What Should an IS Auditor Review When BCP Misses Extended System Outages?
Which of the following is MOST important for an IS auditor to review when an audit identifies that the business continuity plan (BCP) does not address scenarios involving extended system outages?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the distinction between organizational continuity and IT-focused recovery, with the common trap being the selection of high-level risk frameworks over targeted technical documentation.
This CISA question tests the functional boundary between Business Continuity Plans and Disaster Recovery Plans, establishing why the DRP must be reviewed when IT outage scenarios are omitted from broader continuity strategies.
Option D is frequently selected due to the auditor's instinct to start with enterprise-wide risk mapping, but it fails to address the immediate technical gap regarding system restoration procedures.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
When a Business Continuity Plan omits extended system outages, the IS auditor must first examine the Disaster Recovery Plan because it serves as the technical counterpart responsible for IT infrastructure restoration. ISACA guidance explicitly separates operational continuity from IT recovery, meaning gaps in system availability require verification of DRP controls and failover mechanisms. Reviewing the DRP ensures that the organization has documented escalation paths, recovery time objectives, and backup validation procedures tailored to prolonged technology failures.Why the Other Options Are Wrong
Option A focuses on quantifying financial impact, which is valuable but secondary to confirming whether actionable recovery steps actually exist. Option C examines past events, yet historical data cannot replace forward-looking procedural documentation required for compliance and readiness. Option D provides a strategic overview of organizational threats, but it lacks the granular, technology-specific directives needed to resolve a documented gap in system outage handling.Community Comment Notes
Several learners initially questioned whether the enterprise risk assessment should take precedence, noting that unaddressed scenarios typically signal a broader risk management oversight. Others correctly pointed out that the disaster recovery plan becomes particularly crucial since it "outlines specific protocols to recover IT systems after disruptive events." The consensus highlights that while high-level risk reviews matter, auditors must first validate the existence of targeted technical recovery procedures before escalating to strategic assessments.Exam Strategy
Always map audit findings to their closest operational document before expanding to strategic frameworks. For CISA, differentiate between process-oriented continuity plans and technology-focused recovery documents to select the most direct evidence.
Frequently Asked Questions
Why isn't the enterprise risk assessment the best choice here?
ERM provides a broad organizational view, but the auditor needs to immediately verify IT-specific recovery steps when system outages are missing from the BCP.
How do BCP and DRP differ in CISA exams?
BCP covers overall business operations and processes, while DRP focuses specifically on restoring IT infrastructure and data after a disruption.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →