ISACA Certified Information Systems Auditor (CISA) ExamDomain 2: Governance and Management of ITMedium
An organization is developing its business continuity plan (BCP). The CISA notes that while the BCP addresses technical recovery and alternate site activation, it lacks specific procedures for communicating with external stakeholders such as customers, suppliers, and regulatory bodies during a disruption. What is the MOST critical risk introduced by this omission?
- ADelayed recovery of critical IT systems.
- BIneffective training for BCP team members.
- CDamage to reputation and potential legal/regulatory penalties.
- DInability to accurately assess the financial impact of the disaster.
Show answer & explanationAnswer & explanation
Correct answer: C. Damage to reputation and potential legal/regulatory penalties.
Failure to communicate effectively with external stakeholders during a crisis can lead to significant reputational damage, loss of customer trust, and potential legal or regulatory fines for non-compliance, which are critical risks to the organization's long-term viability.
Why the other options are wrong
- A. Technical recovery is addressed; external communication primarily impacts reputation and compliance, not direct system recovery speed.
- B. Team training is important, but the lack of communication procedures itself is a more fundamental risk than just training effectiveness.
- D. Financial assessment is typically part of BIA, which precedes BCP communication planning.
BCP External Communication
A robust Business Continuity Plan (BCP) must include specific procedures for communicating with external stakeholders during a disruption to manage public perception, maintain trust, and ensure compliance.
- Manages reputational risk.
- Ensures compliance with contractual/regulatory obligations.
- Maintains stakeholder confidence.
Memory trick: BCP communication is 'OUTBOUND' for reputation and rules.