An IS auditor learns that an organization's business continuity plan (BCP) has not been updated in the last 18 months and that the organization recently closed a production plant. Which of the following is the auditor's BEST course of action?
A.
Assess the risk to operations from the closing of the plant.
B.
Determine whether the business impact analysis (BIA) is current with the organization's structure and context.
C.
Perform testing to determine the impact to the recovery time objective (RTO).
D.
Determine the types of technologies used at the plant and how they may affect the BCP.
Updating the BCP is crucial for ensuring that the organization can effectively respond to disruptions and maintain business operations. However, before addressing the BCP directly, the auditor should first assess whether the business impact analysis (BIA) is up to date. The BIA identifies critical business functions, dependencies, and potential impacts of disruptions, which forms the foundation for the BCP. Given that the organization recently closed a production plant, it's important to understand how this change impacts the organization's structure and operations. Therefore, verifying the currency and accuracy of the BIA is the initial step in assessing the organization's readiness to address the closure of the plant and any other potential disruptions.
upvoted 1 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Swallows
1 month, 2 weeks ago