nerdexam
Isaca

CISM · Question #664

Which of the following should an information security manager do FIRST when developing an organization's disaster recovery plan (DRP)?

The correct answer is D. Perform a business impact analysis (BIA). The first step in developing a disaster recovery plan is performing a business impact analysis (BIA) to identify critical business functions, recovery priorities, and the potential impact of disruptions, which informs the DRP’s scope and design.

Submitted by kevin_r· Apr 18, 2026Information Security Program Development and Management

Question

Which of the following should an information security manager do FIRST when developing an organization’s disaster recovery plan (DRP)?

Options

  • AConduct a risk assessment
  • BIdentify business requirements
  • CDocument disaster recovery procedures
  • DPerform a business impact analysis (BIA)

How the community answered

(36 responses)
  • A
    6% (2)
  • B
    3% (1)
  • C
    3% (1)
  • D
    89% (32)

Explanation

The first step in developing a disaster recovery plan is performing a business impact analysis (BIA) to identify critical business functions, recovery priorities, and the potential impact of disruptions, which informs the DRP’s scope and design.

Topics

#Disaster Recovery Planning#Business Impact Analysis (BIA)#Business Continuity Management (BCM)#DRP Development

Community Discussion

No community discussion yet for this question.

Full CISM Practice