nerdexam
CompTIA

CAS-003 · Question #36

An organization is preparing to develop a business continuity plan. The organization is required to meet regulatory requirements relating to confidentiality and availability, which are well-defined…

The correct answer is B. Gap assessment. The organization is building a BCP and management has acknowledged they do not fully understand the regulatory requirements for confidentiality and availability. A gap assessment (B) is the correct choice because it compares the current state of the organization's controls and…

Risk Management

Question

An organization is preparing to develop a business continuity plan. The organization is required to meet regulatory requirements relating to confidentiality and availability, which are well-defined. Management has expressed concern following initial meetings that the organization is not fully aware of the requirements associated with the regulations. Which of the following would be MOST appropriate for the project manager to solicit additional resources for during this phase of the project?

Options

  • AAfter-action reports
  • BGap assessment
  • CSecurity requirements traceability matrix
  • DBusiness impact assessment
  • ERisk analysis

How the community answered

(37 responses)
  • A
    5% (2)
  • B
    73% (27)
  • C
    3% (1)
  • D
    3% (1)
  • E
    16% (6)

Explanation

The organization is building a BCP and management has acknowledged they do not fully understand the regulatory requirements for confidentiality and availability. A gap assessment (B) is the correct choice because it compares the current state of the organization's controls and processes against the required regulatory standards, identifying what is missing or insufficient. This is precisely the right tool when the concern is 'we don't know what we're missing.' An after-action report (A) reviews past incidents and is not forward-looking for compliance. A Security Requirements Traceability Matrix (C) maps requirements to controls but presupposes you already know the requirements - which is the problem here. A Business Impact Assessment (D) measures the impact of disruptions but does not address regulatory comprehension. A Risk Analysis (E) evaluates threats and vulnerabilities, not regulatory compliance gaps.

Topics

#business continuity#gap assessment#regulatory compliance#BCP planning

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice