Business impact analyses questionnaire
Assign topic to the user
1 - What impact analyses should I document?
The business processes to be considered are those related to the defined business continuity objectives. For example, if your business objective is to ensure continuity of customer support services, then the processes related to these services need to undergo business impact analysis (e.g., customer service tickets management, escalation process, etc.).
For further information, see:
- How to implement business impact analysis (BIA) according to ISO 22301 https://advisera.com/27001academy/knowledgebase/how-to-implement-business-impact-analysis-bia-according-to-iso-22301/
2 - Do I do a granulate approach and document things like power outages or does things like power outages become a prerequisite to a process not being available.
Please note that for Business Impact Analysis you do not need to take into account risks, only the impact of the disruption over the processes. Risk identification (so you can identify the ones with the most chance to occur) can be performed either before or after BIA, but it is a completely different and independent process.
For further information, see:
- Risk assessment vs. business impact analysis https://advisera.com/27001academy/knowledgebase/risk-assessment-vs-business-impact-analysis/
Comment as guest or Sign in
Jul 01, 2021