I have questions related to business continuity , I'm in process of updating BC for all department and I found that the critical department at the time of the disaster only HR , Finance, communication and IT and only few process with each department not all department processes.
So I did BIA for the critical process for those departments only.
But I don't know how to do BIA for communication department , they already have crisis communication plan and the criticality of their process depend on the level of the emergency event.
What is your advice?
Answer:
The main input for the BIA is the BIA Methodology, and you need one to perform the BIA in the same way for all your processes, I mean, if you have your BIA methodology and your BIA questionnaire, you only need to apply them for all your processes, regardless of the documents or activities that contains. So my recommendation is to have an unique methodology for all processes, and perform the BIA according your methodology. To know the criticality of your processes, my recommendati on is that you use these parameters: Impact assessment, Maximum Data Loss/RPO, MAO, MBCO, Dependencies, etc.
This article about how to implement the BIA can be interesting for you How to implement business impact analysis (BIA) according to ISO 22301 : https://advisera.com/27001academy/knowledgebase/how-to-implement-business-impact-analysis-bia-according-to-iso-22301/
And maybe can be interesting for you to see our BIA methodology (you can see a free version clicking on Free Demo tab) Business Impact Analysis Methodology : https://advisera.com/27001academy/documentation/business-impact-analysis-methodology/
Comment as guest or Sign in
Jan 12, 2016