Domain 4, Information Systems Operations and Resilience, makes up 29% of your CISA exam score. The single biggest reason candidates fail these questions is they evaluate a Business Continuity Plan (BCP) like an IT manager, approving technically correct solutions. The exam requires you to think like an auditor, and an auditor's first question is always: does this plan actually meet the business's stated needs?
For the CISA exam, Business Continuity Planning (BCP) is the overarching business-led strategy to ensure critical functions remain available during a disruption. It is distinct from the Disaster Recovery Plan (DRP), which is the IT-focused component of the BCP. You will be tested on your ability to audit the BCP's alignment with business-defined objectives like RTO and RPO.
Key facts
- Official Body: ISACA (Information Systems Audit and Control Association)
- Relevant Domain: Domain 4: IS Operations and Resilience
- Domain 4 Weighting: 29% of the CISA exam (approx. 44 questions)
- Passing Score: 450 on a scaled score range of 200-800
- Typical Study Hours: 150-200 hours over 2-3 months
- U.S. Salary Range: $100,000 - $160,000+ (varies by location and experience)
What is Business Continuity Planning for the CISA Exam?
Business Continuity Planning is the holistic management process for identifying potential threats to an organization and the impacts to business operations those threats, if realized, might cause. It provides a framework for building organizational resilience with the capability for an effective response that safeguards the interests of its key stakeholders.
For your CISA exam, this isn't just a definition to memorize. It's a lens through which you must evaluate every scenario in Domain 4. The examiner wants to see if you can spot the disconnect between a company's IT actions and its business strategy. Try VoraPrep's free CISA practice questions to see how this judgment is tested.
Studying for CISA CISA4? Benchmark your score in 5 minutes.
Get an instant weak-spot assessment and a custom 12-week study plan PDF generated for your exam window.
An auditor's conclusion is always anchored to business requirements.
The BCP Ecosystem: DRP, IRP, and Crisis Management
Candidates often confuse BCP with its components. The exam will penalize you for this. A BCP is the umbrella strategy; the other plans are specific, tactical responses that fall underneath it.
- Business Continuity Plan (BCP): The overall strategic plan, owned by the business. It focuses on keeping critical business functions running during a disruption. It asks, "How do we continue to take orders and serve customers?"
- Disaster Recovery Plan (DRP): The technical, IT-focused component of the BCP. It details the procedures to recover IT infrastructure, applications, and data. It asks, "How do we restore the servers and databases at the alternate site?"
- Incident Response Plan (IRP): A short-term plan for managing the immediate effects of an incident (e.g., a cyberattack). It focuses on containment, eradication, and recovery from the specific event. It asks, "How do we stop the ransomware from spreading and remove it?"
- Crisis Management Plan (CMP): The high-level plan for managing communications and the overall organizational response. It deals with executive decision-making, public relations, and stakeholder communication. It asks, "What do we tell our customers, regulators, and the media?"
On the exam, a plan to restore servers is a DRP. A plan to handle a data breach is an IRP. The BCP is the master plan that integrates them all to ensure the business survives.
What are the Core Components of a BCP?
The CISA exam tests your understanding of the BCP lifecycle. You must know the purpose of each stage and the auditor's role in evaluating it.
The Foundation: Business Impact Analysis (BIA)
The BIA is the non-negotiable starting point. It is a formal process to determine and evaluate the potential effects of an interruption to critical business operations. The BIA is what provides the data to justify all subsequent BCP decisions.
The BIA identifies:
- Critical business processes.
- The impact of a disruption to those processes over time (financial, reputational, legal).
- The Maximum Tolerable Downtime (MTD), also called Maximum Acceptable Outage (MAO). This is the absolute longest the business can survive without a specific process.
From the MTD, two critical metrics are derived:
- Recovery Time Objective (RTO): The targeted time within which a business process must be restored after a disaster. The RTO must always be less than or equal to the MTD.
- Recovery Point Objective (RPO): The maximum amount of data loss the business can tolerate, measured in time. An RPO of 15 minutes means the business can't afford to lose more than 15 minutes of transaction data.
Strategy and Plan Development
Based on the BIA's RTO and RPO findings, the organization selects recovery strategies. As an auditor, you must assess if the chosen strategy can realistically meet these objectives.
| Recovery Strategy | Typical RTO | Typical RPO | Best For |
|---|---|---|---|
| Hot Site | Minutes to hours | Seconds to minutes | Critical systems with zero to minimal tolerance for downtime or data loss. |
| Warm Site | Hours to days | Hours | Systems that can tolerate some downtime for data restoration. |
| Cold Site | Days to weeks | Days | Non-critical systems where extended downtime is acceptable. |
| Cloud-based Failover | Varies (seconds to hours) | Varies (seconds to hours) | Highly scalable and flexible; can support very aggressive RTO/RPO. |
| Reciprocal Agreement | Unreliable (weeks) | Unreliable | Low-criticality functions; often not a viable primary strategy due to conflicts of interest. |
Testing the Plan
A plan that hasn't been tested is merely a document. The CISA exam requires you to know the hierarchy of tests and recommend the most appropriate one for a given context.
| Test Type | Description | Auditor's Perspective |
|---|---|---|
| Desk Check / Read-through | A simple review of the plan by key team members. | Good for initial validation and training, but provides no real assurance. |
| Structured Walk-through | A tabletop exercise where the team talks through a disaster scenario. | Better for identifying gaps in roles and procedures, but still theoretical. |
| Simulation Test | A practice run of a specific scenario in a test environment. | Good for testing response procedures without impacting production systems. |
| Parallel Test | Recovery systems are run in parallel with production systems. | Tests the actual recovery environment but is complex and costly. |
| Full-Interruption Test | Production systems are shut down and the business fails over to the recovery site. | Provides the highest level of assurance but carries the highest risk and business disruption. |
Maintaining the Plan
The BCP is a living document. It must be reviewed and updated at least annually or whenever a significant change occurs in business processes, technology, or personnel. As an auditor, your first check should be the date of the last BIA, the last plan update, and the last test. An outdated plan is an ineffective plan.
How Do You Solve a CISA Business Continuity Scenario?
Let's walk through a typical CISA scenario. This is about applying principles, not just recalling facts.
Scenario: FinCore Bank provides online banking services. A recent Business Impact Analysis (BIA) for its core transaction processing system established the following requirements:- Recovery Time Objective (RTO): 2 hours
- Recovery Point Objective (RPO): 30 minutes
The IS auditor is reviewing the bank's Disaster Recovery Plan (DRP), which states that the system is backed up using the following procedure:
- A full backup is performed every night at midnight to tape. Tapes are sent offsite the next morning.
- Transaction logs are backed up every 60 minutes to a server in the same data center.
Which of the following is the MOST significant audit finding?
A) The RTO of 2 hours cannot be met because tapes are sent offsite. B) The DRP does not account for denial-of-service attacks. C) The RPO of 30 minutes is not supported by the current backup strategy. D) The use of a single data center for transaction log backups represents a concentration risk.
Step 1: Anchor on the Business Requirements from the BIAFirst, ignore the technology. The business has explicitly stated its needs:
- Maximum tolerable data loss (RPO) = 30 minutes.
- Maximum tolerable downtime (RTO) = 2 hours.
These are your non-negotiable audit criteria.
Step 2: Analyze the Technical Implementation in the DRPNow, map the DRP's capabilities to the requirements.
- Full backup: Once every 24 hours.
- Transaction log backup: Once every 60 minutes.
If a disaster strikes at 2:55 PM, the last successful log backup was at 2:00 PM. This means 55 minutes of transaction data (from 2:00 to 2:55) would be lost.
Step 3: Compare Requirements to Implementation- RPO Check: The business requires a maximum data loss of 30 minutes. The backup strategy results in a potential data loss of up to 60 minutes. This is a direct, mathematical failure. The RPO is not met.
- RTO Check: Can they recover in under 2 hours? The scenario doesn't give enough information. Recovering from tape can be slow, but we can't definitively say it will take more than 2 hours. This is a potential issue, but not as certain as the RPO failure.
- (D) The use of a single data center for transaction log backups represents a concentration risk. This is a completely valid audit finding. If the data center is destroyed, the log backups are lost too. However, the RPO is violated even if the disaster doesn't destroy the data center. The 60-minute backup frequency is a fundamental design flaw that fails the business requirement on its own. The RPO violation is more significant than the concentration risk.
- (A) The RTO of 2 hours cannot be met because tapes are sent offsite. This is a plausible concern, but it's an assumption. We don't know the tape recall time or restoration speed. The RPO failure is a mathematical certainty based on the information given. Auditors report on facts, not assumptions.
- (B) The DRP does not account for denial-of-service attacks. The scenario is about recovery from a system failure, not a specific threat. While a good plan should consider various threats, the immediate, measurable failure here is the gap between the stated business objective (RPO) and the technical capability.
This is the judgment the CISA exam demands. The VoraPrep adaptive learning engine is designed to find your specific weak spots in this kind of analysis and serve you more questions to build that muscle.
Can You Pass These CISA Practice Questions on BCP?
Test your understanding with these sample questions.
Calculate Your CISA Study Hours by Domain
See the exact domain-by-domain study breakdown reflecting the 2024 ISACA Job Practice weighting shifts.
---
Question 1During an audit of a financial institution's BCP, an IS auditor finds that while the data center has a detailed DRP, several key business departments have not documented their manual workarounds. Which of the following is the auditor's BEST course of action?
A) Recommend immediate disciplinary action for the department heads. B) Develop the manual workaround procedures for the departments. C) Report the finding to senior management as a significant gap in the BCP. D) Accept the risk as it is primarily a business, not an IT, issue.
Answer: C Explanation: The auditor's role is to identify risks and report them. A BCP is incomplete if it only covers IT recovery and ignores business processes. (C) correctly reflects the auditor's responsibility. (A) is outside the auditor's authority. (B) impairs independence by performing management's job. (D) is wrong because the integration of IT and business processes is a core CISA concern.---
Question 2A manufacturing firm's BIA specifies a Recovery Time Objective (RTO) of 4 hours for its production line control system. Which recovery strategy would be MOST appropriate?
A) A hot site with real-time data replication. B) A cold site with hardware provisioned within 48 hours. C) A warm site with weekly data backups. D) A reciprocal agreement with a competing firm.
Answer: A Explanation: A 4-hour RTO is aggressive and indicates a critical system. A hot site (A) is designed for near-immediate failover and is the only option that can reliably meet this target. A cold site (B) takes days. A warm site (C) with weekly backups would not meet the RTO or a likely RPO. A reciprocal agreement (D) is generally unreliable for critical systems.---
Question 3An IS auditor is reviewing the project charter for a company's first enterprise-wide BCP. The auditor's PRIMARY concern should be to ensure the BCP development is:
A) led by the information technology department. B) driven by business requirements. C) outsourced to a third-party expert. D) completed within the initial budget.
Answer: B Explanation: This is a foundational CISA principle. Business continuity is a business responsibility. The BCP must be driven by business needs identified through the BIA. If the plan is not aligned with business requirements (B), it will fail. While IT plays a key role (A), they should not lead the effort. Outsourcing (C) and budget (D) are secondary to the plan's effectiveness and business alignment.You can find hundreds more questions like these on the official VoraPrep page for CISA.
What's the Best Strategy for Studying BCP?
When you see a BCP question, find the business driver first. What is the RTO? The RPO? What did the BIA conclude? Frame your analysis around those requirements before you get lost in the technical details.
Remember that BCP connects to other CISA domains:
- Domain 2 (Governance and Management of IT): BCP is a key component of the organization's risk management framework.
- Domain 3 (IS Acquisition, Development and Implementation): When acquiring new systems, you must assess if they meet recoverability requirements, a key part of our guide on CISA vendor evaluation.
- Domain 5 (Protection of Information Assets): Backup media must be properly secured, a topic covered in our guide on the principles of Data Classification and Handling.
In your final study week, redraw the BCP lifecycle from memory. For each stage, write one sentence on its purpose and one on the auditor's role. This will cement the high-level judgment the exam demands.