Which of the following BEST describes the objectives of the business impact analysis (BIA)

© 2022 - Free Practice Exam Collection - www.freecram.net | DMCA

Disclaimer:
www.freecram.net doesn't offer Real GIAC Exam Questions.
www.freecram.net doesn't offer Real SAP Exam Questions.
www.freecram.net doesn't offer Real (ISC)² Exam Questions.
www.freecram.net doesn't offer Real CompTIA Exam Questions.
Oracle and Java are registered trademarks of Oracle and/or its affiliates
www.freecram.net material do not contain actual actual Oracle Exam Questions or material.
www.freecram.net doesn't offer Real Microsoft Exam Questions.
Microsoft®, Azure®, Windows®, Windows Vista®, and the Windows logo are registered trademarks of Microsoft Corporation
www.freecram.net Materials do not contain actual questions and answers from Cisco's Certification Exams. The brand Cisco is a registered trademark of CISCO, Inc
CFA Institute does not endorse, promote or warrant the accuracy or quality of these questions. CFA® and Chartered Financial Analyst® are registered trademarks owned by CFA Institute.
www.freecram.net does not offer exam dumps or questions from actual exams. We offer learning material and practice tests created by subject matter experts to assist and help learners prepare for those exams. All certification brands used on the website are owned by the respective brand owners. www.freecram.net does not own or claim any ownership on any of the brands.

The purpose of the BIA is to identify and prioritize system components by correlating them to the mission/business processes that the system supports and using this information to characterize the impact on those processes if the system were unavailable.

WWT services are designed using the ISO Technical Standard for Business Impact Analysis (BIA) and are aligned with industry-leading accrediting agencies. Based on interviews, WWT will gather business impact and recovery requirements to support the critical business processes.

The BIA is composed of the following three steps: 

  1. Determine mission/business processes and recovery criticality. Mission/business processes supported by the system are identified and the impact of a system disruption to those processes is determined along with outage impacts and estimated downtime. The downtime should reflect the maximum that an organization can tolerate while still maintaining the mission.
  2. Identify resource requirements. Realistic recovery efforts require a thorough evaluation of the resources required to resume mission/business processes and related inter-dependencies as quickly as possible. Examples of resources that should be identified include facilities, personnel, equipment, software, data files, system components and vital records.
  3. Identify recovery priorities for system resources. Based upon the results from the previous activities, system resources can more clearly be linked to critical mission/business processes. Priority levels can be established for sequencing recovery activities and resources.

WWT will determine, based on our process, the Maximum Tolerable Downtime (MTD) for the applications. The MTD represents the total amount of time leaders/managers are willing to accept for a mission/business process outage or disruption and includes all impact considerations. Determining MTD is important because it could leave continuity planners with imprecise direction on (1) selection of an appropriate recovery method, and (2) the depth of detail which will be required when developing recovery procedures, including their scope and content.

 WWT will also identify a Recovery Time Objective (RTO). RTO defines the maximum amount of time that a system resource can remain unavailable before there is an unacceptable impact on other system resources, supported mission/business processes and the MTD. Determining the information system resource RTO is important for selecting appropriate technologies that are best suited for meeting the MTD.

 Finally, we will determine a Recovery Point Objective (RPO). The RPO represents the point in time, prior to a disruption or system outage, to which mission/business process data must be recovered (given the most recent backup copy of the data) after an outage.

 Selected Deliverables 

  • Document inter-dependencies between business process and the supporting applications (data /applications, supply chain management, third-party partners and other resources)
    • Intra-departmental 
    • Inter-departmental 
    • External relationships 
  • Document the order of recovery for core and supporting business functions and technology 
  • Organize and present findings to customer
    • Business unit reports 
    • Executive level report 
  • Recommendations for DR delivery based on application criticality 

What is the purpose of the Business Impact Analysis BIA?

A business impact analysis (BIA) predicts the consequences of disruption of a business function and process and gathers information needed to develop recovery strategies. Potential loss scenarios should be identified during a risk assessment.

What are two objectives of a BIA?

The objectives of a BIA are to: Determine the criticality of individual business functions in the organization. Determine the impact of a disruption on CBFs, e.g. financial and non-financial losses.

Which of the following best describe business impact analysis?

Business impact analysis is performed to BEST identify: The impacts of a risk on the organization. The impacts of a threat to the organization operations.

What are the main components of BIA?

10 Elements in a Business Impact Analysis Report.
Internal and external dependencies..
Vital records..
Service level agreements..
System and application Recovery Point Objectives..
Level of reliance on internal and external systems and applications..
Specialized equipment required..
Backlog information..
Workaround procedures..