Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 1 discussion

Actual exam question from Isaca's CISA
Question #: 1
Topic #: 1
[All CISA Questions]

Which of the following should be of GREATEST concern to an IS auditor reviewing an organization's business continuity plan (BCP)?

  • A. The BCP has not been tested since it was first issued.
  • B. The BCP is not version-controlled.
  • C. The BCP's contact information needs to be updated.
  • D. The BCP has not been approved by senior management.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
GenPatton
Highly Voted 1 year, 1 month ago
Selected Answer: A
I went to the CISA review manual to solve this, and the main concern should be the lack of testing. First: Senior management create a "business continuity policy" (Ref: Review Manual 27th edition 4.15.4). In general, senior management makes policies, and the plebs below make plans and procedures. Therefore a business continuity plan is not necessarily senior management approved. Furthermore there is a passage in the review manual (4.15.11) regarding auditing business continuity. The passage does not really mention senior management, but it does mention plan testing and obtaining historical results of tests during an audit.
upvoted 9 times
...
AbdulQadirKhan
Highly Voted 1 year, 1 month ago
Approval by Senior Management: The approval of the BCP by senior management is a fundamental step in ensuring that the BCP is considered a valid and authoritative document within the organization. Without senior management's buy-in and approval, it may not receive the necessary resources and attention it requires for effective implementation. While the other issues mentioned (A, B, and C) are important and should also be addressed, the lack of senior management approval can indicate a more significant problem with the BCP's overall effectiveness and organizational commitment to business continuity planning. This oversight may result in inadequate support, testing, or maintenance of the BCP, ultimately reducing its ability to ensure business continuity during disruptions.
upvoted 5 times
...
KAP2HURUF
Most Recent 1 month, 3 weeks ago
Selected Answer: A
This is because a BCP that has not been tested is unproven and may not be effective in an actual disaster or business interruption scenario. Testing is essential to identify gaps, ensure that all components of the plan work as intended, and that staff are familiar with their roles in the event of an incident. Without testing, there is no assurance that the BCP will function correctly, which poses a significant risk to the organization's ability to recover from an incident.
upvoted 1 times
Examtopicsn
1 month, 3 weeks ago
Please can anyone help me with contributor access ?
upvoted 1 times
...
...
scriptkiddie
4 months ago
Selected Answer: D
If no one declares the disaster, the BCP would not be invoked, making all other concerns less significant
upvoted 1 times
...
scriptkiddie
4 months ago
D. If no one declares the disaster, the BCP would not be invoked, making all other concerns less significant​​.
upvoted 1 times
...
a84n
6 months, 3 weeks ago
Selected Answer: D
Answer: D
upvoted 1 times
...
5b56aae
7 months, 1 week ago
Selected Answer: A
Testing is the best way to assure the BCP works as intended
upvoted 1 times
...
Olatoyimika
7 months, 2 weeks ago
Answer is D
upvoted 1 times
...
fori12
8 months ago
Selected Answer: A
Note: Assessing the results and the value of the BCP and the DRP tests is an important part of the IS auditor’s responsibility.
upvoted 1 times
...
FAGFUR
12 months ago
Selected Answer: О
Answer A
upvoted 1 times
...
isaphiltrick
1 year, 2 months ago
I meant "BCPs" in my previous post.
upvoted 1 times
...
isaphiltrick
1 year, 2 months ago
I think those of you who selected A assume that there was a long period of time from inception to current. However, the question never said anything about time. How do we know that the document hadn't been tested because it was just created today or yesterday? Therefore, the answer is D --> BIAs must always have senior management approval for it to be valid.
upvoted 2 times
...
minajahan
1 year, 3 months ago
Selected Answer: D
Approval is important
upvoted 1 times
...
assum84
1 year, 3 months ago
Selected Answer: A
Not testing your BCP is the greatest concern, even if approved by the management.
upvoted 3 times
...
frisbg
1 year, 5 months ago
Selected Answer: A
As business owners should participate in BCP their approval is not needed at this point. Only after first test and RPO/RTO is met senior management can finalize the plans or it may not even needed as they are already part of BCP process. But testing is first and only vital point after BCP is finished
upvoted 2 times
...
saado9
1 year, 6 months ago
D. Approval is more important, if not approved then no need for testing in the first place.
upvoted 1 times
...
SBD600
1 year, 6 months ago
Selected Answer: A
answer is a
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...