CISM - Incident Management (30% of the exam) - Section 4.2

Conduct a business impact analysis (BIA) to identify critical systems and processes and determine recovery priorities.

Conduct a business impact analysis (BIA) to identify critical systems and processes, quantify the operational and financial impact of disruption, and establish recovery time objectives (RTO) and recovery point objectives (RPO). Use BIA findings to set recovery priorities and validate that recovery strategies are feasible within the defined RTO and RPO.

Business impact analysisRTORPOCritical systems

Practice question for this objective

Free sampleIncident Managementhard

An information security manager is kicking off a business impact analysis for a logistics firm. The board has agreed to fund the exercise but wants to know what the BIA is fundamentally intended to produce before resources are committed. Which outcome best describes the primary purpose of the BIA?

  • AA catalogue of credible threats and their likelihood of occurring, used to decide which security controls the organisation should invest in first.
  • BA technical inventory of servers, applications and network dependencies, used by operations staff to rebuild the environment after a major outage.
  • CA ranked understanding of which business processes are most time-sensitive and the impact of their disruption over time, used to set recovery priorities. Correct
  • DA statement of residual risk accepted by process owners after controls are applied, used to obtain formal sign-off from senior management.
Recognise that a BIA exists to quantify disruption impact over time and rank processes to set recovery priorities, distinct from a risk assessment. A BIA measures how the consequences of a process outage escalate over time and ranks processes accordingly, which is the foundation for setting recovery objectives and allocating recovery resources. It deliberately addresses impact, not the likelihood or source of the disruption, which is the province of risk assessment.

Why A is wrong: Tempting because threat likelihood feels central to planning, but that is the output of a risk assessment; the BIA focuses on impact of disruption over time, not threat probability.

Why B is wrong: Tempting because dependency mapping does feed recovery, but an asset inventory is a supporting artefact; the BIA's purpose is to quantify business impact and set priorities, not to be a build sheet.

Why C is correct: Correct: the BIA characterises the consequences of disruption to each process over time and ranks them, which is exactly the input needed to drive recovery priorities and resourcing.

Why D is wrong: Tempting because both involve management sign-off, but residual risk acceptance belongs to the risk management process; the BIA produces impact-over-time analysis and recovery priorities, not a risk acceptance record.

See more CISM practice questions, answers explained.

Exam traps in Incident Management

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISM bank for this domain.

  • The recovery point objective, the maximum volume of data that may be lost measured as a period of time.

    Why it is wrong: The recovery point objective is tempting because it is also derived from the impact analysis, but it measures tolerable data loss before the disruption, not how long restoration may take.

  • Keep the ranking by standalone financial impact unchanged, because the BIA already quantified which process causes the greatest loss and that figure should drive the recovery order.

    Why it is wrong: Standalone impact looks authoritative, but it ignores that a high-impact process cannot recover before its prerequisite services, so a pure impact ranking misorders recovery.

  • The information security team, because it can apply a consistent impact methodology across every process and complete the BIA quickly without waiting on business input.

    Why it is wrong: Security-derived figures look consistent, but the team lacks the operational insight to judge real business impact, so the estimates lose credibility and the owners may reject the priorities.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.