nerdexam
Isaca

CRISC · Question #498

A business impact analysis (BIA) enables an organization to determine appropriate IT risk mitigation actions by:

The correct answer is C. identifying IT assets that support key business processes. A Business Impact Analysis (BIA) enables an organization to determine appropriate IT risk mitigation actions by identifying the critical IT assets that support essential business processes.

Submitted by miguelv· Apr 18, 2026IT Risk Assessment

Question

A business impact analysis (BIA) enables an organization to determine appropriate IT risk mitigation actions by:

Options

  • Avalidating whether critical IT risk has been addressed.
  • Bassigning accountability for IT risk to business functions.
  • Cidentifying IT assets that support key business processes.
  • Ddefining the requirements for an IT risk-aware culture

How the community answered

(36 responses)
  • A
    3% (1)
  • C
    94% (34)
  • D
    3% (1)

Why each option

A Business Impact Analysis (BIA) enables an organization to determine appropriate IT risk mitigation actions by identifying the critical IT assets that support essential business processes.

Avalidating whether critical IT risk has been addressed.

A BIA helps prioritize *what* IT risks to mitigate based on business impact, but it's not primarily for validating that critical IT risk has already been addressed.

Bassigning accountability for IT risk to business functions.

Assigning accountability for IT risk to business functions is part of governance, which is informed by a BIA but not its direct function in determining mitigation actions.

Cidentifying IT assets that support key business processes.Correct

The BIA identifies and prioritizes an organization's critical business processes, determines their recovery time objectives (RTOs) and recovery point objectives (RPOs), and consequently identifies the underlying IT systems and assets crucial for their support. This prioritization guides where IT risk mitigation resources should be focused.

Ddefining the requirements for an IT risk-aware culture

While a BIA contributes to an understanding of IT's importance, its direct role is not defining the requirements for an IT risk-aware culture, but rather identifying critical assets and their recovery needs.

Concept tested: Role of Business Impact Analysis (BIA)

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-34r1.pdf

Topics

#Business Impact Analysis (BIA)#IT Risk Mitigation#Critical IT Assets#Business Processes

Community Discussion

No community discussion yet for this question.

Full CRISC Practice