What are the three steps that should be performed in a business impact analysis BIA )?

What are the three steps that should be performed in a business impact analysis BIA )?

What is Business Impact Analysis?

Business Impact Analysis or BIA refers to the process of identifying an organization’s Critical Business Functions (CBFs) and analyzing the potential disruptive impact to the business. The BIA can be used to:

  • Assess the impact of a disruption to any functional area or business operations within the organization
  • Determine the extent to which key functional and operational dependencies exist within the organization
  • Establish the priorities and sequence in which critical IT applications and key business functions should be restored

Objectives

The objectives of a BIA are to:

  • Determine the criticality of individual business functions in the organization
  • Determine the impact of a disruption on CBFs, e.g. financial and non-financial losses
  • Determine the tolerable limits of failure or loss of each CBF
  • Determine the minimum resources to be allocated to recover and resume the CBFs
  • Determine the sequence of recovering CBFs in the event of a disaster
  • Identify the inter- and intra-dependences among the CBFs
  • Identify the vital records needed to support the resumption and recovery of the CBFs

Tasks

The tasks to be led by the BCP Manager (Organization BCM Coordinator) and completed within the BIA phase include:

  • Establish business criticality/ impact criteria using BIAQ
  • Prioritize the importance of each business unit vis-à-vis established criteria
  • Consolidate findings and rankings
  • Present results to the Executive Management to confirm critical classifications and priority listings

Expected Deliverables

The expected deliverables in a typical BIA phase are:

  • Detailed report on findings (approved by the Executive Management) containing:
    • Prioritized Critical Business Functions
    • Classification of Criticality
    • Tolerable Limits
    • Restoration Priority
  • Impact analysis (both quantitative and qualitative) of unavailable business functions, i.e. extent of problems and damage arising as a result of those business functions becoming unavailable
    • Minimum resources needed to recover the prioritized Critical Business Functions

What Does BIA Development Process Entail?

The entire BIA process involves the following steps:

Gather Information
  • Design a BIAQ
  • Gather initial information about business functions, support systems, and IT applications through the use of BIA Questionnaires
Verify & Analyze Information
  • Validate the content of the submitted BIAQ with Business Unit (BU) BCM Coordinators
  • Conduct face-to-face interviews with BU BCM Coordinators to verify the accuracy of the information submitted
  • Analyze information to determine priorities for recovery of business operations, systems and IT applications
  • Establish a Recovery Time Objective (RTO) for each CBF, i.e. time taken from disruption until recovery of operations
Document & Present Findings
  • Prepare the executive summary and BIA report
  • Include recovery priorities supported by graphs, charts, and other visual aids
  • Present findings and recommendations to the Executive Management in written and oral reports
  • Update the Executive Management on the subsequent steps in the BCM planning process

Reference

What are the three steps that should be performed in a business impact analysis BIA )?
Goh, M. H. (2021). Conducting Your Impact Analysis for Business Continuity Planning. Business Continuity Management Planning Series (3rd ed.). Singapore: GMH Pte Ltd.

Extracted from "Chapter 2: What is Business Impact Analysis?"

More Information About Blended Learning BCM-5000 [BL-B-5]

To know more about our blended learning program and when the next course is scheduled, feel free to contact our friendly course consultant colleagues via .  They are the BL-B-3 Blended Learning BCM-300 ISO22301 BCMS Implementer and the BL-B-5 Blended Learning BCM-5000 ISO22301 BCMS Expert Implementer.

What are the steps in performing BIA?

Our process follows five key steps..
Step 1: Scope the Business Impact Analysis. ... .
Step 2: Schedule Business Impact Analysis Interviews. ... .
Step 3: Execute BIA and Risk Assessment Interviews. ... .
Step 4: Document and Approve Each Department-Level BIA Report. ... .
Step 5: Complete a BIA and Risk Assessment Summary..

What are the three methods of impact analysis?

Methods Used for Impact Analysis Scoping or checklists. Qualitative analysis; developing focus groups. Quantitative analysis.

What are the three key outputs of the BIA process?

The BIA quantifies the impacts of disruptions on service delivery, risks to service delivery, and recovery time objectives (RTOs) and recovery point objectives (RPOs).

What are the three goals of a business impact analysis?

Detailed understanding of what your business absolutely must achieve (the critical objectives). An understanding of what interruptions may be faced in trying to achieve these critical objectives. Able to predict the probable outcome of controls and other mitigation strategies.