CISM · Question #385
An event occurred that resulted in the activation of the business continuity plan (BCP). All employees were notified during the event, and they followed the plan. However, two major suppliers missed d
The correct answer is B. Perform testing of the BCP communication plan.. The root cause of the failure was that key external stakeholders (suppliers) were not notified during the event, indicating a gap in the BCP's communication plan. Testing the BCP communication plan would surface this gap before a real event, allowing the organization to update no
Question
An event occurred that resulted in the activation of the business continuity plan (BCP). All employees were notified during the event, and they followed the plan. However, two major suppliers missed deadlines because they were not aware of the disruption. What is the BEST way to prevent a similar situation in the future?
Options
- AEnsure service level agreements (SLAs) with suppliers are enforced.
- BPerform testing of the BCP communication plan.
- CConduct a penetration test.
- DProvide suppliers with access to the BCP document.
How the community answered
(45 responses)- A13% (6)
- B78% (35)
- C2% (1)
- D7% (3)
Explanation
The root cause of the failure was that key external stakeholders (suppliers) were not notified during the event, indicating a gap in the BCP's communication plan. Testing the BCP communication plan would surface this gap before a real event, allowing the organization to update notification lists, procedures, and escalation paths to include critical third parties. Enforcing SLAs (A) addresses supplier accountability after a breach occurs, not the communication failure. A penetration test (C) is a cybersecurity assessment unrelated to BCP communication. Giving suppliers the BCP document (D) might partially help but does not ensure they are actively integrated into the notification and communication workflow.
Topics
Community Discussion
No community discussion yet for this question.