According to lIA guidance on IT, which of the following plans would pair the identification of critical business processes with recovery time objectives?
A.
The business continuity management charter.
B.
The business continuity risk assessment plan.
C.
The business Impact analysis plan
D.
The business case for business continuity planning
The Business Impact Analysis (BIA) plan is a key component of business continuity planning that identifies critical business processes and determines their Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).
Correct Answer (C - Business Impact Analysis Plan)
The BIA is a systematic process that identifies essential functions, assesses potential disruptions, and determines the recovery time requirements to ensure business continuity.
The Recovery Time Objective (RTO) defines the maximum acceptable downtime for critical business functions.
The Recovery Point Objective (RPO) identifies how much data loss is tolerable.
According to the IIA Global Technology Audit Guide (GTAG) 10: Business Continuity Management, a BIA is essential for assessing the financial, operational, and reputational impact of disruptions.
Why Other Options Are Incorrect:
Option A (Business Continuity Management Charter):
A charter defines the governance, responsibilities, and overall framework of business continuity but does not focus on RTOs or critical business processes.
Option B (Business Continuity Risk Assessment Plan):
A risk assessment identifies threats and vulnerabilities but does not define recovery time objectives.
While risk assessments inform the BIA, they do not replace it.
Option D (Business Case for Business Continuity Planning):
A business case justifies investment in continuity planning but does not map business processes to RTOs.
GTAG 10: Business Continuity Management – Defines BIA as the process for identifying critical business functions and their RTOs.
IIA Practice Guide: Auditing Business Continuity – Emphasizes the role of BIA in business resilience.
Step-by-Step Explanation:IIA References for Validation:Thus, the Business Impact Analysis (BIA) Plan (C) is the correct answer because it pairs critical business processes with recovery time objectives.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit