nerdexam
CompTIA

CAS-003 · Question #439

A Chief Information Security Officer (CISO) is developing a new BIA for the organization. The CISO wants to gather requirements to determine the appropriate RTO and RPO for the organization's ERP…

The correct answer is D. Business unit director. A BIA requires input from those who understand the business impact of system downtime, not just technical staff. The business unit director best understands operational dependencies and acceptable recovery windows for the ERP.

Risk Management

Question

A Chief Information Security Officer (CISO) is developing a new BIA for the organization. The CISO wants to gather requirements to determine the appropriate RTO and RPO for the organization's ERP. Which of the following should the CISO interview as MOST qualified to provide RTO/RPO metrics?

Options

  • AData custodian
  • BData owner
  • CSecurity analyst
  • DBusiness unit director
  • EChief Executive Officer (CEO)

How the community answered

(50 responses)
  • A
    2% (1)
  • C
    4% (2)
  • D
    94% (47)

Why each option

A BIA requires input from those who understand the business impact of system downtime, not just technical staff. The business unit director best understands operational dependencies and acceptable recovery windows for the ERP.

AData custodian

A data custodian is a technical role responsible for implementing data controls, not defining business recovery requirements.

BData owner

A data owner focuses on data classification and access policy, not on quantifying the operational impact of system unavailability.

CSecurity analyst

A security analyst assesses threats and vulnerabilities but lacks the business context to define acceptable downtime or data loss thresholds.

DBusiness unit directorCorrect

The business unit director is the most qualified because they understand operational workflows, revenue impact, and tolerance for downtime and data loss. RTO and RPO are business-driven metrics that reflect how quickly operations must be restored and how much data loss is acceptable - decisions that belong to the business, not IT. Technical staff can implement what the business requires, but cannot define what the business needs.

EChief Executive Officer (CEO)

The CEO operates at a strategic level and delegates operational recovery requirements to the business unit leaders who manage day-to-day processes.

Concept tested: Identifying appropriate stakeholders for BIA RTO/RPO

Source: https://csrc.nist.gov/publications/detail/sp/800-34/rev-1/final

Topics

#BIA#RTO RPO#ERP#business continuity

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice