An IS auditor reviewing a business continuity plan (BCP) finds that the plan has not been tested in three years. The MOST significant risk is:
-
A
The plan may contain outdated procedures that fail during an actual disaster
-
B
Staff may be unfamiliar with the document's formatting
-
C
The BCP vendor contract may have expired
-
D
Testing costs have not been budgeted