I think the question is intentionally tricky here. There is no question that BIA is big part of the DR/BCP plan. But it's used to identify Criticality of systems and RTOs based on that. The question is particular is asking what will help to decide the "response". To know how to act you need to know what the threat is or what the risk is. So for me it's Risk assessment.
I usually agree with you , but IMO you're reading into question too much. :) BIA is used to determine what's critical for business to operate and costs associated with it (downtime costs and recovery costs such as activating BCP).
So BIA (C) should be the answer here.
Which of the following would BEST provide stakeholders with information to determine the appropriate RESPONSE to a disaster?
1. Vulnerability or threat by themselves cannot provide the complete picture of the risk (rules out A)
2. Impact or likelihood by themselves cannot provide the complete picture of the risk (rules out C)
3. B has no place in this discussion
Risk management output is "cost-effective response to risk such that residual risk is within acceptable limits". This cannot be done without the complete picture of the risk profile, only possible through risk assessment.
In summary, while both the BIA and risk assessment have their significance in disaster preparedness and response, the BIA is particularly useful for determining the appropriate response to a disaster by providing stakeholders with essential information about critical processes, recovery priorities, and resource allocation.
A business impact analysis (BIA) is used to identify an organization’s business processes, the interdependencies between processes, the resources required for process operation, and the impact on the organization if any business process is incapacitated for a time. A BIA is a cornerstone of a business continuity and disaster recovery
Gregory, Peter H.; Gregory, Peter H.. CISM Certified Information Security Manager Bundle (p. 124). McGraw Hill LLC. Kindle Edition.
This section is not available anymore. Please use the main Exam Page.CISM Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Dravidian
Highly Voted 2 years, 2 months agoAlexJacobson
1 year, 5 months agoSalilgen
1 year, 3 months agoBooict
Most Recent 10 months, 1 week agoafb4b17
1 year agoCISSPST
1 year, 9 months agorichck102
2 years agowello
2 years agoCarlLimps
2 years, 3 months agoCarlPTY07
2 years, 3 months agoaokisan
2 years, 6 months ago