Expert Advice Community

Guest

BIA scope

  Quote
Guest
Guest user Created:   Jan 13, 2017 Last commented:   Jan 13, 2017

BIA scope

I am facing an issue where the operation department within the organization has only provided me with the main services provided and they cannot decide what the support services are. For example, the HR department handles salaries and Its considered a support activity which needs to be part of the BIA. However, the HR department also has activities which are unrelated to the main activities. So how can I decide on what activities are considered related and unrelated, is there an example you can provide me that will detail what to add and what to avoid.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Jan 13, 2017

Answer: The most suitable people to answer what activities should be considered related or unrelated to your main services are the processes owners and the key users (people that have the best knowledge of the process).

In your example, you should ask the person who handles salaries which activities he relies on to deliver his results (e.g., salaries payment), or what would be the worst thing that could happen that would prevent the salaries to be paid. From the answers of these two questions you can identify activities you should consider related to your main process.

Regarding more examples, in the video tutorials that came with your toolkit, you will see how to make considerations for what is related or not to your main process while filling out all the data regarding BIA.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 13, 2017

Jan 13, 2017