Which IS Auditor Concern Takes Priority in BCP Reviews?

Business Continuity & Disaster Recovery
Answer Correct answer: A — Map all process and application dependencies into the business continuity plan to ensure proper recovery sequencing and eliminate audit findings.

Which of the following would be an IS auditor's GREATEST concern when reviewing the organization's business continuity plan (BCP)?

  1. The recovery plan does not contain the process and application dependencies. Correct Answer
  2. The duration of tabletop exercises is longer than the recovery point objective (RPO).
  3. The recovery point objective (RPO) and recovery time objective (RTO) are not the same.
  4. The duration of tabletop exercises is longer than the recovery time objective (RTO).

Community Votes

A
80%
D
20%

80% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests your ability to prioritize foundational BCP architecture over operational testing metrics, highlighting the common trap of confusing exercise timing with core recovery planning gaps.

An IS auditor’s greatest concern when reviewing a BCP is missing process and application dependencies, as they dictate successful recovery sequencing. Community consensus confirms that without these mappings, recovery objectives become unachievable regardless of exercise metrics.

Candidates often choose D, assuming tabletop exercise duration exceeding RTO is the top risk, but auditors prioritize structural completeness—specifically dependency mapping—because flawed sequences invalidate all recovery targets.

Community Discussion (4 comments)

RS66 👍 1 Selected: A
A. The recovery plan does not contain the process and application dependencies.
Swallows 👍 1 Selected: D
Tabletop exercises are simulations to check response plans and procedures in the event of a disaster or failure, and to ensure that relevant parties are prepared in advance. If the time required for the exercise is longer than the RTO, there may not be enough time to restore systems and services as planned in the event of an actual disaster. This has a significant impact on the reliability and effectiveness of the business continuity plan.
KAP2HURUF 👍 1 Selected: A
A business continuity plan (BCP) is a document that outlines how an organization will continue its critical functions in the event of a disruption or disaster. A BCP should include the following elements1: Business impact analysis: This is the process of identifying and prioritizing the key business processes and assets that are essential for the organization's survival and recovery.
Rachy 👍 2 Selected: A
A is the answer here

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

An IS auditor prioritizes foundational plan architecture over operational metrics when evaluating a business continuity plan. Without explicit process and application dependencies, recovery teams cannot restore systems in the correct sequence, leading to cascading failures even if hardware is available. As noted in community feedback, dependency mapping is a non-negotiable element of a viable BCP because it directly dictates whether critical functions can actually resume.

Why the Other Options Are Wrong

Option B incorrectly compares exercise duration to RPO, which measures data loss tolerance rather than response speed, making the comparison logically invalid. Option C is incorrect because RPO and RTO naturally differ by design; RPO addresses data volume while RTO addresses time, so expecting identical values misunderstands both metrics. Option D suggests that tabletop exercises exceeding RTO is the top concern, but exercises are controlled simulations that can be shortened or split, whereas missing dependencies represent a permanent structural flaw that cannot be easily fixed.

Community Comment Notes

High-voted comments [1], [3], and [4] consistently validate that dependency mapping is the primary audit focus, emphasizing that a BCP lacking these relationships fails its core purpose. Contributors correctly point out that simulation timing issues are administrative adjustments, while architectural gaps require immediate remediation. The consensus aligns with ISACA’s emphasis on validating recovery sequences before assessing drill performance.

Official Reference

Exam Strategy

Always evaluate BCP options through the lens of audit prioritization: structural integrity and data/process mapping trump execution metrics. When in doubt between a missing dependency and a timing discrepancy, choose the dependency gap.

Frequently Asked Questions

Why isn't exercise duration exceeding RTO the greatest concern?

Tabletop exercises are training tools, not actual disaster responses, so their length can be adjusted without impacting real recovery capabilities. Auditors prioritize structural gaps like missing dependencies first.

How do RPO and RTO relate to BCP dependency mapping?

RPO and RTO define acceptable data loss and downtime limits, but they cannot be met if critical application relationships are unmapped during restoration.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide