CISM - Incident Management - Section 4.3

Develop and maintain a business continuity plan (BCP) to sustain critical operations during and after a disruption.

Develop and maintain a business continuity plan (BCP) that defines continuity of operations strategies to sustain critical business functions during and after a disruption. Evaluate recovery strategies - such as alternate sites, manual workarounds, and resource pre-positioning - against BIA-derived requirements to confirm they are viable.

Business continuityBCPContinuity of operationsRecovery strategies

Practice question for this objective

Free sampleIncident Managementmedium

A services firm's business continuity plan documents how IT systems will be recovered at an alternate data centre but says nothing about how staff will keep serving customers if the head office is inaccessible. An information security manager reviewing the plan judges this its most serious weakness. Why is this gap significant for business continuity?

  • AIt overlooks that continuity depends on people, premises and processes continuing to function, not only on technology being restored. Correct
  • BIt means the recovery point objective for each system has not been calculated, so data loss during a disruption cannot be bounded.
  • CIt indicates the alternate data centre has not been tested, so there is no assurance the technical failover will work when invoked.
  • DIt shows the plan was written by IT rather than the business, so its recovery priorities will not match the board's stated risk appetite.
A business continuity plan must sustain people, premises and processes during disruption, so addressing only IT recovery leaves critical operations unable to continue. Continuity of operations is broader than technology. If staff cannot reach a workplace and no alternate working or manual process is defined, restored systems alone will not keep critical services running. A plan that treats continuity as purely an IT recovery exercise fails the moment a disruption also affects people or premises.

Why A is correct: Correct because business continuity must sustain the whole operating model, so a plan that addresses only IT recovery cannot keep critical services running when staff and premises are also affected.

Why B is wrong: Tempting because data loss is a real continuity concern, but the gap described is about staff and premises arrangements, not about whether recovery point objectives were set.

Why C is wrong: Tempting because untested failover is a valid risk, but the weakness here is the absence of workforce and premises continuity, not the testing state of the data centre.

Why D is wrong: Tempting because authorship can skew priorities, but the core flaw is the missing people-and-premises dimension itself, which would matter regardless of who drafted the plan.

See more CISM practice questions, answers explained.

More in this domain

Back to all Incident Management objectives, or the CISM cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.