During the process of strategy determination as part of solutions design, the Business Continuity (BC) professional should consider and select solutions to deliver agreed strategies in partnership with the:
Answer : C
Solutions Design (PP4) turns requirements from Analysis into practical strategies and solutions (for people, premises, technology, information, suppliers, etc.). Selecting workable solutions requires collaboration with the stakeholders who own the product/service delivery, activities, and critical resources, because they understand operational constraints, dependencies, performance expectations, and what ''minimum acceptable capacity'' really means in practice. This is reinforced by the CBCI module outline for PP4, which includes selecting strategies/solutions and mitigating unacceptable risks/single points of failure---work that depends on detailed operational input from owners.
The finance director may advise on affordability, but is not the primary partner for solution design decisions. A ''department representative'' is vague and may not have authority/knowledge of the specific priority activity or resource. Incident response team leaders focus on incident-time coordination, not necessarily on designing recovery capabilities. Therefore, partnering with the relevant product, activity, or resource owner (option C) is best practice and delivers solutions that are realistic, maintainable, and actually executable during disruption.
Which of the following is NOT an activity that is undertaken as part of the governance of the Business Continuity Management System (BCMS)?
Answer : A
BCMS governance is about direction, oversight, and control---setting expectations, monitoring whether the BCMS is effective, and ensuring it remains fit for purpose. The BCI GPG 7.0 (Lite) highlights that a BCMS must operate and maintain processes and response structures while monitoring and reviewing performance and effectiveness, and using qualitative/quantitative measures to drive continual improvement. Governance also includes ensuring the BCMS aligns with external obligations such as relevant legal and regulatory requirements, because non-compliance can create unacceptable impacts and can influence priorities and recovery requirements.
What governance does not do is ''run the recovery work'' itself. Carrying out specific operational activities (e.g., restoring systems, relocating teams, executing step-by-step recovery tasks) is the role of operational teams and plan owners under the response structure, not BCMS governance. Governance ensures those operational capabilities exist, are resourced, and are validated---but it does not execute them day-to-day. Therefore, option A is the activity that is not part of governance, while options B, C, and D are core governance responsibilities.
Strategic, tactical, and operational plans should always be activated:
Answer : D
The CBCI 7.0 course specifies that activation of strategic, tactical, and operational plans must be based on the conditions or triggering events detailed in each specific plan. Each plan type serves distinct purposes at different organizational levels and phases of incident response. Strategic plans set the overarching direction; tactical plans translate this into actions, and operational plans provide detailed task instructions. The triggering conditions---such as incident severity, scope, or impact---dictate when each plan should be activated to optimize resource use and response effectiveness. Simultaneous activation is neither practical nor efficient. Activation cascading from the strategic team is a controlled process, but ultimately depends on predefined triggers, ensuring an orderly and appropriate escalation.
A Products and Services Business Impact Analysis (BIA) would NOT be used:
Answer : D
In CBCI 7.0 / BCI GPG 7.0, the Analysis practice (PP3) clearly separates two techniques: Business Impact Analysis (BIA) and Risk Assessment. The BIA estimates the impacts of disruption over time to determine response/recovery priorities and resource requirements, while risk assessment analyses relevant risks to prioritised activities (i.e., threats, vulnerabilities, points of failure).
A Products & Services BIA is a strategic-level BIA used to understand which products and services matter most, the impacts if they are disrupted, and therefore supports decisions such as prioritisation and even clarifying/adjusting BCMS scope at a high level. It can also be used when major operational change occurs to re-check disruption impacts and priorities.
However, identifying the likelihood and consequences of specific threats is the role of risk assessment, not the Products & Services BIA. The question's wording (''likelihood and consequences of specific threats'') matches risk assessment language, so option D is the one the Products & Services BIA would NOT be used for.
In your role as a Business Continuity (BC) professional you have submitted your company's first gap analysis to top management for their review and approval. The response is a decision not to address some gaps even though you had recommended some new strategies and solutions. The best course of action is to:
Answer : B
Within CBCI 7.0 (aligned to the BCI GPG 7.0 model), Solutions Design is where strategies are selected that best meet the organization's continuity requirements while remaining viable and proportionate. Crucially, the outcomes of analysis (BIA/RA and any resulting gap picture) are used to highlight ''gaps for top management to address or accept.'' If top management decides not to fully close certain gaps, the BC professional should treat this as a governance decision (risk/impact acceptance) and then work constructively to refine options that improve resilience within the constraints set by management. Recommending adjusted strategies and solutions (option B) supports continual improvement without ignoring leadership's decision, and it keeps momentum by delivering partial risk reduction and capability uplift where feasible.
Option A may be appropriate if the decision appears uninformed, but it does not directly move the BCMS forward. Option C is only one possible input to adjustment (cost is not the only constraint). Option D misplaces the timing---validation tests what exists; it is not the stage to ''re-pitch'' unapproved solutions.
When deciding whether or not to include a product or service in the initial scope of the Business Continuity Management System (BCMS), which of the following would be considered?
Answer : A
In CBCI 7.0 (aligned with BCI GPG 7.0), PP1 -- Establishing a BCMS includes defining the scope of the BCMS as a foundational activity. Scoping decisions must be rational, risk-informed, and aligned to what the organization must protect to survive disruption---especially the delivery of its products and services and achievement of organizational objectives.
Among the answer options, financial value is a legitimate scoping consideration because it directly relates to business objectives (income, margin, cashflow, contractual value, and critical revenue streams). A product/service that generates significant revenue or underpins strategic outcomes typically warrants inclusion, because disruption would quickly create unacceptable impacts and threaten viability.
By contrast, consultation with staff is an important method for gathering inputs, but it is not, by itself, a primary criterion for deciding scope. ''Ease of incorporation'' is not good-practice justification for inclusion (scope is set by business need, not convenience). Competitor approaches may be interesting context, but scope should be determined by the organization's own objectives, obligations, and dependency landscape, not benchmarking alone.
Which of the following would NOT affect the scope of the Business Continuity Management System (BCMS) and lead to the need for the scope of the BCMS to be reviewed?
Answer : D
In CBCI 7.0, PP1 -- Establishing a BCMS includes defining the BCMS scope and recognizing that BCMS activities are not one-time tasks; they evolve as the organization changes. Scope review is normally triggered by changes that materially affect continuity requirements---such as structural changes, changes to products/services, delivery models, locations, technology, critical resources, or external obligations. A merger (A) can significantly change organizational boundaries, critical activities, and dependency networks, requiring scope reassessment. A change in legal/regulatory requirements (B) can introduce new continuity obligations and thresholds for unacceptable impact, again affecting scope. A change in how products/services are delivered (C)---for example increased outsourcing, new platforms, or new channels---changes dependencies and recovery priorities, often requiring scope review.
Option D is different: appointing a communications manager to run a promotion campaign is not, by itself, a material change to continuity requirements or the operating model of prioritized products and services. Unless it creates a new critical service/dependency (which the option does not state), it would not normally trigger a BCMS scope review.