BCI Risk Assessment & Impact Analysis 3 — Questions and Answers
Question 1: Which of the following best describes a 'threat' in the context of BCI risk assessment methodology?
- A potential cause of an unwanted incident that may harm the organization (Correct answer)
- The likelihood that a vulnerability will be exploited
- The financial value of assets that could be lost
- A documented control gap identified during an audit
Correct answer: A potential cause of an unwanted incident that may harm the organization
A threat is any potential event or action that could negatively impact the organization's ability to deliver its objectives.
Question 2: The BIA process typically begins with identifying:
- Critical business activities and the resources required to perform them (Correct answer)
- IT recovery time objectives for all applications
- The financial budget allocated for business continuity
- All risks listed in the corporate risk register
Correct answer: Critical business activities and the resources required to perform them
The BIA starts by identifying which activities are critical to the organization and mapping what resources they require.
Question 3: A qualitative risk assessment matrix typically plots risks according to:
- Likelihood and impact using descriptive scales such as High/Medium/Low (Correct answer)
- Exact financial cost and statistical probability percentages
- Time to recovery and resource replacement cost
- Regulatory priority and stakeholder concern level
Correct answer: Likelihood and impact using descriptive scales such as High/Medium/Low
Qualitative matrices use descriptive rating scales rather than precise numerical values to position risks.
Question 4: Which scenario best illustrates a 'loss of access' disruption scenario used in BIA?
- A building evacuation prevents staff from reaching their workstations for several days (Correct answer)
- A cyberattack corrupts all data on company servers
- A key supplier fails to deliver critical components
- A pandemic reduces staff availability by 50%
Correct answer: A building evacuation prevents staff from reaching their workstations for several days
Loss of access scenarios specifically address situations where physical entry to premises or resources is denied.
Question 5: In the BCI framework, 'vulnerability' in risk assessment refers to:
- A weakness in an asset or control that could be exploited by a threat (Correct answer)
- The probability that a specific threat will materialize
- The total financial exposure if all risks occur simultaneously
- A gap between current and target recovery capabilities
Correct answer: A weakness in an asset or control that could be exploited by a threat
Vulnerability is an inherent weakness that makes an organization susceptible to harm from a threat source.
Question 6: Which metric specifically measures the point in time to which data must be restored after a disruption?
- Recovery Point Objective (RPO) (Correct answer)
- Recovery Time Objective (RTO)
- Maximum Tolerable Period of Disruption (MTPD)
- Minimum Business Continuity Objective (MBCO)
Correct answer: Recovery Point Objective (RPO)
RPO defines the acceptable data loss measured in time, determining how frequently data backups must occur.
Question 7: When assessing supply chain risk, which factor is most important to evaluate for critical suppliers?
- The supplier's own business continuity arrangements and financial stability (Correct answer)
- The supplier's marketing capabilities and brand reputation
- The geographic proximity of the supplier's head office
- The number of years the supplier has been in business
Correct answer: The supplier's own business continuity arrangements and financial stability
A supplier's own resilience and financial health directly determines whether they can continue to deliver during a crisis.
Which of the following best describes a 'threat' in the context of BCI risk assessment methodology?