ISACA Certified Information Systems Auditor (CISA) ExamDomain 4: Information Systems Operations and Business ResilienceHard

An IS auditor is evaluating an organization's business continuity plan (BCP) testing program. The auditor finds that while the BCP is regularly tested through tabletop exercises, a full simulation exercise involving all critical systems and personnel has not been conducted in three years. The organization has experienced significant changes to its IT infrastructure and key personnel during this period. What is the MOST significant risk associated with this finding?

  1. ATabletop exercises are generally less effective than full simulation exercises.
  2. BThe organization may fail to meet regulatory requirements for BCP testing.
  3. CKey personnel may not be adequately trained on their BCP roles and responsibilities.
  4. DThe BCP may contain outdated procedures that are no longer effective in the current environment.
Show answer & explanation

Correct answer: D. The BCP may contain outdated procedures that are no longer effective in the current environment.

While all options present risks, the most significant risk is that the BCP itself, despite tabletop exercises, has not been validated against the *actual* operational environment. Significant infrastructure and personnel changes over three years mean that documented procedures, recovery strategies, and interdependencies are very likely to be outdated and ineffective in a real disaster, rendering the BCP potentially inoperable.

Why the other options are wrong

  • A. While true, this is a general statement about exercise types and doesn't capture the specific severity of having an untested plan in a changed environment.
  • B. Regulatory non-compliance is a serious consequence, but the primary operational risk is the BCP's inability to function, which directly impacts business survival.
  • C. Personnel training is a risk, but the underlying issue is that the procedures themselves might be wrong, making training on them ineffective.

Business Continuity Plan (BCP) Testing Frequency

Business Continuity Plan (BCP) testing should be conducted regularly and include a variety of exercise types, from tabletop discussions to full simulations, to ensure the plan remains current, effective, and aligns with the evolving organizational and technical landscape.

  • Frequency and type should align with risk and criticality.
  • Full simulations validate procedures, resources, and personnel.
  • Outdated plans are ineffective plans.

Memory trick: BCP: Be Current, Please!

More Domain 4: Information Systems Operations and Business Resilience questions