Business Continuity (BC) and Business Impact Analysis (BIA) Flashcards
What is Business Continuity Planning (BCP)?
process of developing prior arrangements and procedures that enable organization to respond to an event so that critical business functions can continue within planned levels of disruption
What is the primary goal of BCP?
enable organizations to maintain essential functions, minimize downtime, and recover critical operations as quickly as possible following a disruption
What is the end result of the planning?
BC plan
What is the Business Continuity Plan (BCP)?
- overall organization plan for “how-to” continue business
- documented collection of procedures and information that is developed, compiled and maintained in readiness for use in an incident
What is Disaster Recovery Plan (DRP)?
- the plan of recovering from a disaster impacting IT and returning the IT infrastructure to operation
- technical aspect of business continuity
What is the difference between BCP and DRP?
- BCP addresses the entire organization’s operations, including people, processes, technology, and facilities
- DRP deals with the technical aspects of recovery, such as restoring IT systems, networks, databases, and applications
What is Business Continuity Management Systems (BCMS)?
- BCMS provides a systematic approach to BCP, incorporating risk assessment, business impact analysis, planning, implementation, testing, and continual improvement
- some organizations adopt formal BCMS based on standards such as ISO 22301
What are three components of BCMS?
- IRP (Incident Response Planning)
- BCP (Business Continuity Planning)
- DRP (Disaster Recovery Planning)
Business Continuity Plan is in place for what occasions?
the times when the duration of an incident affects business operations for an unacceptable period of time
What does BCP integrates with?
- BCP integrates with risk assessment and management processes to identify potential threats and vulnerabilities that could disrupt business operations
- by understanding and mitigating these risks, organizations can develop effective BCP strategies tailored to their specific needs
What is Business Impact Analysis?
- assessing impact over time of the potential disruptions or incidents on an organization’s critical business processes, systems, and resources
- concerned with business impact analysis, not information systems impact analysis
How is the impact measured in BIA?
- quantitative measures
- impact in money
- qualitative
- impact in reputation
What is the purpose of BIA?
- identify and prioritize critical business functions (CBFs) and the potential impacts that could arise from their disruption
- help organizations to understand the financial, operational, reputational, and legal consequences of disruptions
What are the key steps in BIA?
- Identify Critical Functions
- identify and prioritize the organization’s critical business functions, which are essential for its continued operation and achieving its objectives
- Determine Impact Criteria
- used to assess the consequences of disruptions
- may include factors like financial loss, customer impact, regulatory compliance, reputation damage, and legal implications
- Assess Impact and Dependencies
- analyze the potential impact of disruptions on critical functions and identify the dependencies and interdependencies between processes, systems, and resources
- Establish Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs)
- define the acceptable time frames for recovery of critical functions (RTO) and the acceptable level of data loss (RPO) that the organization can tolerate
- Analyze Costs and Resources
- evaluate the resources, personnel, equipment, and financial implications associated with recovering critical functions and maintaining business operations during a disruption
- Document BIA Results
- document the findings of the BIA, including the identified critical functions, impact assessments, dependencies, recovery objectives, and resource requirements
What’s Maximum Tolerable Downtime (MTD)?
- determines the longest period of time that the business is unable to provide its core product until the business fails
- represents the upper limit of acceptable downtime, beyond which the organization’s objectives and functions may be severely impacted
What’s Recovery Time Objective (RTO)?
- defines when the business should recover to an acceptable level from the impact
- represents the targeted timeframe for recovering the affected services, systems, or processes to ensure that they can resume normal operations or provide a minimum level of service
What’s Recovery Point Objective (RPO)?
- represents the point in time to which data must be recovered in order to resume operations effectively
- typically measured in terms of time and indicates the maximum acceptable time gap between the last data backup or synchronization and the point of failure or disruption
What’s Service Delivery Objective (SDO)?
- targeted level of service availability and performance that an organization aims to achieve for its services or systems
- typically defined in the context of service level agreements (SLAs) and outlines the specific requirements and expectations for service availability, response time, throughput, and other performance indicators
- SDO is often tied to key performance indicators (KPIs) and is regularly monitored and reported to ensure that service levels are being met
What’s Maximum Tolerable Outage (MTO)?
- maximum allowable duration of time that a system or service can be unavailable or inaccessible before it significantly impacts the organization’s operations or goals until the business is restored to normal
- encompasses not only the recovery of the system or service but also the time required for any necessary repairs, testing, and verification of functionality
What should emergency response guidelines include?
- immediate steps organization should follow when responding to an emergency situation
- immediate response procedures, list of individuals to contact, secondary response procedures for first responders
- do not inlcude long-term actions
Does CEO serve in the BCP team?
no, but best to obtain top level management approval for the BCP plan