Certified Information Security Manager (CISM) — Question 55
The PRIMARY goal of conducting a business impact analysis (BIA) as part of an overall continuity planning process is to:
Answer options
- A. obtain the support of executive management.
- B. document the disaster recovery process.
- C. map the business process to supporting IT and other corporate resources.
- D. identify critical processes and the degree of reliance on support services.
Correct answer: D
Explanation
The correct answer is D, as the primary aim of a BIA is to identify critical processes and assess how much they depend on support services. Option A is incorrect since gaining executive support, while important, is not the primary goal of a BIA. Option B focuses on documenting recovery processes rather than assessing impacts, and option C relates to mapping resources, which is part of the analysis but not the main focus.