mediumMultiple ChoiceObjective-mapped
CISSP Practice Question: Is developing a business continuity plan (BCP)…
An organization is developing a business continuity plan (BCP) for its critical IT systems. Which of the following is the FIRST step in the BCP process?
⚠ Common exam trap
Watch out — candidates often confuse the risk assessment (which identifies threats) with the BIA (which identifies business impact), but the BCP process explicitly begins with the BIA to prioritize business functions before addressing threats or recovery strategies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a business impact analysis (BIA) to prioritize critical business functions.
The first step in the BCP process is to conduct a Business Impact Analysis (BIA) to identify and prioritize critical business functions and their dependencies. Without the BIA, you cannot determine which systems require recovery strategies or what recovery time objectives (RTOs) and recovery point objectives (RPOs) are needed. The BIA provides the quantitative and qualitative basis for all subsequent BCP decisions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Identify recovery strategies for critical systems.
Why it's wrong here
Identifying recovery strategies for critical systems is a subsequent step in the business continuity planning process, occurring after the Business Impact Analysis (BIA) has been completed. The BIA provides essential data, such as Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs), which directly inform the selection and design of appropriate and cost-effective recovery strategies. Without understanding the true impact and required recovery timelines, strategy development would lack the necessary foundational context and prioritization.
- ✓
Conduct a business impact analysis (BIA) to prioritize critical business functions.
Why this is correct
Conducting a Business Impact Analysis (BIA) is the foundational and initial step in developing a robust Business Continuity Plan (BCP). The BIA systematically identifies and prioritizes an organization's critical business functions and processes, quantifying the potential financial and operational impacts of their disruption. This analysis establishes crucial metrics like Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs), which are indispensable for guiding all subsequent BCP activities, including strategy selection and resource allocation.
- ✗
Develop a testing schedule for the BCP.
Why it's wrong here
Developing a testing schedule for the Business Continuity Plan (BCP) is a critical phase, but it occurs much later in the BCP lifecycle. Before a testing schedule can be effectively created and implemented, the BCP itself must first be fully developed, documented, approved by management, and communicated to relevant stakeholders. Testing validates the plan's effectiveness and identifies areas for improvement, making it an operational step that follows the plan's initial creation and implementation.
- ✗
Perform a risk assessment to identify potential threats.
Why it's wrong here
While performing a comprehensive risk assessment is an integral component of an organization's overall information security and resilience program, it is not the initial step specifically for developing a Business Continuity Plan (BCP). A risk assessment primarily identifies potential threats and vulnerabilities to assets. In contrast, the Business Impact Analysis (BIA) directly focuses on the consequences of disruptions to business functions, regardless of the specific threat, thereby establishing the criticality and recovery requirements that directly drive BCP development.
Go deeper
Related to this question
About these practice questions
One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.