Certified Risk and Information Systems Control (CRISC) Exam: Resilient Business and Information Systems Processes

Resilient Business and Information Systems Processes

Prev Question Next Question

Question

Which of the following business requirements MOST relates to the need for resilient business and information systems processes?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

D.

Availability relates to information being available when required by the business process in present as well as in future.

Resilience is the ability to provide and maintain an acceptable level of service during disasters or when facing operational challenges.

Hence they are most closely related.

Incorrect Answers: A: Integrity relates to the accuracy and completeness of information as well as to its validity in accordance with business values and expectations.

While the lack of system resilience can in some cases affect data integrity, resilience is more closely linked to the business information requirement of availability.

B: Confidentiality deals with the protection of sensitive information from unauthorized disclosure.

While the lack of system resilience can in some cases affect data confidentiality, resilience is more closely linked to the business information requirement of availability.

C: Effectiveness deals with information being relevant and pertinent to the business process as well as being delivered in a timely, correct, consistent and usable manner.

While the lack of system resilience can in some cases affect effectiveness, resilience is more closely linked to the business information requirement of availability.

The business requirement that MOST relates to the need for resilient business and information systems processes is availability.

Availability refers to the ability of systems and processes to be accessible and functioning when needed. Resilient business and information systems processes ensure that services are available and can continue to operate during unforeseen disruptions, such as system failures, cyber-attacks, natural disasters, or other disruptions that could interrupt business operations.

Business and information systems processes must be designed and implemented in a way that ensures the continuity of critical business functions, even in the face of unexpected disruptions. This requires implementing redundancy, failover, backup and recovery, and other strategies to minimize downtime and ensure that services are available when needed.

Confidentiality, integrity, and effectiveness are also important business requirements, but they do not directly relate to the need for resilient business and information systems processes. Confidentiality relates to the protection of sensitive information from unauthorized access, disclosure, or theft. Integrity relates to the accuracy and completeness of data and information. Effectiveness relates to the ability of systems and processes to meet the needs and objectives of the business.

In summary, the business requirement that MOST relates to the need for resilient business and information systems processes is availability. Resilient systems ensure that services are available and can continue to operate during unforeseen disruptions, and require redundancy, failover, backup, and recovery strategies to minimize downtime and ensure that services are available when needed.