CISM - Incident Management - Section 4.2

Conduct a business impact analysis (BIA) to identify critical systems and processes and determine recovery priorities.

Conduct a business impact analysis (BIA) to identify critical systems and processes, quantify the operational and financial impact of disruption, and establish recovery time objectives (RTO) and recovery point objectives (RPO). Use BIA findings to set recovery priorities and validate that recovery strategies are feasible within the defined RTO and RPO.

Business impact analysisRTORPOCritical systems

Practice question for this objective

Free sampleIncident Managementhard

An information security manager is kicking off a business impact analysis for a logistics firm. The board has agreed to fund the exercise but wants to know what the BIA is fundamentally intended to produce before resources are committed. Which outcome best describes the primary purpose of the BIA?

  • AA catalogue of credible threats and their likelihood of occurring, used to decide which security controls the organisation should invest in first.
  • BA technical inventory of servers, applications and network dependencies, used by operations staff to rebuild the environment after a major outage.
  • CA ranked understanding of which business processes are most time-sensitive and the impact of their disruption over time, used to set recovery priorities. Correct
  • DA statement of residual risk accepted by process owners after controls are applied, used to obtain formal sign-off from senior management.
Recognise that a BIA exists to quantify disruption impact over time and rank processes to set recovery priorities, distinct from a risk assessment. A BIA measures how the consequences of a process outage escalate over time and ranks processes accordingly, which is the foundation for setting recovery objectives and allocating recovery resources. It deliberately addresses impact, not the likelihood or source of the disruption, which is the province of risk assessment.

Why A is wrong: Tempting because threat likelihood feels central to planning, but that is the output of a risk assessment; the BIA focuses on impact of disruption over time, not threat probability.

Why B is wrong: Tempting because dependency mapping does feed recovery, but an asset inventory is a supporting artefact; the BIA's purpose is to quantify business impact and set priorities, not to be a build sheet.

Why C is correct: Correct: the BIA characterises the consequences of disruption to each process over time and ranks them, which is exactly the input needed to drive recovery priorities and resourcing.

Why D is wrong: Tempting because both involve management sign-off, but residual risk acceptance belongs to the risk management process; the BIA produces impact-over-time analysis and recovery priorities, not a risk acceptance record.

See more CISM practice questions, answers explained.

More in this domain

Back to all Incident Management objectives, or the CISM cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.