Certified Information Security Manager (CISM) — Question 963
When an organization experiences a disruptive event, the business continuity plan (BCP) should be triggered PRIMARILY based on:
Answer options
- A. expected duration of outage.
- B. the root cause of the event.
- C. type of security incident.
- D. management direction.
Correct answer: A
Explanation
The correct answer is A, as the expected duration of the outage directly influences the organization's ability to resume operations effectively. The root cause of the event (B), type of security incident (C), and management direction (D) may inform response actions, but the critical factor for triggering the BCP is how long the disruption is anticipated to last.