CISA Practice Question: Information Systems Operations and Business Resilience
An IS auditor is reviewing an organization's IT service continuity plan (ITSCP) that supports its business continuity plan (BCP). The auditor finds that the ITSCP includes recovery strategies for critical systems but lacks details on roles and responsibilities during a disaster. Which TWO of the following should the auditor recommend to address this gap? (Choose two.)
⚠ Common exam trap
The trap here is selecting testing or procedure documentation as the primary fix, when the specific deficiency is the absence of defined roles and responsibilities, which are best addressed by establishing a crisis management team and an emergency operations center.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Define a crisis management team with clear roles and decision-making authority.
The ITSCP lacks details on roles and responsibilities during a disaster. To address this, the auditor should recommend defining a crisis management team with clear roles and establishing an emergency operations center with assigned staff and contact information. These actions directly provide the missing structure for decision-making and coordination. Documenting recovery procedures, testing, and aligning with BCP are important but do not specifically fill the gap of roles and responsibilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Align the ITSCP with the BCP by mapping IT recovery times to business process RTOs.
Why it's wrong here
Aligning ITSCP with BCP is crucial for ensuring that IT recovery supports business needs. However, the scenario states that the ITSCP already supports the BCP but lacks roles and responsibilities. While alignment is important, it does not directly address the identified gap. The auditor should focus on the missing roles and responsibilities, making this option less appropriate than the two correct choices.
- ✗
Conduct regular testing of the ITSCP through tabletop exercises.
Why it's wrong here
Testing is important to validate the plan, but the gap identified is the lack of roles and responsibilities. While tabletop exercises can help clarify roles, they are not a direct recommendation to define them. The auditor should first recommend establishing the roles and responsibilities, then testing them. Therefore, this option is not one of the two most appropriate to address the specific deficiency.
- ✗
Document detailed recovery procedures for each critical system.
Why it's wrong here
While recovery procedures are important, the scenario specifically notes a lack of roles and responsibilities, not procedures. Documenting procedures addresses a different gap. The auditor should focus on recommendations that directly address the identified deficiency. Therefore, this option is not one of the two most appropriate recommendations for the stated gap.
- ✓
Define a crisis management team with clear roles and decision-making authority.
Why this is correct
A crisis management team with defined roles ensures that during a disaster, there is clear leadership and decision-making. This addresses the gap in roles and responsibilities. The team should include representatives from IT, business units, and communications. Clear authority helps avoid confusion and delays. This is a key recommendation to improve the ITSCP's effectiveness and alignment with the BCP.
- ✓
Establish an emergency operations center (EOC) with assigned staff and contact information.
Why this is correct
An emergency operations center (EOC) with assigned staff and contact information directly addresses the lack of roles and responsibilities. It provides a central location for coordination and ensures that key personnel can be reached. This is essential for effective disaster response and is a key recommendation to fill the identified gap in the ITSCP.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.