nerdexam
Isaca

CISA · Question #80

An organization's business continuity plan (BCP) should be:

The correct answer is A. updated based on changes to personnel and environments. An organization's business continuity plan (BCP) must be regularly updated to reflect any changes in personnel, technology, processes, or the operating environment to ensure its continued relevance and effectiveness.

Submitted by khalil_dz· Apr 18, 2026Information Systems Operations and Business Resilience

Question

An organization’s business continuity plan (BCP) should be:

Options

  • Aupdated based on changes to personnel and environments
  • Btested whenever new applications are implemented
  • Cupdated before an independent audit review
  • Dtested after an intrusion attempt into the organization's hot site

How the community answered

(43 responses)
  • A
    86% (37)
  • B
    7% (3)
  • C
    2% (1)
  • D
    5% (2)

Why each option

An organization's business continuity plan (BCP) must be regularly updated to reflect any changes in personnel, technology, processes, or the operating environment to ensure its continued relevance and effectiveness.

Aupdated based on changes to personnel and environmentsCorrect

A BCP relies on accurate information about an organization's resources, personnel, processes, and external dependencies. Any changes to these elements, such as staffing changes, new technologies, or facility relocations, can render parts of the BCP obsolete, necessitating immediate updates to maintain its viability for effective recovery.

Btested whenever new applications are implemented

While new applications might warrant a review or specific testing, the BCP as a whole is typically tested on a scheduled basis, not *whenever* new applications are implemented.

Cupdated before an independent audit review

The BCP should be updated based on operational changes, not primarily in anticipation of an independent audit, although an audit might identify areas needing updates.

Dtested after an intrusion attempt into the organization's hot site

Testing a BCP after an intrusion attempt is reactive; BCPs should be tested proactively and regularly to ensure preparedness, rather than only in response to specific security incidents.

Concept tested: Business Continuity Plan (BCP) maintenance

Source: https://csrc.nist.gov/publications/detail/sp/800-34/rev-1/final

Topics

#Business Continuity Plan (BCP)#BCP Maintenance#BCP Updating#Organizational Changes

Community Discussion

No community discussion yet for this question.

Full CISA Practice