Certified in Risk and Information Systems Control (CRISC) — Question 658
When a risk practitioner is determining a system's criticality, it is MOST helpful to review the associated:
Answer options
- A. process flow.
- B. business impact analysis (BIA).
- C. system architecture.
- D. service level agreement (SLA).
Correct answer: B
Explanation
The business impact analysis (BIA) is crucial for understanding the potential effects of system failures on business operations, making it the best choice for determining criticality. While process flow, system architecture, and service level agreements provide valuable information, they do not directly assess the business impact as effectively as a BIA does.