SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Risk assessment and BIA

  Quote
Guest
Guest user Created:   Apr 04, 2017 Last commented:   Apr 04, 2017

Risk assessment and BIA

What would be the best practice for inclusion of ISMS risk in the BIA analysis, or in the questionnaire? My colleague, ISMS manager thinks I should add to BIA questionnaire fields with URLs applications that are used, so we are interested in what is "best practice" for this purpose?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Apr 04, 2017

Answer: In fact BIA and Risk assessment are two different processes with different purposes that can't be merged, although they exchange information between them. They main question between practitioners is in which sequence they should be performed. I particularly follow the thought that risk assessment should be performed before the BIA and the BIA questionnaire, because this way both BIA and questionnaire can make use of the results of risk assessment to help improve the reliability of their results (by identifying the risks you’re most exposed you can focus on consequences of those incidents and the main assets that are under risk).

These articles will provide you further explanation about risk assessment and BIA:
- Risk assessment vs. business impact analys is https://advisera.com/27001academy/knowledgebase/risk-assessment-vs-business-impact-analysis/
- How to implement business impact analysis (BIA) according to ISO 22301 https://advisera.com/27001academy/knowledgebase/how-to-implement-business-impact-analysis-bia-according-to-iso-22301/

These materials will also help you regarding risk assessment and BIA:
- Book Becoming Resilient: The Definitive Guide to ISO 22301 Implementation https://advisera.com/books/becoming-resilient-the-definitive-guide-to-iso-22301-implementation/
- Book ISO 27001 Risk Management in Plain English https://advisera.com/books/iso-27001-annex-controls-plain-english/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Apr 04, 2017

Apr 04, 2017

Suggested Topics

Guest user Created:   Apr 17, 2019 ISO 27001 & 22301
Replies: 1
0 0

Risk assessment and BIA

Guest user Created:   Jan 10, 2018 ISO 27001 & 22301
Replies: 1
0 0

Risk assessment and BIA