Certified Information Security Manager (CISM) — Question 770
Which of the following is the MOST important reason to conduct interviews as part of the business impact analysis (BIA) process?
Answer options
- A. To facilitate a qualitative risk assessment following the BIA
- B. To obtain input from as many relevant stakeholders as possible
- C. To ensure the stakeholders providing input own the related risk
- D. To increase awareness of information security among key stakeholders
Correct answer: B
Explanation
The correct answer is B because gathering input from a wide range of relevant stakeholders ensures that the BIA reflects diverse perspectives and critical insights. While the other options have value, they are secondary to the necessity of comprehensive stakeholder input, which is fundamental for an effective BIA.