Systems Security Certified Practitioner – SSCP – Question0601

A Business Continuity Plan should be tested:

A.
Once a month.
B. At least twice a year.
C. At least once a year.
D. At least once every two years.

Correct Answer: C

Explanation:

It is recommended that testing does not exceed established frequency limits. For a plan to be effective, all components of the BCP should be tested at least once a year. Also, if there is a major change in the operations of the organization, the plan should be revised and tested not more than three months after the change becomes operational.
Source: BARNES, James C. & ROTHSTEIN, Philip J., A Guide to Business Continuity Planning, John Wiley & Sons, 2001 (page 165).