CISA Exam · 14 min read Updated

CISA Information Systems Operations & Resilience: Business Continuity Planning — Complete Study Guide

Rob Pfleghardt

10-year Price Waterhouse alumnus · Founder of VoraPrep · Former CPA (1987–2024) · with the VoraPrep Editorial Team

CISA Information Systems Operations & Resilience: Business Continuity Planning — Complete Study Guide

Key Takeaways

  • The CISA exam tests BCP as a business governance issue first; a technically perfect IT recovery plan that fails to meet business needs is an audit failure.
  • Your role as an auditor is to provide assurance on the BCP, not to write, own, or approve the plan, which would impair your independence.
  • A Business Impact Analysis (BIA) is the mandatory starting point that defines recovery priorities based on Maximum Tolerable Downtime (MTD).
  • The Disaster Recovery Plan (DRP) is the IT-focused subset of the BCP; questions will test your ability to distinguish their scope and purpose.
  • A BCP that has not been tested within the last 12 months (or after a major system change) is considered unreliable and is a significant audit finding.
  • The most common exam trap is choosing a technically valid finding (like concentration risk) over a direct violation of a business-defined RTO or RPO.

Domain 4, Information Systems Operations and Resilience, makes up 29% of your CISA exam score. The single biggest reason candidates fail these questions is they evaluate a Business Continuity Plan (BCP) like an IT manager, approving technically correct solutions. The exam requires you to think like an auditor, and an auditor's first question is always: does this plan actually meet the business's stated needs?

Quick answer

For the CISA exam, Business Continuity Planning (BCP) is the overarching business-led strategy to ensure critical functions remain available during a disruption. It is distinct from the Disaster Recovery Plan (DRP), which is the IT-focused component of the BCP. You will be tested on your ability to audit the BCP's alignment with business-defined objectives like RTO and RPO.

Key facts

  • Official Body: ISACA (Information Systems Audit and Control Association)
  • Relevant Domain: Domain 4: IS Operations and Resilience
  • Domain 4 Weighting: 29% of the CISA exam (approx. 44 questions)
  • Passing Score: 450 on a scaled score range of 200-800
  • Typical Study Hours: 150-200 hours over 2-3 months
  • U.S. Salary Range: $100,000 - $160,000+ (varies by location and experience)

What is Business Continuity Planning for the CISA Exam?

Business Continuity Planning is the holistic management process for identifying potential threats to an organization and the impacts to business operations those threats, if realized, might cause. It provides a framework for building organizational resilience with the capability for an effective response that safeguards the interests of its key stakeholders.

For your CISA exam, this isn't just a definition to memorize. It's a lens through which you must evaluate every scenario in Domain 4. The examiner wants to see if you can spot the disconnect between a company's IT actions and its business strategy. Try VoraPrep's free CISA practice questions to see how this judgment is tested.

Free 5-Min Diagnostic

Studying for CISA CISA4? Benchmark your score in 5 minutes.

Get an instant weak-spot assessment and a custom 12-week study plan PDF generated for your exam window.

An auditor's conclusion is always anchored to business requirements.

The BCP Ecosystem: DRP, IRP, and Crisis Management

Candidates often confuse BCP with its components. The exam will penalize you for this. A BCP is the umbrella strategy; the other plans are specific, tactical responses that fall underneath it.

  • Business Continuity Plan (BCP): The overall strategic plan, owned by the business. It focuses on keeping critical business functions running during a disruption. It asks, "How do we continue to take orders and serve customers?"
  • Disaster Recovery Plan (DRP): The technical, IT-focused component of the BCP. It details the procedures to recover IT infrastructure, applications, and data. It asks, "How do we restore the servers and databases at the alternate site?"
  • Incident Response Plan (IRP): A short-term plan for managing the immediate effects of an incident (e.g., a cyberattack). It focuses on containment, eradication, and recovery from the specific event. It asks, "How do we stop the ransomware from spreading and remove it?"
  • Crisis Management Plan (CMP): The high-level plan for managing communications and the overall organizational response. It deals with executive decision-making, public relations, and stakeholder communication. It asks, "What do we tell our customers, regulators, and the media?"

On the exam, a plan to restore servers is a DRP. A plan to handle a data breach is an IRP. The BCP is the master plan that integrates them all to ensure the business survives.

What are the Core Components of a BCP?

The CISA exam tests your understanding of the BCP lifecycle. You must know the purpose of each stage and the auditor's role in evaluating it.

The Foundation: Business Impact Analysis (BIA)

The BIA is the non-negotiable starting point. It is a formal process to determine and evaluate the potential effects of an interruption to critical business operations. The BIA is what provides the data to justify all subsequent BCP decisions.

The BIA identifies:

  1. Critical business processes.
  2. The impact of a disruption to those processes over time (financial, reputational, legal).
  3. The Maximum Tolerable Downtime (MTD), also called Maximum Acceptable Outage (MAO). This is the absolute longest the business can survive without a specific process.

From the MTD, two critical metrics are derived:

  • Recovery Time Objective (RTO): The targeted time within which a business process must be restored after a disaster. The RTO must always be less than or equal to the MTD.
  • Recovery Point Objective (RPO): The maximum amount of data loss the business can tolerate, measured in time. An RPO of 15 minutes means the business can't afford to lose more than 15 minutes of transaction data.

Strategy and Plan Development

Based on the BIA's RTO and RPO findings, the organization selects recovery strategies. As an auditor, you must assess if the chosen strategy can realistically meet these objectives.

Recovery StrategyTypical RTOTypical RPOBest For
Hot SiteMinutes to hoursSeconds to minutesCritical systems with zero to minimal tolerance for downtime or data loss.
Warm SiteHours to daysHoursSystems that can tolerate some downtime for data restoration.
Cold SiteDays to weeksDaysNon-critical systems where extended downtime is acceptable.
Cloud-based FailoverVaries (seconds to hours)Varies (seconds to hours)Highly scalable and flexible; can support very aggressive RTO/RPO.
Reciprocal AgreementUnreliable (weeks)UnreliableLow-criticality functions; often not a viable primary strategy due to conflicts of interest.

Testing the Plan

A plan that hasn't been tested is merely a document. The CISA exam requires you to know the hierarchy of tests and recommend the most appropriate one for a given context.

Test TypeDescriptionAuditor's Perspective
Desk Check / Read-throughA simple review of the plan by key team members.Good for initial validation and training, but provides no real assurance.
Structured Walk-throughA tabletop exercise where the team talks through a disaster scenario.Better for identifying gaps in roles and procedures, but still theoretical.
Simulation TestA practice run of a specific scenario in a test environment.Good for testing response procedures without impacting production systems.
Parallel TestRecovery systems are run in parallel with production systems.Tests the actual recovery environment but is complex and costly.
Full-Interruption TestProduction systems are shut down and the business fails over to the recovery site.Provides the highest level of assurance but carries the highest risk and business disruption.

Maintaining the Plan

The BCP is a living document. It must be reviewed and updated at least annually or whenever a significant change occurs in business processes, technology, or personnel. As an auditor, your first check should be the date of the last BIA, the last plan update, and the last test. An outdated plan is an ineffective plan.

How Do You Solve a CISA Business Continuity Scenario?

Let's walk through a typical CISA scenario. This is about applying principles, not just recalling facts.

Scenario: FinCore Bank provides online banking services. A recent Business Impact Analysis (BIA) for its core transaction processing system established the following requirements:
  • Recovery Time Objective (RTO): 2 hours
  • Recovery Point Objective (RPO): 30 minutes

The IS auditor is reviewing the bank's Disaster Recovery Plan (DRP), which states that the system is backed up using the following procedure:

  • A full backup is performed every night at midnight to tape. Tapes are sent offsite the next morning.
  • Transaction logs are backed up every 60 minutes to a server in the same data center.

Which of the following is the MOST significant audit finding?

A) The RTO of 2 hours cannot be met because tapes are sent offsite. B) The DRP does not account for denial-of-service attacks. C) The RPO of 30 minutes is not supported by the current backup strategy. D) The use of a single data center for transaction log backups represents a concentration risk.

Step 1: Anchor on the Business Requirements from the BIA

First, ignore the technology. The business has explicitly stated its needs:

  • Maximum tolerable data loss (RPO) = 30 minutes.
  • Maximum tolerable downtime (RTO) = 2 hours.

These are your non-negotiable audit criteria.

Step 2: Analyze the Technical Implementation in the DRP

Now, map the DRP's capabilities to the requirements.

  • Full backup: Once every 24 hours.
  • Transaction log backup: Once every 60 minutes.

If a disaster strikes at 2:55 PM, the last successful log backup was at 2:00 PM. This means 55 minutes of transaction data (from 2:00 to 2:55) would be lost.

Step 3: Compare Requirements to Implementation
  • RPO Check: The business requires a maximum data loss of 30 minutes. The backup strategy results in a potential data loss of up to 60 minutes. This is a direct, mathematical failure. The RPO is not met.
  • RTO Check: Can they recover in under 2 hours? The scenario doesn't give enough information. Recovering from tape can be slow, but we can't definitively say it will take more than 2 hours. This is a potential issue, but not as certain as the RPO failure.
Step 4: Evaluate the Tempting Wrong Answers
  • (D) The use of a single data center for transaction log backups represents a concentration risk. This is a completely valid audit finding. If the data center is destroyed, the log backups are lost too. However, the RPO is violated even if the disaster doesn't destroy the data center. The 60-minute backup frequency is a fundamental design flaw that fails the business requirement on its own. The RPO violation is more significant than the concentration risk.
  • (A) The RTO of 2 hours cannot be met because tapes are sent offsite. This is a plausible concern, but it's an assumption. We don't know the tape recall time or restoration speed. The RPO failure is a mathematical certainty based on the information given. Auditors report on facts, not assumptions.
  • (B) The DRP does not account for denial-of-service attacks. The scenario is about recovery from a system failure, not a specific threat. While a good plan should consider various threats, the immediate, measurable failure here is the gap between the stated business objective (RPO) and the technical capability.
Step 5: Select the Best Answer (C) The RPO of 30 minutes is not supported by the current backup strategy. This is the most significant finding because it is a direct, measurable violation of a business requirement defined in the BIA. The other issues are valid risks but are either secondary (D) or based on assumptions (A).

This is the judgment the CISA exam demands. The VoraPrep adaptive learning engine is designed to find your specific weak spots in this kind of analysis and serve you more questions to build that muscle.

Can You Pass These CISA Practice Questions on BCP?

Test your understanding with these sample questions.

✨ Free Domain Calculator

Calculate Your CISA Study Hours by Domain

See the exact domain-by-domain study breakdown reflecting the 2024 ISACA Job Practice weighting shifts.

Calculate CISA Study Plan →

---

Question 1

During an audit of a financial institution's BCP, an IS auditor finds that while the data center has a detailed DRP, several key business departments have not documented their manual workarounds. Which of the following is the auditor's BEST course of action?

A) Recommend immediate disciplinary action for the department heads. B) Develop the manual workaround procedures for the departments. C) Report the finding to senior management as a significant gap in the BCP. D) Accept the risk as it is primarily a business, not an IT, issue.

Answer: C Explanation: The auditor's role is to identify risks and report them. A BCP is incomplete if it only covers IT recovery and ignores business processes. (C) correctly reflects the auditor's responsibility. (A) is outside the auditor's authority. (B) impairs independence by performing management's job. (D) is wrong because the integration of IT and business processes is a core CISA concern.

---

Question 2

A manufacturing firm's BIA specifies a Recovery Time Objective (RTO) of 4 hours for its production line control system. Which recovery strategy would be MOST appropriate?

A) A hot site with real-time data replication. B) A cold site with hardware provisioned within 48 hours. C) A warm site with weekly data backups. D) A reciprocal agreement with a competing firm.

Answer: A Explanation: A 4-hour RTO is aggressive and indicates a critical system. A hot site (A) is designed for near-immediate failover and is the only option that can reliably meet this target. A cold site (B) takes days. A warm site (C) with weekly backups would not meet the RTO or a likely RPO. A reciprocal agreement (D) is generally unreliable for critical systems.

---

Question 3

An IS auditor is reviewing the project charter for a company's first enterprise-wide BCP. The auditor's PRIMARY concern should be to ensure the BCP development is:

A) led by the information technology department. B) driven by business requirements. C) outsourced to a third-party expert. D) completed within the initial budget.

Answer: B Explanation: This is a foundational CISA principle. Business continuity is a business responsibility. The BCP must be driven by business needs identified through the BIA. If the plan is not aligned with business requirements (B), it will fail. While IT plays a key role (A), they should not lead the effort. Outsourcing (C) and budget (D) are secondary to the plan's effectiveness and business alignment.

You can find hundreds more questions like these on the official VoraPrep page for CISA.

What's the Best Strategy for Studying BCP?

When you see a BCP question, find the business driver first. What is the RTO? The RPO? What did the BIA conclude? Frame your analysis around those requirements before you get lost in the technical details.

Remember that BCP connects to other CISA domains:

  • Domain 2 (Governance and Management of IT): BCP is a key component of the organization's risk management framework.
  • Domain 3 (IS Acquisition, Development and Implementation): When acquiring new systems, you must assess if they meet recoverability requirements, a key part of our guide on CISA vendor evaluation.
  • Domain 5 (Protection of Information Assets): Backup media must be properly secured, a topic covered in our guide on the principles of Data Classification and Handling.

In your final study week, redraw the BCP lifecycle from memory. For each stage, write one sentence on its purpose and one on the auditor's role. This will cement the high-level judgment the exam demands.

⚡ Instant Knowledge Check · 1-Click Test Drive
CISA Domain 5: Protection of Information Assets

When conducting an IS audit of an enterprise cloud infrastructure environment, which of the following identity and access management (IAM) findings represents the GREATEST information security risk?

Official resources and references

Frequently asked questions

How many questions on Business Continuity Planning appear on the CISA exam? Domain 4 is 29% of the 150-question exam, which is about 44 questions. BCP and DRP are the largest components of this domain, so you can expect 15-20 questions directly related to business resilience. What's the best way to study Business Continuity Planning? Focus on the concepts and the "why" behind each step. Use practice questions heavily to train your judgment in applying these concepts to scenarios, paying close attention to the explanations for both right and wrong answers. Is Business Continuity Planning tested in simulations or only multiple-choice questions? The CISA exam consists entirely of multiple-choice questions. There are no simulations. However, the questions are scenario-based and require you to apply knowledge to make a judgment, not just recall facts. How long should I spend studying Business Continuity Planning? Given Domain 4 is 29% of the exam, you should allocate about 29% of your study time to it. If you plan for 150 hours total, that means about 40-45 hours should be dedicated to the topics in this domain, with a significant portion focused on BCP and DRP.

---

Ready to Pass Your CISA Exam?

You don't have to study alone. VoraPrep's CISA course is designed to teach you how to think like the examiner. Our adaptive learning engine finds your weak spots, and our 2,300+ practice questions come with detailed explanations that build your audit judgment.

Visit voraprep.com to get started and see why hundreds of candidates trust us to help them pass.

Start Your Free 14-Day Trial at voraprep.com →
RP

About the Author: Rob Pfleghardt

Rob Pfleghardt is the founder of VoraPrep, a comprehensive exam prep platform for the CPA, CMA, EA, CIA, CISA, and CFP exams. A Virginia Tech graduate in Accounting and Finance, Rob began his career at Price Waterhouse, spending a decade in audit and IT consulting. After holding a CPA license for 37 years (1987–2024) and successfully scaling his own enterprise IT consultancy serving the Department of Defense, Rob launched VoraPrep. He now leverages his deep systems architecture background to build the adaptive training technology and curriculum that helps candidates pass their certification exams efficiently.

Connect with Rob on LinkedIn →
Free Diagnostic Assessment

Find your exact CISA weak spots in 10 minutes.

Most candidates fail because they study blindly. Take our free 10-question diagnostic to identify your weakest blueprint topics and receive a custom 12-week study plan PDF generated instantly.

Keep reading

Free 5-min CISA diagnostic + 12-week plan PDF

Start →
CISA 1:1 Prometric Simulator

2,300+ practice questions with instant Socratic feedback