nerdexam
Isaca

CISM · Question #965

Which of the following is the PRIMARY reason to perform a business impact analysis (BIA)?

The correct answer is D. Prioritizing critical processes. A Business Impact Analysis (BIA) exists fundamentally to identify and prioritize which business processes are most critical to organizational survival - without this ranking, no recovery planning can be properly scoped or funded. Why the distractors are wrong: A (Risk…

Submitted by manish99· Apr 18, 2026Information Security Risk Management

Question

Which of the following is the PRIMARY reason to perform a business impact analysis (BIA)?

Options

  • ADetermining risk mitigation options
  • BDetermining information sensitivity
  • CEstablishing recovery point objectives (RPOs)
  • DPrioritizing critical processes

How the community answered

(22 responses)
  • A
    5% (1)
  • D
    95% (21)

Explanation

A Business Impact Analysis (BIA) exists fundamentally to identify and prioritize which business processes are most critical to organizational survival - without this ranking, no recovery planning can be properly scoped or funded.

Why the distractors are wrong:

  • A (Risk mitigation options) - That's the domain of risk assessments and risk treatment plans, which come after a BIA informs you what's worth protecting.
  • B (Information sensitivity) - Data classification is a separate exercise, typically part of an information security program, not a BIA output.
  • C (Establishing RPOs) - RPOs result from a BIA; they're a downstream artifact, not the primary purpose. The BIA first tells you which processes matter, then RPOs/RTOs are defined for those processes.

Memory tip: Think of BIA = "Business Importance Assessment." Before you can recover anything, you must know what's important - that's prioritization. Everything else (RPOs, mitigation strategies) flows from that foundation.

Topics

#Business Impact Analysis (BIA)#Critical Process Prioritization#Business Continuity Planning#Risk Assessment

Community Discussion

No community discussion yet for this question.

Full CISM Practice