A services firm's business continuity plan documents how IT systems will be recovered at an alternate data centre but says nothing about how staff will keep serving customers if the head office is inaccessible. An information security manager reviewing the plan judges this its most serious weakness. Why is this gap significant for business continuity?
- AIt overlooks that continuity depends on people, premises and processes continuing to function, not only on technology being restored. Correct
- BIt means the recovery point objective for each system has not been calculated, so data loss during a disruption cannot be bounded.
- CIt indicates the alternate data centre has not been tested, so there is no assurance the technical failover will work when invoked.
- DIt shows the plan was written by IT rather than the business, so its recovery priorities will not match the board's stated risk appetite.
Why A is correct: Correct because business continuity must sustain the whole operating model, so a plan that addresses only IT recovery cannot keep critical services running when staff and premises are also affected.
Why B is wrong: Tempting because data loss is a real continuity concern, but the gap described is about staff and premises arrangements, not about whether recovery point objectives were set.
Why C is wrong: Tempting because untested failover is a valid risk, but the weakness here is the absence of workforce and premises continuity, not the testing state of the data centre.
Why D is wrong: Tempting because authorship can skew priorities, but the core flaw is the missing people-and-premises dimension itself, which would matter regardless of who drafted the plan.