Which IS Auditor Concern Takes Priority in BCP Reviews?
Which of the following would be an IS auditor's GREATEST concern when reviewing the organization's business continuity plan (BCP)?
Community Votes
80% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests your ability to prioritize foundational BCP architecture over operational testing metrics, highlighting the common trap of confusing exercise timing with core recovery planning gaps.
An IS auditor’s greatest concern when reviewing a BCP is missing process and application dependencies, as they dictate successful recovery sequencing. Community consensus confirms that without these mappings, recovery objectives become unachievable regardless of exercise metrics.
Candidates often choose D, assuming tabletop exercise duration exceeding RTO is the top risk, but auditors prioritize structural completeness—specifically dependency mapping—because flawed sequences invalidate all recovery targets.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
An IS auditor prioritizes foundational plan architecture over operational metrics when evaluating a business continuity plan. Without explicit process and application dependencies, recovery teams cannot restore systems in the correct sequence, leading to cascading failures even if hardware is available. As noted in community feedback, dependency mapping is a non-negotiable element of a viable BCP because it directly dictates whether critical functions can actually resume.Why the Other Options Are Wrong
Option B incorrectly compares exercise duration to RPO, which measures data loss tolerance rather than response speed, making the comparison logically invalid. Option C is incorrect because RPO and RTO naturally differ by design; RPO addresses data volume while RTO addresses time, so expecting identical values misunderstands both metrics. Option D suggests that tabletop exercises exceeding RTO is the top concern, but exercises are controlled simulations that can be shortened or split, whereas missing dependencies represent a permanent structural flaw that cannot be easily fixed.Community Comment Notes
High-voted comments [1], [3], and [4] consistently validate that dependency mapping is the primary audit focus, emphasizing that a BCP lacking these relationships fails its core purpose. Contributors correctly point out that simulation timing issues are administrative adjustments, while architectural gaps require immediate remediation. The consensus aligns with ISACA’s emphasis on validating recovery sequences before assessing drill performance.Official Reference
Exam Strategy
Always evaluate BCP options through the lens of audit prioritization: structural integrity and data/process mapping trump execution metrics. When in doubt between a missing dependency and a timing discrepancy, choose the dependency gap.
Frequently Asked Questions
Why isn't exercise duration exceeding RTO the greatest concern?
Tabletop exercises are training tools, not actual disaster responses, so their length can be adjusted without impacting real recovery capabilities. Auditors prioritize structural gaps like missing dependencies first.
How do RPO and RTO relate to BCP dependency mapping?
RPO and RTO define acceptable data loss and downtime limits, but they cannot be met if critical application relationships are unmapped during restoration.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →