CISA · Question #425
Which of the following should be of MOST concern to an IS auditor reviewing an organization's business impact analysis (BIA)?
The correct answer is D. A risk assessment was not conducted prior to completing the BIA. A BIA identifies which business processes and systems are critical and estimates the impact of their disruption - but without a prior risk assessment, the BIA lacks the foundation needed to understand which threats and vulnerabilities actually exist, making the entire analysis in
Question
Which of the following should be of MOST concern to an IS auditor reviewing an organization’s business impact analysis (BIA)?
Options
- AThe BIA was not signed off by executive management
- BSystem criticality information was only provided by the IT manager
- CA questionnaire was used to gather information as opposed to in-person interviews
- DA risk assessment was not conducted prior to completing the BIA
How the community answered
(46 responses)- A26% (12)
- B13% (6)
- C7% (3)
- D54% (25)
Explanation
A BIA identifies which business processes and systems are critical and estimates the impact of their disruption - but without a prior risk assessment, the BIA lacks the foundation needed to understand which threats and vulnerabilities actually exist, making the entire analysis incomplete and potentially misleading.
Why the distractors are wrong:
- A - Executive sign-off is important for governance, but its absence is a procedural gap, not a fundamental flaw in the BIA's analytical validity.
- B - Input from only the IT manager is a limitation (business owners should also contribute), but it's a quality concern, not a structural dependency that invalidates the BIA's purpose.
- C - Questionnaires are a legitimate and commonly accepted data-gathering method for BIAs; the methodology choice alone is not a significant concern.
Memory tip: Think of the BIA and risk assessment as a two-step sequence - risk assessment first, BIA second. The risk assessment tells you what could go wrong; the BIA tells you what happens to the business if it does. Skipping step one means step two is built on assumptions rather than evidence, which is the auditor's red flag.
Topics
Community Discussion
No community discussion yet for this question.