BCI Risk Assessment & Impact Analysis 2 — Questions and Answers
Question 1: Which technique uses a structured 'what-if' approach to systematically identify potential failure modes in a business continuity context?
- HAZOP (Hazard and Operability Study) (Correct answer)
- PESTLE Analysis
- Porter's Five Forces
- Gap Analysis
Correct answer: HAZOP (Hazard and Operability Study)
HAZOP systematically examines processes using guide words to identify deviations that could cause disruptions.
Question 2: In a Business Impact Analysis, what does the term 'single point of failure' refer to?
- A component whose failure causes the entire system or process to stop functioning (Correct answer)
- The first point at which financial losses begin
- A backup system that can only handle one type of failure
- The single most likely risk in a risk register
Correct answer: A component whose failure causes the entire system or process to stop functioning
A single point of failure is any non-redundant element whose failure would halt the entire dependent system or process.
Question 3: The BCI Good Practice Guidelines recommend that BIA data should be validated by:
- Senior management and process owners, not just IT (Correct answer)
- Only the BCM team to maintain confidentiality
- External auditors on an annual basis only
- The board of directors exclusively
Correct answer: Senior management and process owners, not just IT
BIA outputs must be validated by process owners and senior management to ensure accuracy and business relevance.
Question 4: Which risk treatment option involves accepting the potential consequences of a risk without taking mitigating action?
- Risk retention (Correct answer)
- Risk avoidance
- Risk transfer
- Risk reduction
Correct answer: Risk retention
Risk retention (or acceptance) means the organization consciously decides to absorb the impact if the risk materializes.
Question 5: When conducting a BIA, 'interdependency mapping' is used to:
- Identify upstream and downstream dependencies that could amplify disruption impact (Correct answer)
- Map the geographical locations of all business units
- Chart reporting lines within the incident management team
- Document software version dependencies in IT systems only
Correct answer: Identify upstream and downstream dependencies that could amplify disruption impact
Interdependency mapping reveals how a disruption to one process can cascade to affect other connected processes.
Question 6: What is the primary purpose of a Maximum Tolerable Period of Disruption (MTPD)?
- To define the absolute time limit beyond which business viability is threatened (Correct answer)
- To set the target for how quickly IT systems must be restored
- To measure the average downtime experienced historically
- To establish the timeframe for notifying regulators after an incident
Correct answer: To define the absolute time limit beyond which business viability is threatened
MTPD is the outer boundary of acceptable disruption, after which the organization may not be able to survive as a going concern.
Question 7: In risk assessment, 'inherent risk' differs from 'residual risk' in that inherent risk is:
- The risk level before any controls are applied (Correct answer)
- The risk remaining after all mitigation measures are in place
- The risk transferred to a third party via insurance
- The risk identified through historical incident data only
Correct answer: The risk level before any controls are applied
Inherent risk is the raw, uncontrolled risk level; residual risk is what remains after controls are implemented.
Which technique uses a structured 'what-if' approach to systematically identify potential failure modes in a business continuity context?