Ferndale Credit Union is starting to build its first business continuity plan. Before the team can decide which systems to recover first after a disruption, which activity should they carry out to identify their critical business functions and the impact of losing each one over time?
- AA penetration test that probes the network for exploitable technical vulnerabilities and misconfigurations
- BA quantitative risk assessment that calculates annualised loss expectancy for each identified threat
- CA business impact analysis that ranks functions by the operational and financial harm caused by their disruption Correct
- DA disaster recovery test that fails over the data centre to the alternate site and measures restore time
Why A is wrong: A penetration test finds security weaknesses, which is valuable, but it does not rank business functions by the impact of their disruption, so it cannot drive recovery priorities.
Why B is wrong: Risk assessment estimates the likelihood and cost of threats, which is tempting because it also uses financial figures, but it focuses on threats rather than on which functions are critical to keep running.
Why C is correct: The business impact analysis identifies critical business functions and quantifies the harm of losing each over time, which is exactly the input needed to set recovery priorities.
Why D is wrong: A recovery test validates that technical failover works, but it comes after priorities are set and assumes the critical functions have already been identified.