Courseiva

CISM Information Security Programme Practice Question

A financial services firm has completed a business impact analysis (BIA). The CISO must now ensure the information security programme's recovery priorities are consistent with the BIA results. Which action should the CISO take NEXT?

⚠ Common exam trap

The trap here is treating the BIA as a document to be filed rather than a driver for updating recovery plans; testing or insurance does not substitute for aligning RTOs and RPOs with business needs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Update the disaster recovery plan to reflect the recovery time objectives (RTOs) and recovery point objectives (RPOs) identified in the BIA.

The BIA defines critical processes and their RTOs and RPOs. To make the security programme consistent with these findings, the CISO must ensure disaster recovery and related plans are updated so that systems and data can be restored within the required timeframes. This is a direct, necessary step before validating or transferring risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Conduct a penetration test of the disaster recovery site to validate its security posture.

    Why it's wrong here

    Penetration testing the recovery site assesses its security vulnerabilities but does not ensure recovery priorities match the BIA. The BIA defines what must be recovered and how quickly; testing the site does not address whether the plan's RTOs and RPOs are aligned with those business requirements. This action is premature and tangential to the immediate goal.

  • ✓

    Update the disaster recovery plan to reflect the recovery time objectives (RTOs) and recovery point objectives (RPOs) identified in the BIA.

    Why this is correct

    The BIA establishes critical business processes and their maximum tolerable downtime and data loss, expressed as RTOs and RPOs. The next logical step is to ensure the disaster recovery plan for information systems is updated to meet these targets. This directly links security and resilience priorities to business impact, ensuring recovery capabilities are aligned with what the business actually needs.

  • ✗

    Launch a security awareness programme focused on business continuity responsibilities.

    Why it's wrong here

    Awareness is useful for ensuring staff understand their roles in continuity, but it does not align technical recovery priorities with the BIA. The gap identified is between business impact requirements and information security recovery planning. Training alone will not update plans or ensure systems meet RTOs and RPOs, so it is not the next appropriate action.

  • ✗

    Increase the cybersecurity insurance coverage to transfer residual risk identified in the BIA.

    Why it's wrong here

    Insurance can transfer financial risk, but the CISO's immediate task is to align recovery priorities with the BIA, not to adjust risk transfer. Insurance does not ensure that systems can be recovered within required timeframes. While insurance is part of risk treatment, it does not address the operational alignment between the BIA and the information security programme's recovery capabilities.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.