Business Continuity and Disaster Recovery - Business Impact Analysis

Business impact analysis is a critical part of the business continuity planning process. This step quantifies data and gets into the real world issue of potential losses that can negatively impact your business. It is used to understand the most important impacts and how to best protect your people, processes, data, communications, assets and the organization's goodwill and reputation.

Organizations often think in terms of disaster recovery. Business continuity and the business impact analysis is more focused on keeping the business up and running and less focused on recovery after a disaster. The business impact analysis also is not focused only on the potential disasters, but on all potentially critical discontinuities. Key elements of the Business Impact Analysis are to identify critical business functions, establish the maximum acceptable outage time for each of these functions and then to determine the impact of not performing those functions. This can be measured against regulatory, legal, financial, operations or customer service requirements.

Once the adequacy of security and controls is evaluated and critical business functions and outage times are defined, the business continuity planner needs to develop an understanding of the probability of threats factored by the severity or impact and to start to develop a cost benefit analysis of the largest impact and highest probability threats.

It's virtually impossible to create an absolute value and prioritization of threats and impacts. Generally, a relational system is used to drive out the key priorities. Often, each threat is evaluated according to its probability and assigned a 1, 5 or 10 rating. Then, each threat is evaluated according to its impact on critical business functions and on the business overall. For example, a discontinuity in a critical business function of less than one hour might receive a value of 0. A discontinuity of one to eight hours might be ranked a 1, eight to twenty four hours might be ranked a 2 and over 24 hours might be ranked a 3. Obviously, these rankings need to be developed on a company specific basis. Probability factored by impact creates the relational prioritization list.

This approach to risk evaluation and control allows management to start to quantify the risks and potential impacts on the organization in a thoughtful and analytical way. This results not only in higher quality decisions, but also provides an audit trail that demonstrates that management is paying attention to its risk management responsibilities. These responsibilities might be established by regulatory or legal bodies, demanded as a contractual commitment by customers or simply expected by shareholders as sound and prudent management. The key corporate goals are to protect people, protect assets, protect data and to protect the brand and reputation of the organization.

About The Author

Robert Mahood has significant technology and management experience in data communications, internet, storage, disaster recovery and data recovery. He is currently the president of Midwest Data Recovery. www.midwestdatarecovery.com

bmahood@midwestdatarecovery.com, 312 907 2100 or 866 786 2595

How Secure Are Online Data Backups?

Processing DATA is what all businesses do. Protecting data is... Read More

Offsite Data Backup Not Just for Fortune 500 Companies Anymore

In today's high paced digital world there is a very... Read More

Online Data Backups for Newbies

How long have you been doing business online? Whether you... Read More

Disaster Recovery Made Easy With Online Backups

Whenever disaster strikes the most critical asset that every company... Read More

Big Time Disaster Recovery Solutions Available for the Little Guy

There was a time - not too long ago -... Read More

Hard Drive Crash? The Essential Data Recovery Report

Your worst nightmare just became a horrifying reality. You keep... Read More

Data Recovery - What Not to Do!

Data recovery is a tricky thing, and if you've somehow... Read More

Data Recovery - You Can Get It Back!

Data recovery is a process whereby you can save data... Read More

Data Recovery The Easy Way

If you aren't prepared in advance, you will most likely... Read More

The Best Data Recovery Choice For You

The best defense against a loss of data is a... Read More

Do You Have The One Key Ingredient Necessary For Disaster Recovery?

It is not rocket science, we all know that we... Read More

Are The Words Business Continuity and Disaster Recovery Planning Rolling Off Your Lips?

It might be more fun to talk about those free... Read More

Want To Beat The Odds? Disaster Recovery Planning is Essential

Statistics show two out of five businesses go out of... Read More

Comparing Data Recovery Software

Software programmers recognize the importance of data files, and thankfully,... Read More

Do I Really Need To Backup?

Okay, computers a machine, right? Okay, maybe not yours. You... Read More

Computer Data Recovery Options

Losing files on your computer can be a frightening experience... Read More

Learn How To Make Data Backup Over The Internet!

Why should you backup your data on the Internet?There are... Read More

Data Recovery

Every person who uses a personal computer will eventually face... Read More

Business Continuity and Disaster Recovery - Reducing Your Risk Profile

Like all plans, there is an ultimate goal to achieve.... Read More

Business Continuity and Disaster Recovery - The Business Continuity and Disaster Recovery Plan

Essentially, the plan addresses the who, what, where, why and... Read More

Business Continuity and Disaster Recovery - Selecting A Business Continuity Strategy

The risk analysis and business impact analysis have identified risks... Read More

Business Continuity and Disaster Recovery - Business Impact Analysis

Business impact analysis is a critical part of the business... Read More

Business Continuity and Disaster Recovery - Risk Analysis and Control

In the risk evaluation phase, there are a number of... Read More

Business Continuity and Disaster Recovery - A Business Not a Technology Issue

Hackers, hurricanes, fires, flooding, power outages, denial of service attacks,... Read More

The Seven Golden Rules Of Data Backups

Backups of company data are carried out for two main... Read More