CISM · Question #111
The resilience requirements of an application are BEST determined by:
The correct answer is C. a business impact analysis (BIA).. The resilience requirements of an application are best determined by a business impact analysis (BIA), which identifies critical functions and their recovery time objectives (RTO) and recovery point objectives (RPO).
Question
The resilience requirements of an application are BEST determined by:
Options
- Aa cost-benefit analysis.
- Ba threat assessment.
- Ca business impact analysis (BIA).
- Da risk assessment.
How the community answered
(29 responses)- A3% (1)
- B7% (2)
- C90% (26)
Why each option
The resilience requirements of an application are best determined by a business impact analysis (BIA), which identifies critical functions and their recovery time objectives (RTO) and recovery point objectives (RPO).
A cost-benefit analysis helps justify investments but doesn't primarily define the technical requirements for resilience.
A threat assessment identifies potential threats but doesn't quantify the business impact or recovery objectives associated with application downtime or data loss.
A Business Impact Analysis (BIA) systematically identifies and evaluates the potential effects of business disruptions, determining the criticality of business processes and the applications that support them. This analysis directly quantifies the impact of downtime and data loss, thereby establishing the precise Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs) that define an application's resilience requirements.
A risk assessment identifies risks and their likelihood/impact, but a BIA specifically focuses on the impact of disruptions to business functions, which directly informs resilience requirements like RTO/RPO.
Concept tested: Business impact analysis for resilience
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-34r1.pdf
Topics
Community Discussion
No community discussion yet for this question.