|
Home::All
Business Continuity and Disaster Recovery - Business Impact Analysis
Author : Robert Mahood
Business impact analysis is a critical part of the business continuity planning process. This step quantifies data and gets into the real world issue of potential losses that can negatively impact your business. It is used to understand the most important impacts and how to best protect your people, processes, data, communications, assets and the organization’s goodwill and reputation. Organizations often think in terms of disaster recovery. Business continuity and the business impact analysis is more focused on keeping the business up and running and less focused on recovery after a disaster. The business impact analysis also is not focused only on the potential disasters, but on all potentially critical discontinuities. Key elements of the Business Impact Analysis are to identify critical business functions, establish the maximum acceptable outage time for each of these functions and then to determine the impact of not performing those functions. This can be measured against regulatory, legal, financial, operations or customer service requirements. Once the adequacy of security and controls is evaluated and critical business functions and outage times are defined, the business continuity planner needs to develop an understanding of the probability of threats factored by the severity or impact and to start to develop a cost benefit analysis of the largest impact and highest probability threats. It’s virtually impossible to create an absolute value and prioritization of threats and impacts. Generally, a relational system is used to drive out the key priorities. Often, each threat is evaluated according to its probability and assigned a 1, 5 or 10 rating. Then, each threat is evaluated according to its impact on critical business functions and on the business overall. For example, a discontinuity in a critical business function of less than one hour might receive a value of 0. A discontinuity of one to eight hours might be ranked a 1, eight to twenty four hours might be ranked a 2 and over 24 hours might be ranked a 3. Obviously, these rankings need to be developed on a company specific basis. Probability factored by impact creates the relational prioritization list. This approach to risk evaluation and control allows management to start to quantify the risks and potential impacts on the organization in a thoughtful and analytical way. This results not only in higher quality decisions, but also provides an audit trail that demonstrates that management is paying attention to its risk management responsibilities. These responsibilities might be established by regulatory or legal bodies, demanded as a contractual commitment by customers or simply expected by shareholders as sound and prudent management. The key corporate goals are to protect people, protect assets, protect data and to protect the brand and reputation of the organization. About The Author Robert Mahood has significant technology and management experience in data communications, internet, storage, disaster recovery and data recovery. He is currently the president of Midwest Data Recovery. www.midwestdatarecovery.com bmahood@midwestdatarecovery.com, 312 907 2100 or 866 786 2595 Spam emails More free articles Related articles
|
More related feeds |
AT&T Study: Nearly One in Five North Carolina Businesses Does Not ... AT&T brings its own business continuity and disaster recovery expertise in running and managing some of the world's largest and most complex networks — including its own — to businesses worldwide. AT&T offers a wide array of business ...Business Continuity and Disaster Recovery - Busine Organizations often think in terms of disaster recovery. Business continuity and the business impact analysis is more focused on keeping the business up and running and less focused on recovery after a disaster. The business impact ... Business Continuity and Disaster Recovery - Risk A Business Continuity and Disaster Recovery - Risk Analysis and Control. by: Robert Mahood. In the risk evaluation phase, there are a number of key areas that must be covered. One of the most important is to understand probable threats. ... A strategy for survival: developing a sound business continuity plan Once there is a clearer picture of the risks involved, a business impact analysis will help to determine which applications require the most protection based on value of the data and the business impact of downtime. ... Business Continuity and Disaster Recovery - Select Business Continuity and Disaster Recovery - Selecting A Business Continuity Strategy. by: Robert Mahood. The risk analysis and business impact analysis have identified risks to key business functions. Also, the potential impacts and ... Business Continuity and Disaster Recovery - Reduci However, through risk analysis, business impact analysis, selecting effective strategies, documenting detailed recovery plans and testing your plans, you can significantly reduce many of your risks, often in a very cost effective way. ... Identifying Priorities in Business Continuity Planning (BCP) using ... operation, the more expensive the recovery options. For RPO, the more-critical the need for data currency, the greater the cost of maintaining that currency. Check out to DRII’s — Business Impact Analysis — http://www.drii.org/ — for a ... The Latest DRP Template Update If you are not thoroughly satisfied with the collection of documents and templates included in the the Disaster Recovery & Business Continuity Template Pack, let us know within 30 days and we will refund 100% of your purchase price. ... Business Continuity and Disaster Recovery - Risk Analysis and Control This requires an extensive scan of the organization to identify vulnerabilities and then analysis to understand those vulnerabilities which would have the greatest impact on your critical business processes and the organization. ... Sorry, the server抯 down, can you call back later? Part 1 The potential for a real impact on your business is massive, so what抯 the answer? The first step is to review what plans you have in place already. You may have a Disaster Recovery or some kind of Business Continuity plan or you may ...
|
|
|