Certified in Risk and Information Systems Control (CRISC) — Question 362
A core data center went offline abruptly for several hours, affecting many transactions across multiple locations. Which of the following would provide the MOST useful information to determine mitigating controls?
Answer options
- A. Root cause analysis
- B. Risk assessment
- C. Business impact analysis (BIA)
- D. Forensic analysis
Correct answer: A
Explanation
The correct answer is A, Root cause analysis, as it helps identify the underlying reasons for the outage, enabling the organization to implement effective mitigating controls. The other options, while useful in their own right, do not directly address the need to understand the cause of the issue to prevent future occurrences.