CISM · Question #915
A business impact analysis (BIA) should be periodically executed PRIMARILY to:
The correct answer is C. analyze the importance of assets. A Business Impact Analysis (BIA) is specifically designed to identify and evaluate the criticality of business assets, processes, and resources - determining what matters most to the organization and what the consequences would be if those assets were disrupted. Option C is…
Question
A business impact analysis (BIA) should be periodically executed PRIMARILY to:
Options
- Avalidate vulnerabilities on environmental changes.
- Bcheck compliance with regulations.
- Canalyze the importance of assets.
- Dverify the effectiveness of controls.
How the community answered
(37 responses)- A3% (1)
- C92% (34)
- D5% (2)
Explanation
A Business Impact Analysis (BIA) is specifically designed to identify and evaluate the criticality of business assets, processes, and resources - determining what matters most to the organization and what the consequences would be if those assets were disrupted. Option C is correct because the BIA's primary output is a prioritized understanding of asset importance, including recovery time objectives (RTOs) and recovery point objectives (RPOs).
Why the distractors are wrong:
- A (validate vulnerabilities) - Vulnerability assessment is a separate security activity, not a BIA concern.
- B (check compliance) - Compliance audits serve this purpose; a BIA is driven by business continuity needs, not regulatory checklists.
- D (verify control effectiveness) - That's the role of control testing or audits (e.g., security assessments), not a BIA.
Memory tip: Think of BIA as "Business Importance Analysis" - its core job is always to rank what matters most to keeping the business alive, so you know where to focus recovery efforts.
Topics
Community Discussion
No community discussion yet for this question.