Essential Components of a Business Continuity Plan
A company is developing a business continuity plan (BCP). Which TWO of the following are essential components that must be included in a BCP?
Quick Answer
The answer is the Recovery Time Objective (RTO) and the Business Impact Analysis (BIA). These are essential components of a business continuity plan because the BIA identifies critical business functions and quantifies the financial and operational impact of disruptions, while the RTO defines the maximum acceptable downtime for each function before severe consequences occur. Together, they form the data-driven foundation that prioritizes recovery efforts and resource allocation, ensuring the BCP is actionable rather than theoretical. On the ISC2 Certified in Cybersecurity CC exam, this concept tests your understanding of how risk management and business continuity intersect; a common trap is confusing RTO with Recovery Point Objective (RPO), which focuses on data loss tolerance rather than downtime. Remember the mnemonic: “BIA tells you what’s vital, RTO tells you how fast to revive it.”
⚠ Common exam trap
ISC2 often tests the distinction between components that are 'essential' to the BCP itself versus supporting documents or risk management activities, causing candidates to select asset inventory or vulnerability assessment as core BCP elements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Business Impact Analysis (BIA)
Option C, Business Impact Analysis (BIA), is essential because it identifies critical business functions, quantifies the operational and financial impact of their disruption, and establishes the priorities and dependencies that drive the entire BCP strategy. Option D, Recovery Time Objective (RTO), is essential because it defines the maximum acceptable downtime for each critical process, directly shaping the recovery strategies, resource allocation, and backup/replication design documented in the BCP. Options A, B, and E are supporting inputs rather than mandatory BCP components: an asset inventory and network diagram are useful technical references, and a vulnerability assessment belongs to risk assessment activities that inform, but are not part of, the core BCP structure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Asset inventory
Why it's wrong here
An asset inventory lists hardware and software but omits recovery strategies, RTOs, and succession or communication plans, so it alone cannot satisfy the BCP's essential components. It is tempting because assets underpin impact analysis, and it would be correct as an input when scoping risk assessments or configuration management baselines.
- ✗
Vulnerability assessment
Why it's wrong here
A vulnerability assessment identifies weaknesses for risk treatment; it does not document recovery priorities, RTOs, or alternate processing sites, so it cannot satisfy the BCP's continuity requirements. It is tempting because vulnerability findings feed risk analysis, and it would be correct when scoping security remediation or penetration-test planning rather than continuity planning.
- ✓
Business Impact Analysis (BIA)
Why this is correct
The Business Impact Analysis identifies critical business functions, their dependencies and the consequences of disruption, establishing the maximum tolerable downtime. It supplies the foundational data from which recovery priorities, strategies and objectives within the BCP are derived.
- ✓
Recovery Time Objective (RTO)
Why this is correct
The Recovery Time Objective defines the maximum acceptable duration for restoring a function or system after disruption. It is an essential BCP component because it sets the target against which recovery strategies and resource requirements are designed and validated.
- ✗
Network diagram
Why it's wrong here
A network diagram maps topology but records no recovery time objectives, critical process dependencies, or alternate site arrangements, so it cannot fulfil the BCP's continuity content. It is tempting because topology aids impact analysis, and it would be correct when documenting infrastructure for troubleshooting or change management.
Go deeper
Related to this question
Learn chapter
Risk Management and Security Controls
Key term
Risk assessment
Risk assessment is the process of identifying, analyzing, and evaluating potential threats to an organization's assets to determine the likelihood and impact of those threats, and to decide on appropriate treatment measures.
Key term
Analysis
In incident response, analysis is the process of examining data and events to determine what happened, how it happened, and what actions to take.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
3 more ways this is tested on CC
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which THREE elements are essential components of a business continuity plan (BCP)?
medium- ✓ A.Data backup schedules and procedures
- ✓ B.Business impact analysis (BIA) results
- C.Incident response team roster
- ✓ D.Emergency contact lists
- E.Detailed network topology diagrams
Why A: A business continuity plan must be grounded in a business impact analysis (BIA), so option B is correct because the BIA identifies critical business functions, recovery time objectives (RTOs), and recovery point objectives (RPOs) that drive the entire continuity strategy. Option A is correct because data backup schedules and procedures are essential to restore systems and data within the RTO/RPO targets defined by the BIA, directly enabling recovery of operations. Option D is correct because emergency contact lists ensure the right personnel, vendors, and stakeholders can be reached immediately during a disruption to activate and coordinate the BCP. Option C is not essential to a BCP because an incident response team roster belongs to the incident response plan, which handles detection and containment of security events rather than long-term business continuity. Option E is not essential because detailed network topology diagrams are supporting technical documentation, not a core BCP element, and continuity planning focuses on business processes and recovery priorities rather than network design detail.
Variation 2. Which TWO are primary objectives of a Business Continuity Plan (BCP)? (Select two.)
medium- A.Comply with regulations
- ✓ B.Ensure employee safety
- C.Restore IT systems within RTO
- ✓ D.Minimize financial loss
- E.Protect brand reputation
Why B: Option B (Ensure employee safety) is correct because the protection of human life is universally recognized as the first and foremost objective of any Business Continuity Plan; no recovery activity should proceed until personnel are accounted for and safe. Option D (Minimize financial loss) is correct because a core purpose of a BCP is to reduce the economic impact of a disruption by maintaining or quickly resuming critical business functions, thereby limiting lost revenue, penalties, and recovery costs. Option A (Comply with regulations) is a driver or benefit of having a BCP rather than a primary objective of the plan itself, and option C (Restore IT systems within RTO) is a Disaster Recovery Plan objective focused on technology recovery, not the broader business-focused BCP. Option E (Protect brand reputation) is a desirable outcome of effective continuity management but is a secondary consequence rather than a primary objective of the BCP.
Variation 3. Which document outlines the procedures for maintaining critical business functions during a disruption?
easy- ✓ A.Business Continuity Plan
- B.Continuity of Operations Plan
- C.Incident Response Plan
- D.Disaster Recovery Plan
Why A: The Business Continuity Plan (BCP) is the correct answer because it specifically outlines the procedures and strategies to maintain critical business functions during a disruption. Unlike other plans that focus on IT recovery or incident response, the BCP ensures that essential business operations continue, often by leveraging alternate work sites, manual workarounds, or scaled-down processes, until normal operations can be restored.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.