A company's IT governance policy requires that all critical systems have a documented business continuity plan (BCP). During an audit, an IT auditor finds that the BCP for a critical financial system has not been updated in three years. Which of the following is the BEST recommendation?
Trap 1: Archive the outdated BCP and develop a new one from scratch.
Archiving discards the existing plan's documented recovery procedures, dependencies and RTO/RPO baselines, which the audit finding requires updating, not replacing. Rebuilding from scratch is tempting when a plan is stale, yet a full rewrite is warranted only for a system whose architecture or business processes have fundamentally changed.
Trap 2: Accept the risk because the system has been stable.
Accepting the risk leaves the governance policy's documented-BCP requirement unmet; three years of unrefreshed recovery procedures means untested assumptions about dependencies and recovery times. Risk acceptance is tempting for demonstrably stable systems, but it requires formal management sign-off and cannot substitute for the mandated plan update.
Trap 3: Implement a new system with built-in redundancy.
Adding redundant systems addresses availability engineering, not the governance gap of an outdated BCP, so it leaves the audit finding unresolved. It is tempting because redundancy supports resilience, but the recommendation should be to update and re-approve the BCP on a defined review cycle.
- A
Archive the outdated BCP and develop a new one from scratch.
Why it fails: Archiving discards the existing plan's documented recovery procedures, dependencies and RTO/RPO baselines, which the audit finding requires updating, not replacing. Rebuilding from scratch is tempting when a plan is stale, yet a full rewrite is warranted only for a system whose architecture or business processes have fundamentally changed.
- B
Update the BCP to reflect current processes and conduct a test.
A three-year-old BCP for a critical financial system is stale and untested, so the auditor should recommend refreshing it against current processes and validating it through testing. This restores alignment with the governance policy's documented-plan requirement.
- C
Accept the risk because the system has been stable.
Why it fails: Accepting the risk leaves the governance policy's documented-BCP requirement unmet; three years of unrefreshed recovery procedures means untested assumptions about dependencies and recovery times. Risk acceptance is tempting for demonstrably stable systems, but it requires formal management sign-off and cannot substitute for the mandated plan update.
- D
Implement a new system with built-in redundancy.
Why it fails: Adding redundant systems addresses availability engineering, not the governance gap of an outdated BCP, so it leaves the audit finding unresolved. It is tempting because redundancy supports resilience, but the recommendation should be to update and re-approve the BCP on a defined review cycle.