Valid CISA Dumps shared by ExamDiscuss.com for Helping Passing CISA Exam! ExamDiscuss.com now offer the newest CISA exam dumps, the ExamDiscuss.com CISA exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com CISA dumps with Test Engine here:
Which of the following should be of MOST concern to an IS auditor reviewing an organization's business impact analysis (BIA)?
Correct Answer: B
The business impact analysis (BIA) is a critical component of an organization's business continuity planning (BCP) process. The most concerning issue is when system criticality information is provided only by the IT manager (Option B). This presents a risk of bias or incomplete analysis, as business units must also provide input to ensure a comprehensive assessment. ISACA CISA Reference: According to ISACA's BCP and DRP guidelines, BIA should involve input from multiple business functions, including finance, operations, and risk management, rather than relying solely on IT. Risk Implication: Without broader business input, the criticality of systems may be misclassified, leading to incorrect recovery priorities and potential business disruption. Alternative Choices: Option A: While a risk assessment is important, a BIA can still be completed without it and later validated. Option C: The use of questionnaires is a valid method if responses are verified. Option D: Lack of executive sign-off is concerning but does not directly impact the accuracy of system criticality assessment.