What Should an IS Auditor Review When BCP Misses Extended System Outages?

Business Continuity & Disaster Recovery
Answer Correct answer: B — evaluate the disaster recovery plan to confirm it contains adequate IT system restoration procedures for prolonged outages.

Which of the following is MOST important for an IS auditor to review when an audit identifies that the business continuity plan (BCP) does not address scenarios involving extended system outages?

  1. Risk rating of business non-continuity
  2. Disaster recovery plan (DRP) Correct Answer
  3. Historical incidents resulting in extended system outages
  4. Enterprise risk assessment

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the distinction between organizational continuity and IT-focused recovery, with the common trap being the selection of high-level risk frameworks over targeted technical documentation.

This CISA question tests the functional boundary between Business Continuity Plans and Disaster Recovery Plans, establishing why the DRP must be reviewed when IT outage scenarios are omitted from broader continuity strategies.

Option D is frequently selected due to the auditor's instinct to start with enterprise-wide risk mapping, but it fails to address the immediate technical gap regarding system restoration procedures.

Community Discussion (7 comments)

Sibsankar 👍 2
let's reconsider the question. If the business continuity plan (BCP) does not address scenarios involving extended system outages, it implies a potential gap in risk management. In such a situation, reviewing the risk rating of business non-continuity (Option A) would indeed be crucial.
Swallows 👍 2 Selected: B
A disaster recovery plan (DRP) typically focuses on restoring IT infrastructure and systems after a disruption. If the BCP does not address scenarios involving extended system outages, it suggests a gap in continuity planning, particularly regarding IT systems. Reviewing the DRP is crucial to determine if it adequately addresses extended system outages and provides the necessary procedures and resources to recover IT systems within an acceptable timeframe.
KAP2HURUF 👍 2 Selected: B
Enterprise risk assessment: An enterprise risk assessment is a broad review of all potential risks facing an organization. While it is important for understanding the overall risk landscape, it is not as specific as the DRP in addressing the immediate concern of extended system outages.
nwachinanulogu 👍 3
I think D. Enterprise Risk Assessment. Generally, a DRP is a subset of the BCP, so if the extended system outages were not addressed by the BCP, I would think that those scenarios have not been considered as a valid business risk. Hence, the IS Auditor might need to review the Enterprise risk assessment to investigate further.
Zirgelis1 👍 1
Why not A?
MJORGER 👍 2
B. Disaster recovery plan (DRP): (DRP) becomes particularly crucial. The DRP outlines specific procedures and protocols to recover IT systems and infrastructure after a disruptive event, such as extended system outages. Therefore, reviewing the DRP is essential to ensure that there are adequate strategies and measures in place to address such scenarios and minimize the impact on business operations.
Sibsankar 👍 2
May be B is right

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

When a Business Continuity Plan omits extended system outages, the IS auditor must first examine the Disaster Recovery Plan because it serves as the technical counterpart responsible for IT infrastructure restoration. ISACA guidance explicitly separates operational continuity from IT recovery, meaning gaps in system availability require verification of DRP controls and failover mechanisms. Reviewing the DRP ensures that the organization has documented escalation paths, recovery time objectives, and backup validation procedures tailored to prolonged technology failures.

Why the Other Options Are Wrong

Option A focuses on quantifying financial impact, which is valuable but secondary to confirming whether actionable recovery steps actually exist. Option C examines past events, yet historical data cannot replace forward-looking procedural documentation required for compliance and readiness. Option D provides a strategic overview of organizational threats, but it lacks the granular, technology-specific directives needed to resolve a documented gap in system outage handling.

Community Comment Notes

Several learners initially questioned whether the enterprise risk assessment should take precedence, noting that unaddressed scenarios typically signal a broader risk management oversight. Others correctly pointed out that the disaster recovery plan becomes particularly crucial since it "outlines specific protocols to recover IT systems after disruptive events." The consensus highlights that while high-level risk reviews matter, auditors must first validate the existence of targeted technical recovery procedures before escalating to strategic assessments.

Exam Strategy

Always map audit findings to their closest operational document before expanding to strategic frameworks. For CISA, differentiate between process-oriented continuity plans and technology-focused recovery documents to select the most direct evidence.

Frequently Asked Questions

Why isn't the enterprise risk assessment the best choice here?

ERM provides a broad organizational view, but the auditor needs to immediately verify IT-specific recovery steps when system outages are missing from the BCP.

How do BCP and DRP differ in CISA exams?

BCP covers overall business operations and processes, while DRP focuses specifically on restoring IT infrastructure and data after a disruption.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide