nerdexam
Isaca

CISM · Question #915

A business impact analysis (BIA) should be periodically executed PRIMARILY to:

The correct answer is C. analyze the importance of assets. A Business Impact Analysis (BIA) is specifically designed to identify and evaluate the criticality of business assets, processes, and resources - determining what matters most to the organization and what the consequences would be if those assets were disrupted. Option C is…

Submitted by omar99· Apr 18, 2026Information Security Risk Management

Question

A business impact analysis (BIA) should be periodically executed PRIMARILY to:

Options

  • Avalidate vulnerabilities on environmental changes.
  • Bcheck compliance with regulations.
  • Canalyze the importance of assets.
  • Dverify the effectiveness of controls.

How the community answered

(37 responses)
  • A
    3% (1)
  • C
    92% (34)
  • D
    5% (2)

Explanation

A Business Impact Analysis (BIA) is specifically designed to identify and evaluate the criticality of business assets, processes, and resources - determining what matters most to the organization and what the consequences would be if those assets were disrupted. Option C is correct because the BIA's primary output is a prioritized understanding of asset importance, including recovery time objectives (RTOs) and recovery point objectives (RPOs).

Why the distractors are wrong:

  • A (validate vulnerabilities) - Vulnerability assessment is a separate security activity, not a BIA concern.
  • B (check compliance) - Compliance audits serve this purpose; a BIA is driven by business continuity needs, not regulatory checklists.
  • D (verify control effectiveness) - That's the role of control testing or audits (e.g., security assessments), not a BIA.

Memory tip: Think of BIA as "Business Importance Analysis" - its core job is always to rank what matters most to keeping the business alive, so you know where to focus recovery efforts.

Topics

#Business Impact Analysis#Asset Criticality#Business Continuity Planning

Community Discussion

No community discussion yet for this question.

Full CISM Practice