BCLE 2000C PG 03 Jan2019
BCLE 2000C PG 03 Jan2019
Professional’s Role
1. Identify the qualitative and quantitative criteria to be used to assess the impact to the entity as the result
of an event
2. Gain leadership agreement on business impact analysis (BIA) methodology and the criteria to be used to
establish the BIA process and methodology
3. Plan and coordinate data gathering and analysis
4. Establish the criteria and methodology used in conducting the BIA process
5. Analyze the collected data against the approved criteria to establish a recovery time objective (RTO) and
recovery point objective (RPO) for each operational area and the technology that supports those areas
6. Prepare and present the BIA results to leadership. Gain acceptance of the RTO and RPO.
3
BCLE 2000: Canadian Participant’s Guide Lesson 3: Business Impact Analysis
Qualitative:
Customer Impact
Possible customer impacts include:
a. How quickly customers will learn that a problem exists
b. The likelihood that they will take their business elsewhere
c. Concern about meeting existing agreements and service levels
d. The impact to the customer’s supply chain
e. Whether there were any injuries or deaths as a result of the event
Financial Impact
Possible financial impacts include:
a. Loss of revenue
b. Loss of profits
c. Impact to cash flow
d. Impact to market share
e. Impact to the share price of stock (if applicable)
f. Contractual fines or penalties
g. Losses resulting from required payments for fixed costs
h. Increased overtime costs
4
BCLE 2000: Canadian Participant’s Guide Lesson 3: Business Impact Analysis
Regulatory Impact
Possible regulatory impacts include:
a. Fines
b. Penalties
c. Requirements to recall products
d. Revocation of license permits
e. Termination of business
Operational Impact
Possible operational impacts include:
a. Discontinued or reduced product and/or service levels
b. Workflow disruptions
c. Supply chain disruptions
Reputational Impact
Possible reputational impacts include:
a. Negative
• Media attention
• Social media commentary
• Community perception
Example: Wells Fargo – California suspends its relationship with the bank (a major financial loss to
Wells Fargo)
b. Loss of shareholder confidence
Human Impact
Possible human impacts include:
a. Loss of life and injury
b. Impact to the community
c. Short and long term emotional damage
2.
5
BCLE 2000: Canadian Participant’s Guide Lesson 3: Business Impact Analysis
BIA Objectives:
1.
2.
3.
4.
5.
6.
Recovery Objectives
Recovery Time Objective (RTO)
Time goal for the restoration and recovery of functions or resources based on the acceptable down time and
acceptable level of performance in case of a disruption of operations
2.
3.
4.
7
BCLE 2000: Canadian Participant’s Guide Lesson 3: Business Impact Analysis
Restoration Schedule
8
BCLE 2000: Canadian Participant’s Guide Lesson 3: Business Impact Analysis
Dependencies
1. List the other areas, departments, vendors, and external resources the function will need to perform.
Discrepancies?
9
BCLE 2000: Canadian Participant’s Guide Lesson 3: Business Impact Analysis
Resource Requirements
Determine the minimum resource requirements in the following categories:
• Internal and external
• Owned versus non-owned
• Short term versus long term
10
BCLE 2000: Canadian Participant’s Guide Lesson 3: Business Impact Analysis
11
BCLE 2000: Canadian Participant’s Guide Lesson 3: Business Impact Analysis
12
BCLE 2000: Canadian Participant’s Guide Lesson 3: Business Impact Analysis
13
BCLE 2000: Canadian Participant’s Guide Lesson 3: Business Impact Analysis
Important Concepts
Business Impact Analysis Objectives
Dependencies
Vital records
14
BCLE 2000: Canadian Participant’s Guide Lesson 3: Business Impact Analysis
Class Exercise
• Work in assigned teams
• Develop a prioritized list of:
• Functions/processes (at least 3)
• Recovery Time Objective (RTO)
• Order the list by ascending value of RTO
• Select a team presenter to report to the class
15
BCLE 2000: Canadian Participant’s Guide Lesson 3: Business Impact Analysis
Knowledge Checks
Professional Practice Three: Business Impact Analysis
Circle the best choice for each question below. There is only one correct answer for each question.
2. What phrase best describes the reason for establishing recovery point objectives?
a. To establish the time frame in which processes must be restored to prevent an unacceptable impact to
the entity
b. To determine the level of risk and potential loss that leadership is willing to accept
c. To determine the amount of data that will be lost in the event of the data destruction of a storage device
d. To obtain a qualitative estimate of the impact of a threat
3. What phrase best describes the reason for establishing recovery time objectives?
a. To establish the timeframe in which processes must be restored to prevent an unacceptable impact to the
entity
b. To determine the level of risk and potential loss that leadership is willing to accept following an event
c. To determine the point in time when the entity’s EOC must be opened after a disaster is declared
d. To determine the point in time in which transactions and data must be recovered after an outage
4. What is the desired result of the business impact analysis presentation to leadership?
a. Obtaining leadership’s approval for the relative ranking of processes, their RTOs, and resource gaps
b. Obtaining leadership’s approval for implementing recovery strategies
c. Obtaining leadership’s approval for implementing additional controls
d. Obtaining leadership’s approval on reducing the recovery time objective for identified processes
Canadian Resources
Public Safety Canada - Resources
https://www.publicsafety.gc.ca/cnt/rsrcs/index-en.aspx
16