nerdexam
Isaca

CISA · Question #425

Which of the following should be of MOST concern to an IS auditor reviewing an organization's business impact analysis (BIA)?

The correct answer is D. A risk assessment was not conducted prior to completing the BIA. A BIA identifies which business processes and systems are critical and estimates the impact of their disruption - but without a prior risk assessment, the BIA lacks the foundation needed to understand which threats and vulnerabilities actually exist, making the entire analysis in

Submitted by paula_co· Apr 18, 2026Information Systems Operations and Business Resilience

Question

Which of the following should be of MOST concern to an IS auditor reviewing an organization’s business impact analysis (BIA)?

Options

  • AThe BIA was not signed off by executive management
  • BSystem criticality information was only provided by the IT manager
  • CA questionnaire was used to gather information as opposed to in-person interviews
  • DA risk assessment was not conducted prior to completing the BIA

How the community answered

(46 responses)
  • A
    26% (12)
  • B
    13% (6)
  • C
    7% (3)
  • D
    54% (25)

Explanation

A BIA identifies which business processes and systems are critical and estimates the impact of their disruption - but without a prior risk assessment, the BIA lacks the foundation needed to understand which threats and vulnerabilities actually exist, making the entire analysis incomplete and potentially misleading.

Why the distractors are wrong:

  • A - Executive sign-off is important for governance, but its absence is a procedural gap, not a fundamental flaw in the BIA's analytical validity.
  • B - Input from only the IT manager is a limitation (business owners should also contribute), but it's a quality concern, not a structural dependency that invalidates the BIA's purpose.
  • C - Questionnaires are a legitimate and commonly accepted data-gathering method for BIAs; the methodology choice alone is not a significant concern.

Memory tip: Think of the BIA and risk assessment as a two-step sequence - risk assessment first, BIA second. The risk assessment tells you what could go wrong; the BIA tells you what happens to the business if it does. Skipping step one means step two is built on assumptions rather than evidence, which is the auditor's red flag.

Topics

#Business Impact Analysis (BIA)#Risk Assessment#Business Continuity Planning#IS Audit Concerns

Community Discussion

No community discussion yet for this question.

Full CISA Practice