) is to determine the effect of mission-critical information system failures on core business processes. A BIA evaluates the potential effects of an interruption to critical business operations as a result of a disaster, accident, or emergency. Its primary goal is to collect information to help the organization prepare for these disruptions by understanding how system failures can impact essential business functions and processes.

Discussion

6 comments
Sign in to comment
CuteRabbit168Option: D
Sep 29, 2022

A business impact analysis (BIA) is a systematic process to determine and evaluate the potential effects of an interruption to critical business operations as a result of a disaster, accident or emergency. A business impact analysis (BIA) predicts the consequences of a disruption or outage of a business function, system or process and gathers information needed to develop recovery strategies.

jackdryan
May 14, 2023

D is correct

sandeepghadgeOption: C
Sep 27, 2022

Conducting the Business Impact Analysis (BIA) The next step in the planning process is to have the planning team perform a BIA. The BIA will help the company decide what needs to be recovered, and how quickly. Mission functions are typically designated with terms such as critical, essential, supporting, and nonessential to help determine the appropriate prioritization. I will go with C

Goseu
Apr 7, 2023

I agree with you.

WiDeBarulhoOption: D
Oct 25, 2022

Going with "D" on this one. Option "C" falls more towards the DR aspect of BIA.

franbarproOption: D
Oct 25, 2022

Failures on core business processes sounds like it could have a huge impact on the business.

eboehmOption: C
Apr 10, 2024

Interesting everyone went with D. The problem I have with answer d is that it mentions Information systems when a bia is about all business processes. I honestly think C is a better answer. Why do you identify critical processes? its for part 2(identify resource requirements) and 3(identify recovery priorities) of the BIA process. Ultimately, part 1 feeds into part 2. Everyone can claim their system is the most critical but once faced with how much recovery costs would be, this often changes. The critical outcomes of BIA will be a series of time measurements: MTD, RTO, RPO, WRT. None of the other BCP planing steps can be done without these values. Infact the MTD is what escalates incident to being a disaster

TheManiacOption: D
May 19, 2024

BIA is not made for infosec systems. answer is D

TheManiac
May 19, 2024

I meant C :( but there is no edit button