QuestionQ317

Information Security Risk Management

Which of the following is the GREATEST concern for an information security manager when an annual audit finds that the organization's business continuity plan (BCP) has not been reviewed or updated for more than a year?

  • A The organization may suffer reputational damage for not following industry best practices.
  • B The audit finding may impact the overall risk rating of the organization.
  • C An outdated BCP may result in less efficient recovery if an actual incident occurs.
  • D The lack of updates to the BCP may result in noncompliance with internal policies.
Explanation

An obsolete BCP can omit current systems, business requirements, dependencies, roles, and recovery procedures, causing recovery to be less effective or slower during an actual incident. The central purpose of continuity planning is to sustain and restore critical operations; audit, policy, and reputational effects are consequential but secondary. NIST guidance calls for reviewing contingency plans at least annually and revising them for organizational or system changes.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!