ISC2-CC - Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts (10% of the exam) - Section 2.1

Understand the purpose, importance, and components of a business continuity plan, including the business impact analysis.

Explain that business continuity (BC) keeps critical business functions running during a disruption, driven by a business impact analysis (BIA) that identifies essential processes and their tolerable downtime. Distinguish BC from disaster recovery: BC sustains operations broadly, while DR focuses on restoring IT systems and data.

Business continuityBusiness impact analysisCritical business functionsBC plan

Practice question for this objective

Free sampleBusiness Continuity (BC), Disaster Recovery (DR) & Incident Response Conceptsmedium

Ferndale Credit Union is starting to build its first business continuity plan. Before the team can decide which systems to recover first after a disruption, which activity should they carry out to identify their critical business functions and the impact of losing each one over time?

  • AA penetration test that probes the network for exploitable technical vulnerabilities and misconfigurations
  • BA quantitative risk assessment that calculates annualised loss expectancy for each identified threat
  • CA business impact analysis that ranks functions by the operational and financial harm caused by their disruption Correct
  • DA disaster recovery test that fails over the data centre to the alternate site and measures restore time
The business impact analysis identifies critical business functions and quantifies the impact of disruption to prioritise recovery. The business impact analysis is the foundational study that catalogues business functions, determines which are critical, and measures how the harm from losing each grows over time, giving the plan the ranking it needs before recovery objectives are chosen.

Why A is wrong: A penetration test finds security weaknesses, which is valuable, but it does not rank business functions by the impact of their disruption, so it cannot drive recovery priorities.

Why B is wrong: Risk assessment estimates the likelihood and cost of threats, which is tempting because it also uses financial figures, but it focuses on threats rather than on which functions are critical to keep running.

Why C is correct: The business impact analysis identifies critical business functions and quantifies the harm of losing each over time, which is exactly the input needed to set recovery priorities.

Why D is wrong: A recovery test validates that technical failover works, but it comes after priorities are set and assumes the critical functions have already been identified.

See more ISC2-CC practice questions, answers explained.

Exam traps in Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts

Answers that look right on this material and are not. Each one is a distractor from a different question in the ISC2-CC bank for this domain.

  • It restores IT systems and data to a working state after a technical failure or outage.

    Why it is wrong: This describes disaster recovery, which focuses on technology restoration. It is tempting because DR is part of resilience planning, but the business continuity plan has a broader aim than rebuilding systems.

  • A ranked list of the security controls that must be purchased before the next audit cycle.

    Why it is wrong: Control selection belongs to risk treatment, not the impact analysis. It is tempting because both feed resilience, but the analysis measures disruption effects rather than recommending purchases.

  • Disaster recovery replaces business continuity once a plan is signed, making the continuity plan redundant

    Why it is wrong: This inverts the hierarchy; disaster recovery supports continuity rather than superseding it, and the continuity plan remains the governing framework.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.