Professional Practice Three - Business Impact Analysis Flashcards Preview

Disaster Recovery Institute > Professional Practice Three - Business Impact Analysis > Flashcards

Flashcards in Professional Practice Three - Business Impact Analysis Deck (33):
0

The BCP will demonstrate knowledge of Business Impact Analysis by (a)

Identify the criteria to be used to quantify and qualify the entity's impact from events.

1

The BCP will demonstrate knowledge of Business Impact Analysis by (b)

Establish the Business Impact Analysis (BIA) process and methodology

2

The BCP will demonstrate knowledge of Business Impact Analysis by (c)

Plan and coordinate data gathering and analysis

3

The BCP will demonstrate knowledge of Business Impact Analysis by (d)

Gain leadership agreement on BIA methodology and criteria to be used

4

The BCP will demonstrate knowledge of Business Impact Analysis by (e)

Analyze the data collected against the approved criteria to establish RTO and RPO for each operational area and the technology that supports them

5

The BCP will demonstrate knowledge of Business Impact Analysis by (f)

Document minimum resource requirements for resumption and recovery of core and support business functions and their escalation over time.

6

The BCP will demonstrate knowledge of Business Impact Analysis by (g)

Prepare and present the BIA results to the entity's leadership and gain acceptance of the RTO and RPO for each process.

7

How does BCP Identify the criteria to be used to quantify and qualify the impact to the entity?

Define and obtain approval for criteria to be used to assess the impact on the entity's operations including 1)Customer impact, 2) Financial impact, 3) Regulatory impact, 4) Operational impact, 5) Reputational impact, 6) Human impact

8

Define Customer impact as it relates to BIA

How quickly customers will know, How worried they will be, What is the likelihood they will seek an alternative, What the impact to service level will be, The impact to supply chain customers, Injury or death of customer.

9

Define Financial impact as it relates to BIA

Loss of revenue, additional cost of recovery, clean up and restoration cost, loss of financial control, impact to cash flow, market share, future sales, share price of stock, contractual fines and penalties, Lawsuits

10

Define Regulatory impact as it relates to BIA

Fines, penalties, recall requirement

11

Define operational impact as it relates to BIA

Reduced services level, increased overtime cost, Workflow disruptions, loss of control, inability to meet deadlines, supply chain disruption

12

Define Reputational impact as it relates to BIA

Media attention, social media, community, shareholder confidence, competitor taking advantage of negative attention

13

Define Human impact as it relates to BIA

Loss of life and injury, impact to the community, stress, long term emotional impact

14

How will BCP establish the BIA process and methodology?

Identify and obtain a sponsor for the BIA, Define objectives and scope for the BIA process, Choose an appropriate BIA planning methodology, Choose an appropriate BIA data collection methodology.

15

Data to be collected include

Operational Process.
Impacts to the process and how those impacts change over time.

16

What are the minimum resource requirements to perform function at the minimum acceptable level?

Technology, Physical Space, Equipment, Vital Records, Personnel, Supplies

17

How would BCP plan and coordinate data gathering and analysis?

Data collection via questionnaires, data collection via interviews, data collection via workshop

18

How would BCP gain the leadership agreement on BIA methodology and criteria to be used? (a)

Identify and obtain agreement as to how potential financial and non- financial impact can be quantified and evaluated in each impact area.

19

How would BCP gain the leadership agreement on BIA methodology and criteria to be used? (b)

Identify and obtain agreement on requirements for non-quantifiable impact information in data collection.

20

How would BCP gain the leadership agreement on BIA methodology and criteria to be used? (c)

Establish definition of the impact scale to be used during the data collection.

21

How would BCP gain the leadership agreement on BIA methodology and criteria to be used? (e)

Identify team members to participate in BiA process

22

How would BCP gain the leadership agreement on BIA methodology and criteria to be used? (f)

Conduct data collection.

23

How would the BCP analyze the data collected against the approved criteria to establish RTO and RPO for each operational area and the technology that supports them? (a)

Based on the data collected, determine the prioritize toon of processes/services

24

How would the BCP analyze the data collected against the approved criteria to establish RTO and RPO for each operational area and the technology that supports them? (b)

Document interdependencies between each business process and the supporting infrastructure.

25

How would the BCP analyze the data collected against the approved criteria to establish RTO and RPO for each operational area and the technology that supports them? (c)

Determine the order of recovery for core and support business functions and technology.

26

How would BCP document minimum resource requirements for resumption and recovery of core and support business functions? (a)

Include internal and external resources, owned vs. non-owned, short vs. long term resource needs, and existing and additional resources.

27

How would BCP document minimum resource requirements for resumption and recovery of core and support business functions? (b)

Vital Records Management - Document vital records and evaluate existing backup and restoration procedures

28

How would BCP document minimum resource requirements for resumption and recovery of core and support business functions? (c)

Identify gaps between current recovery capabilities and requirements defined by the results of the BIA.

29

How would a BCP prepare and present the BIA results to entity's leadership? (a)

Prepare draft BIA report using initial impact and identified gaps.

30

How would BCP document minimum resource requirements for resumption and recovery of core and support business functions? (b)

Prepare final BiA

31

How would BCP document minimum resource requirements for resumption and recovery of core and support business functions? (c)

Prepare and submit formal presentation of BIA findings to entity's leadership.

32

How would BCP document minimum resource requirements for resumption and recovery of core and support business functions? (d)

Gain acceptance of the RTO and RPO for each process as defined by the results of the BIA.