CISA Governance and Management of IT Practice Question
A company's IT governance policy requires that all critical systems have a documented business continuity plan (BCP). During an audit, an IT auditor finds that the BCP for a critical financial system has not been updated in three years. Which of the following is the BEST recommendation?
⚠ Common exam trap
Many exam-takers assume a stable system means the BCP remains valid, but CISA tests the principle that BCPs must be living documents reviewed and tested at regular intervals (typically annually) regardless of system stability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Update the BCP to reflect current processes and conduct a test.
IT governance policies require that BCPs remain current to reflect actual operational processes. An outdated BCP (three years stale) may contain obsolete recovery procedures, contact information, or dependencies, rendering it ineffective during a real incident. Updating the BCP and then testing it validates that the documented steps align with the current system architecture and can be executed successfully, which is a core requirement of the BCP lifecycle per ISACA guidelines.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Archive the outdated BCP and develop a new one from scratch.
Why it's wrong here
Archiving does not solve the need for an updated plan.
- ✓
Update the BCP to reflect current processes and conduct a test.
Why this is correct
Updating and testing ensures the plan is viable and aligns with governance requirements.
- ✗
Accept the risk because the system has been stable.
Why it's wrong here
Risk acceptance is not appropriate; governance requires current plans.
- ✗
Implement a new system with built-in redundancy.
Why it's wrong here
Replacing the system is an overreaction and costly.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 995-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.