Conducting a business impact analysis
One of the most important things for an organization is to ensure that contingency plans are in place to protect the business from adverse events and conditions. Business leaders must ensure that a Business Impact Analysis (BIA) is performed to determine critical systems and services that will have a disproportionate effect on the enterprise if they are not available. Stakeholder involvement is important, enabling the business to identify key business processes.
The first step in the assessment should be the purpose. This can be performed in three steps. See Figure 15.1 for more information:
The initial purpose document can be used to build the contingency plan, while it can also be used as the basis for a DRP. Once key systems are identified, this information can also be used to document an effective cyber incident response plan.
The purpose of a BIA is to identify critical services...