Certified Information Systems Auditor (CISA) — Question 578
An organization is permanently transitioning from onsite to fully remote business operations. When should the existing business impact analysis (BIA) be reviewed?
Answer options
- A. At least one year after the transition
- B. As soon as the new operating model is in place
- C. During the next scheduled review
- D. As soon as the decision about the transition is announced
Correct answer: D
Explanation
The correct answer is D, as reviewing the BIA promptly after the transition decision ensures that any potential impacts are assessed in the context of the new operational model. Options A, B, and C delay the review process, which could lead to outdated analyses that do not reflect the current business environment.