CISA Practice Question: Information Systems Operations and Business Resilience
An organization is developing a business continuity strategy. According to best practices, which THREE of the following should be included in the strategy?
⚠ Common exam trap
The trap is confusing BCP strategy elements with BCP inputs or administrative details; candidates may pick 'IT asset inventory' because it sounds important, but it is an input, not a strategic element.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Customer and partner communications plan.
A customer and partner communications plan (A) is a required element of a business continuity strategy because during a disruption the organization must be able to notify external stakeholders about service status, expected recovery times, and alternate contact channels, which protects reputation and contractual relationships. Procedures for staff to work remotely (C) belong in the strategy because personnel are the most critical resource; documented remote-work procedures ensure that essential functions can continue when the primary site is unavailable. Details of alternate processing facilities (E) are essential because the strategy must identify where and how critical systems and operations will be resumed, including recovery site type (hot, warm, or cold), location, and activation criteria. Vendor contract renewal dates (B) are administrative procurement data rather than continuity planning content, and an IT asset inventory list (D) is an operational input used during business impact analysis and recovery planning, not a strategic continuity element itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Customer and partner communications plan.
Why this is correct
A customer and partner communications plan ensures external stakeholders receive timely, accurate notifications during disruption, protecting reputation and contractual obligations. It satisfies the strategy's requirement to address interdependent parties, since continuity depends on coordinated messaging rather than internal recovery alone.
- ✗
Vendor contract renewal dates.
Why it's wrong here
Renewal dates are contract administration detail, not a continuity strategy component. Tracking them is valid vendor management practise, yet the strategy requires recovery objectives, dependency mapping, and continuity arrangements; renewal timing neither restores operations nor sets tolerable downtime.
- ✓
Procedures for staff to work remotely.
Why this is correct
Remote working procedures let staff continue critical functions when the primary site is unavailable, directly satisfying the strategy's need for alternate work arrangements. This addresses the people and workplace dependency, ensuring essential roles remain productive throughout the disruption.
- ✗
IT asset inventory list.
Why it's wrong here
An asset inventory supports impact analysis but is an input to the strategy, not a component of it. It is tempting because recovery planning depends on knowing which systems exist; however, the strategy itself must define recovery time and recovery point objectives, roles, and alternate processing arrangements.
- ✓
Details of alternate processing facilities.
Why this is correct
Alternate processing facilities provide the recoverable infrastructure on which critical systems resume, satisfying the strategy's requirement for technical recovery capability. Without a designated alternate site, recovery objectives such as RTO cannot be met when the primary data centre is lost.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.