Business Impact Analysis (BIA) Essentials
Which TWO are essential elements of a business impact analysis (BIA)?
Quick Answer
The answer is the determination of maximum acceptable outage (MAO) and the identification of critical business functions. These are essential elements of a business impact analysis (BIA) because the BIA’s core purpose is to quantify the operational and financial consequences of disruptions, and without knowing which functions are critical and how long they can be down, you cannot prioritize recovery or allocate resources effectively. On the ISC2 Certified in Cybersecurity CC exam, this concept tests your understanding of disaster recovery fundamentals; a common trap is confusing the BIA with the risk assessment itself—remember, the BIA focuses on impact and recovery time objectives, not on threats or vulnerabilities. A useful memory tip is to think “BIA = Business Impact = what breaks first and how long can it stay broken.”
⚠ Common exam trap
ISC2 often tests the distinction between BIA elements (like critical functions and MAO) and technical implementation details (like IP addresses or network diagrams), so candidates mistakenly choose options that sound technical but are irrelevant to the BIA process.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identification of critical business functions
Option C is correct because a BIA must identify the critical business functions (and the processes and resources supporting them) so that recovery priorities, dependencies, and RTO/RPO targets can be established. Option E is correct because the BIA must determine the maximum acceptable outage (MAO), also expressed as maximum tolerable downtime (MTD), which sets the upper limit of tolerable disruption and drives the recovery time objective (RTO) and continuity strategies. Options A, B, and D are not essential BIA elements: a network topology diagram is a technical/infrastructure artifact used in DR planning, a list of all employees is an HR record rather than an impact analysis input, and IP address assignment is a network administration task unrelated to assessing business impact.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A network topology diagram
Why it's wrong here
A network topology diagram documents infrastructure, not business processes or their dependencies. A BIA requires identifying critical business functions and the impact of their disruption; topology belongs to a technical recovery plan, not the BIA itself.
- ✗
List of all employees
Why it's wrong here
A list of all employees is an HR inventory, not a BIA element. A BIA identifies critical business processes, their dependencies, and quantified impact over time; staffing rosters belong to resource planning or a call tree, not the impact analysis.
- ✓
Identification of critical business functions
Why this is correct
A BIA must catalogue the business processes whose disruption would halt operations, because every later figure — recovery time objectives, resource priorities, continuity strategies — is derived from that inventory. Without identifying critical business functions, the analysis has no scope to measure impact against.
- ✗
Assignment of IP addresses
Why it's wrong here
IP address assignment is a technical configuration detail, not a BIA component. A BIA captures business process criticality, dependency mapping, and downtime impact; addressing schemes belong to network design or recovery runbooks, not the impact analysis.
- ✓
Determination of maximum acceptable outage (MAO)
Why this is correct
Maximum acceptable outage defines how long a process may remain unavailable before the impact becomes intolerable, directly driving the recovery time objective. It converts business tolerance into a measurable downtime limit that continuity and recovery plans must satisfy.
Go deeper
Related to this question
Learn chapter
Network Security Components and Controls
Key term
RPO
Recovery Point Objective (RPO) is the maximum acceptable amount of data loss measured in time, defining how recent data must be to resume operations after a disruption.
Key term
Business impact analysis
A systematic process used to identify and evaluate the potential effects of an interruption to critical business operations as a result of a disaster, accident, or emergency.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on CC
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which of the following is the PRIMARY purpose of a business impact analysis (BIA)?
easy- A.Determine the cost of implementing security controls
- B.List all IT assets
- ✓ C.Identify critical business processes and their recovery priorities
- D.Assign incident response roles
Why C: The primary purpose of a business impact analysis (BIA) is to identify critical business processes and quantify the impact of their disruption, which directly determines recovery priorities and objectives (RTO/RPO). This output drives the business continuity and disaster recovery strategy, not asset inventory or cost estimation.
Variation 2. Which TWO are key outputs of a Business Impact Analysis (BIA)?
easy- ✓ A.List of critical business processes
- B.Password policy
- C.Network diagram
- D.Risk register
- ✓ E.Recovery Time Objectives
Why A: A Business Impact Analysis (BIA) identifies and prioritizes the business functions whose disruption would most affect the organization, so option A, the list of critical business processes, is a core output because it establishes what must be protected and restored first. Option E, Recovery Time Objectives (RTOs), is also a key BIA output because the BIA determines the maximum tolerable downtime for each critical process, which then drives continuity and recovery planning targets. By contrast, option B (password policy) is an access-control/security governance artifact, not a BIA deliverable. Option C (network diagram) is a technical architecture document produced by network or infrastructure teams, not by a BIA. Option D (risk register) is an output of risk assessment/risk management processes, where risks are logged and tracked; while a BIA may inform risk analysis, the risk register itself is not a primary BIA output.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.