Question 1 of 25
Which of the following should be of GREATEST concern to an IS auditor reviewing an organization's business continuity plan (BCP)?
Show answer
How others answered
- A56%
- D44%
Only 56% agreed on this answer — treat it as contested rather than settled.
Explanation
I went to the CISA review manual to solve this, and the main concern should be the lack of testing. First: Senior management create a "business continuity policy" (Ref: Review Manual 27th edition 4.15.4). In general, senior management makes policies, and the plebs below make plans and procedures. Therefore a business continuity plan is not necessarily senior management approved. Furthermore there is a passage in the review manual (4.15.11) regarding auditing business continuity. The passage does not really mention senior management, but it does mention plan testing and obtaining historical results of tests during an audit.
Adapted from community discussion by GenPatton · 2023-09-24 · 11 community upvotes. Third-party contribution; reviewed by our quality filter, not independently verified.