Which of the following should be of GREATEST concern to an IS auditor reviewing an organization's business continuity plan (BCP)?
Answer: A
This question falls under CISA Domain 4 (Information Systems Operations and Business Resilience), which focuses on validating an organization's ability to maintain operational continuity and recover from disruptions. The core priority of an IS auditor reviewing a BCP is to confirm the plan will effectively enable recovery of critical business functions when needed. An untested BCP provides no objective evidence that procedures, resource allocations, recovery timelines, or stakeholder responsibilities are accurate or feasible. Even well-documented, approved, and updated BCPs often contain unforeseen gaps such as incompatible recovery tools, misaligned recovery time objectives (RTO)/recovery point objectives (RPO), or undocumented process dependencies that only testing can identify. The lack of testing eliminates all assurance of BCP effectiveness, which poses a far higher business risk than the other listed gaps, making this the greatest concern. Option Analysis:
A. Correct. BCP testing is a foundational control required to validate plan feasibility, accuracy, and alignment with business recovery objectives. Without testing, there is no guarantee the BCP will function as intended during an actual disruption, exposing the organization to unmitigated financial, operational, and reputational loss. This gap invalidates the core purpose of the BCP, making it the highest priority concern.
B. Incorrect. Lack of version control is an administrative process gap that can lead to distribution of outdated BCP copies, but it is a low-impact, easily remediated issue. Version control does not directly impact the core functionality of the BCP, so it is a lesser concern than an untested plan.
C. Incorrect. Outdated contact information is a minor operational gap that can cause minor delays during BCP activation, but it is simple to update and does not undermine the overall effectiveness of the recovery plan. This is a lower priority concern than lack of testing.
D. Incorrect. While senior management approval is a recommended governance control to formalize BCP accountability and resource allocation, an unapproved but thoroughly tested BCP can still effectively support recovery during a disruption. An approved but untested BCP provides no recoverability assurance, so lack of approval is a lower risk than lack of testing. Key Concepts:
1. BCP Effectiveness Validation: CISA guidance specifies that testing is the only reliable method to confirm a BCP meets RTO/RPO requirements and addresses all critical recovery dependencies, as documentation reviews cannot identify process or resource gaps that appear during real-world activation.
2. Risk Prioritization for IS Auditors: Auditors rank control gaps based on their impact to core business objectives. Gaps that eliminate all assurance of a critical control like BCP functionality are prioritized over administrative or governance gaps that only reduce control efficiency.
3. Business Resilience Maturity: A mature business continuity management (BCM) program requires regular testing, updates, and training as core components, with testing being the most critical metric of program effectiveness per ISACA frameworks. References:
ISACA CISA Exam Domains, ISACA Business Continuity Management Practical Guide, https://www.isaca.org/resources/isaca-journal/issues/2020/volume-3/business-continuity-management-a-practical-guide