CompTIA SecurityX (CAS-005)Governance, Risk and ComplianceEasy
A security architect is reviewing the organization's disaster recovery plan (DRP) and business continuity plan (BCP). They note that while the DRP outlines detailed steps for restoring IT systems, the BCP lacks comprehensive strategies for maintaining critical business functions during a prolonged outage. Which governance framework element is primarily being overlooked?
- ASecurity Metrics Reporting
- BThird-Party Risk Management
- CRisk Appetite Statement
- DBusiness Impact Analysis (BIA)
Show answer & explanationAnswer & explanation
Correct answer: D. Business Impact Analysis (BIA)
A Business Impact Analysis (BIA) is crucial for identifying critical business functions and the impact of their disruption, which directly informs the development of a comprehensive BCP. Without a BIA, the BCP will likely be incomplete regarding business function continuity.
Why the other options are wrong
- A. Security Metrics Reporting focuses on measuring security effectiveness, not on identifying critical business functions for continuity.
- B. Third-Party Risk Management addresses risks associated with external vendors, not the internal identification of critical business functions.
- C. A Risk Appetite Statement defines the level of risk an organization is willing to accept, but doesn't detail specific business functions.
Business Impact Analysis (BIA)
A systematic process to determine and evaluate the potential effects of an interruption to critical business operations as a result of a disaster, accident or emergency.
- Identifies critical business functions.
- Determines potential financial and operational impacts.
- Establishes recovery time objectives (RTO) and recovery point objectives (RPO).
Memory trick: To bounce back strong, first know what hits hardest.