SlideShare a Scribd company logo
1 of 23
The Business Impact
Analysis (BIA) as
Foundation of the BCM
Approach
Dr. Wolfgang H. Mahr, M.Sc., BBA, MBCI, CISA
governance & continuuuity gmbh
CH-8408 Winterthur, Switzerland
www.continuuuity.ch
LinkedIn, XING, Twitter
wolfgang.mahr@continuuuity.ch
Contents
 Why a BIA?
 BIA in the BCM Lifecycle
 Outcomes of the BIA
 BIA supporting BCM Goals
 ISO 22317 on the BIA
 BIA Approaches
 Challenges when doing a BIA
 Sokrates Maps –what’s this?
 Sokrates Maps Benefits and Applications
 Sokrates Maps for the BIA
 BIA Critical Success Factors
Abstract
• This contribution underlines the fundamental importance of the one of
the most important phases in the BCM lifecycle – the BIA.
• Other - subsequent - phases such as selecting one or more business
continuity strategies or the formulation of a BC plan, exhibit a much
smaller space of choices than the BIA, which is primarily an information
gathering stage, charged with understanding the business.
• Critically important information needs to be unearthed and, ideally, not
one important aspect must be omitted or forgotten. This is the reason
why ISO TC 292 (formerly 223), after developing ISO 22301 and ISO
22313, has embarked on developing a standard on the BIA: ISO 22317.
It is being presented in another contribution at this conference.
• This paper focuses on a visualization and presentation method newly
applied to the BIA process, in order to better understand a company’s
processes, resources and their interdependencies.
Why a BIA?
• BCM is a cyclic process
• BCM is based on continuous improvement
• BIA makes you know your processes better
• BIA is the base for the subsequent development of one
or more Business Continuity Strategies
• …
Why a BIA?
• Increasing the efficiency of the organisation
• Evaluate alternative strategic planning options
• Assist in long-term strategy decision making
• Assist in developing a risk analysis
• …
BIA in the BCM lifecycle
Reference: The Business Continuity Institute
BIA in the BCM lifecycle
Reference: ISO 22301:2012
Outcomes of the BIA
• Major outcomes include:
– Validation of the organisation’s BC programme scope
– Identification of requirements the organisation
– Determination of impacts, over time (of disruptions)
– Identification of relationships between
• Products/services
• Processes
• Activities
• Resources
– Resources needed to perform prioritised activities
– Such as facilities, people, assets, supplies, financial resources
– Dependencies and interrelationships
– …
BIA supporting BCM Goals
• Protecting company value and reputation
• Safeguards the reputation and future of the company in an
emergency
• Increase shareholder value and demonstrates commitment by
management
• Assures the survival of the company in the case of a serious incident
• Minimize financial losses in case of an incident or emergency
ISO/TS 22317 on BIA
• Developed by ISO TC292 (“Security and Resilience”)
• Currently as DTS (Draft Technical Specification)
• To be published within the next couple of months
• Based on ISO 22301, ISO 22313 and ISO 22300
• Focus on Performing the BIA:
– Project Planning and Management
– Product and Service Prioritisation
– Process Prioritisation
– Activity Prioritisation
– Analysis and Consolidation
– Top Management Endorsement of BIA Results
• Annexes on
– Terminology Mapping
– Information Collection Methods
BIA Approaches
• Gold, Silver, Bronze
• Strategic / Tactical
• Iterations
• Questionnaires
• Workshops
• Interviews
– Middle Management
– Process Owners
Challenges when doing a BIA
• Commitment
• Level of effort
• “Right” effort
• Correctness /Completeness
• No excessive overlap / no white spots
Sokrates Maps – what’s this?
Sokrates Maps – what’s this?
Sokrates Maps – what’s this?
Sokrates Maps – Benefits
• Benefits
– Foundation of method
– Psychological background
– Common view across hierarchies and disciplines
– Discover new:
• Ideas
• Facts
• Relationships
• Dependencies
• Communicate & visualize
• Hierarchical view on complex situations
• Electronic representation, communication and archiving
Sokrates Maps - Applications
Sokrates Maps - Applications
 Board Level view of a
hospital:
 Get the big picture
◦ Based on details
Sokrates Maps - Applications
Sokrates Maps for BIA
• Visualisation of the standards (psychological foundation)
– ISO 22301, ISO 22317 (maturity model)
• Assessment tool, BIA support tool
– Presentation of BIA findings (electronic representation, communication and
archiving)
– Usage as questionnaire (maturity model, psychological foundation)
• Single person or in workshops
– Visualisation (hierarchical, common view across disciplines)
• Overlaps (discover ideas, facts, relationships, dependencies)
• Gaps (discover ideas, facts, relationships, dependencies)
• Redundancies (discover ideas, facts, relationships, dependencies)
–  Enhanced BIA quality and maturity
BIA Critical Success Factors
• Follow best practices such as
– BCI’s Good Practice Guidelines and/or
– ISO Standards such a ISO 22301, ISO 22313 and ISO/TS 22317
• Obtain top management commitment
• Apply project management methodologies
• Follow a BIA approach fit for the selected type of BIA
• Use an approach compatible with the company’s structure
• Deploy tools helping to obtain a “true and fair” representation
of products, services, priorities, dependencies and
requirements
• Develop a hierarchical view on complex situations
• Use electronic representation, communication and archiving
Thank you

More Related Content

What's hot

Assess Your Business Continuity Management Process
Assess Your Business Continuity Management ProcessAssess Your Business Continuity Management Process
Assess Your Business Continuity Management ProcessAnand Subramaniam
 
Business Continuity and Disaster Recovery Strategy
Business Continuity and Disaster Recovery Strategy Business Continuity and Disaster Recovery Strategy
Business Continuity and Disaster Recovery Strategy Chandrak Trivedi
 
Building a business impact analysis (bia) process a hands on blueprint
Building a business impact analysis (bia) process a hands on blueprintBuilding a business impact analysis (bia) process a hands on blueprint
Building a business impact analysis (bia) process a hands on blueprintluweinet
 
BIA - Example of Business Impact Analysis and Dependencies
BIA - Example of Business Impact Analysis and DependenciesBIA - Example of Business Impact Analysis and Dependencies
BIA - Example of Business Impact Analysis and DependenciesRamiro Cid
 
Integrating Risk into your Balanced Scorecard
Integrating Risk into your Balanced Scorecard Integrating Risk into your Balanced Scorecard
Integrating Risk into your Balanced Scorecard Andrew Smart
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planningalanlund
 
business-continuity-management-awareness-presentation-for-mampu2929
business-continuity-management-awareness-presentation-for-mampu2929business-continuity-management-awareness-presentation-for-mampu2929
business-continuity-management-awareness-presentation-for-mampu2929Andy Willams
 
Bcm Framework PowerPoint Presentation Slides
Bcm Framework PowerPoint Presentation SlidesBcm Framework PowerPoint Presentation Slides
Bcm Framework PowerPoint Presentation SlidesSlideTeam
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity PlanningDipankar Ghosh
 
Business continuity overview
Business continuity overviewBusiness continuity overview
Business continuity overviewRod Davis
 
CISA Domain- 1 - InfosecTrain
CISA Domain- 1  - InfosecTrainCISA Domain- 1  - InfosecTrain
CISA Domain- 1 - InfosecTrainInfosecTrain
 
Business Continuity Planning Presentation Overview
Business Continuity Planning Presentation OverviewBusiness Continuity Planning Presentation Overview
Business Continuity Planning Presentation OverviewBob Winkler
 
02 Practical Strategies of Conducting BIA
02 Practical Strategies of Conducting BIA02 Practical Strategies of Conducting BIA
02 Practical Strategies of Conducting BIABCM Institute
 
BCMS Presentation1
BCMS Presentation1BCMS Presentation1
BCMS Presentation1barbytee
 
Governance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management SolutionGovernance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management SolutionRishabh Software
 
Disaster Recovery Plan for IT
Disaster Recovery Plan for ITDisaster Recovery Plan for IT
Disaster Recovery Plan for IThhuihhui
 
Business impact.analysis based on ISO 22301
Business impact.analysis based on ISO 22301Business impact.analysis based on ISO 22301
Business impact.analysis based on ISO 22301mascot4u
 

What's hot (20)

Assess Your Business Continuity Management Process
Assess Your Business Continuity Management ProcessAssess Your Business Continuity Management Process
Assess Your Business Continuity Management Process
 
Business Continuity and Disaster Recovery Strategy
Business Continuity and Disaster Recovery Strategy Business Continuity and Disaster Recovery Strategy
Business Continuity and Disaster Recovery Strategy
 
Building a business impact analysis (bia) process a hands on blueprint
Building a business impact analysis (bia) process a hands on blueprintBuilding a business impact analysis (bia) process a hands on blueprint
Building a business impact analysis (bia) process a hands on blueprint
 
009.itsecurity bcp v1
009.itsecurity bcp v1009.itsecurity bcp v1
009.itsecurity bcp v1
 
BIA - Example of Business Impact Analysis and Dependencies
BIA - Example of Business Impact Analysis and DependenciesBIA - Example of Business Impact Analysis and Dependencies
BIA - Example of Business Impact Analysis and Dependencies
 
Integrating Risk into your Balanced Scorecard
Integrating Risk into your Balanced Scorecard Integrating Risk into your Balanced Scorecard
Integrating Risk into your Balanced Scorecard
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planning
 
business-continuity-management-awareness-presentation-for-mampu2929
business-continuity-management-awareness-presentation-for-mampu2929business-continuity-management-awareness-presentation-for-mampu2929
business-continuity-management-awareness-presentation-for-mampu2929
 
Bcm Framework PowerPoint Presentation Slides
Bcm Framework PowerPoint Presentation SlidesBcm Framework PowerPoint Presentation Slides
Bcm Framework PowerPoint Presentation Slides
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planning
 
Business continuity overview
Business continuity overviewBusiness continuity overview
Business continuity overview
 
Business Continuity Planning Presentation
Business Continuity Planning PresentationBusiness Continuity Planning Presentation
Business Continuity Planning Presentation
 
CISA Domain- 1 - InfosecTrain
CISA Domain- 1  - InfosecTrainCISA Domain- 1  - InfosecTrain
CISA Domain- 1 - InfosecTrain
 
Business Continuity Planning Presentation Overview
Business Continuity Planning Presentation OverviewBusiness Continuity Planning Presentation Overview
Business Continuity Planning Presentation Overview
 
02 Practical Strategies of Conducting BIA
02 Practical Strategies of Conducting BIA02 Practical Strategies of Conducting BIA
02 Practical Strategies of Conducting BIA
 
BCMS Presentation1
BCMS Presentation1BCMS Presentation1
BCMS Presentation1
 
Governance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management SolutionGovernance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management Solution
 
Disaster Recovery Plan for IT
Disaster Recovery Plan for ITDisaster Recovery Plan for IT
Disaster Recovery Plan for IT
 
Business impact.analysis based on ISO 22301
Business impact.analysis based on ISO 22301Business impact.analysis based on ISO 22301
Business impact.analysis based on ISO 22301
 
Business impact analysis
Business impact analysis Business impact analysis
Business impact analysis
 

Similar to PECB Webinar: The importance of business impact analysis

Development of business strategies and business models for associations
Development of business strategies and business models for associationsDevelopment of business strategies and business models for associations
Development of business strategies and business models for associationsajcortese
 
ITSM Academy Webinar - Establishing A Business Process Group
ITSM Academy Webinar - Establishing A Business Process GroupITSM Academy Webinar - Establishing A Business Process Group
ITSM Academy Webinar - Establishing A Business Process GroupITSM Academy, Inc.
 
SOEDS, 11th April 2022 How to Evaluate CSR Projects and Programmes.pptx
SOEDS, 11th April 2022 How to Evaluate CSR Projects and Programmes.pptxSOEDS, 11th April 2022 How to Evaluate CSR Projects and Programmes.pptx
SOEDS, 11th April 2022 How to Evaluate CSR Projects and Programmes.pptxRAKESHNANDAN7
 
itSMF 2020 - Business Analyzis
itSMF 2020 - Business AnalyzisitSMF 2020 - Business Analyzis
itSMF 2020 - Business AnalyzisitSMF Belgium
 
Operationalisng SROI
Operationalisng SROIOperationalisng SROI
Operationalisng SROISWF
 
NFP Strategic Initiatives Process 2012
NFP Strategic Initiatives Process  2012NFP Strategic Initiatives Process  2012
NFP Strategic Initiatives Process 2012chaberkorn
 
Harnessing cpd a road map for the future by Luke Stevens
Harnessing cpd a road map for the future by Luke Stevens Harnessing cpd a road map for the future by Luke Stevens
Harnessing cpd a road map for the future by Luke Stevens L2Lproject
 
Charles Rygula: Value Beyond Words
Charles Rygula: Value Beyond WordsCharles Rygula: Value Beyond Words
Charles Rygula: Value Beyond WordsJack Molisani
 
Framgångsfaktorer för Agil Utveckling av Mycket Stora Programvaruprodukter
Framgångsfaktorer för Agil Utveckling av Mycket Stora ProgramvaruprodukterFramgångsfaktorer för Agil Utveckling av Mycket Stora Programvaruprodukter
Framgångsfaktorer för Agil Utveckling av Mycket Stora ProgramvaruprodukterHansoft AB
 
Horizon 2020: UK Bio-based Industries Joint Undertaking Information and Broke...
Horizon 2020: UK Bio-based Industries Joint Undertaking Information and Broke...Horizon 2020: UK Bio-based Industries Joint Undertaking Information and Broke...
Horizon 2020: UK Bio-based Industries Joint Undertaking Information and Broke...KTN
 
JISC Beyond the Business Intelligence Programme
JISC Beyond the Business Intelligence ProgrammeJISC Beyond the Business Intelligence Programme
JISC Beyond the Business Intelligence Programmemylesdanson
 
Module 4.2 - Performance management
Module 4.2 - Performance managementModule 4.2 - Performance management
Module 4.2 - Performance managementszpinter
 
organizational culture
organizational culture organizational culture
organizational culture karan992457
 
ToC_training slide_set_Sniffer Aug 2015 v2 num-sm
ToC_training slide_set_Sniffer Aug 2015 v2 num-smToC_training slide_set_Sniffer Aug 2015 v2 num-sm
ToC_training slide_set_Sniffer Aug 2015 v2 num-smDr Seán Doolan, MBA
 
Monitoring and Evaluation of International Development Assistance to the Priv...
Monitoring and Evaluation of International Development Assistance to the Priv...Monitoring and Evaluation of International Development Assistance to the Priv...
Monitoring and Evaluation of International Development Assistance to the Priv...CesToronto
 
Keynote Address: Robbie Atabaigi, Manager Advisory Information Protection, KP...
Keynote Address: Robbie Atabaigi, Manager Advisory Information Protection, KP...Keynote Address: Robbie Atabaigi, Manager Advisory Information Protection, KP...
Keynote Address: Robbie Atabaigi, Manager Advisory Information Protection, KP...NICSA
 
Assessing the Impact of a Disruption: Building an Effective Business Impact A...
Assessing the Impact of a Disruption: Building an Effective Business Impact A...Assessing the Impact of a Disruption: Building an Effective Business Impact A...
Assessing the Impact of a Disruption: Building an Effective Business Impact A...PECB
 

Similar to PECB Webinar: The importance of business impact analysis (20)

Development of business strategies and business models for associations
Development of business strategies and business models for associationsDevelopment of business strategies and business models for associations
Development of business strategies and business models for associations
 
ITSM Academy Webinar - Establishing A Business Process Group
ITSM Academy Webinar - Establishing A Business Process GroupITSM Academy Webinar - Establishing A Business Process Group
ITSM Academy Webinar - Establishing A Business Process Group
 
SOEDS, 11th April 2022 How to Evaluate CSR Projects and Programmes.pptx
SOEDS, 11th April 2022 How to Evaluate CSR Projects and Programmes.pptxSOEDS, 11th April 2022 How to Evaluate CSR Projects and Programmes.pptx
SOEDS, 11th April 2022 How to Evaluate CSR Projects and Programmes.pptx
 
itSMF 2020 - Business Analyzis
itSMF 2020 - Business AnalyzisitSMF 2020 - Business Analyzis
itSMF 2020 - Business Analyzis
 
Operationalisng SROI
Operationalisng SROIOperationalisng SROI
Operationalisng SROI
 
NFP Strategic Initiatives Process 2012
NFP Strategic Initiatives Process  2012NFP Strategic Initiatives Process  2012
NFP Strategic Initiatives Process 2012
 
Harnessing cpd a road map for the future by Luke Stevens
Harnessing cpd a road map for the future by Luke Stevens Harnessing cpd a road map for the future by Luke Stevens
Harnessing cpd a road map for the future by Luke Stevens
 
Charles Rygula: Value Beyond Words
Charles Rygula: Value Beyond WordsCharles Rygula: Value Beyond Words
Charles Rygula: Value Beyond Words
 
Framgångsfaktorer för Agil Utveckling av Mycket Stora Programvaruprodukter
Framgångsfaktorer för Agil Utveckling av Mycket Stora ProgramvaruprodukterFramgångsfaktorer för Agil Utveckling av Mycket Stora Programvaruprodukter
Framgångsfaktorer för Agil Utveckling av Mycket Stora Programvaruprodukter
 
Horizon 2020: UK Bio-based Industries Joint Undertaking Information and Broke...
Horizon 2020: UK Bio-based Industries Joint Undertaking Information and Broke...Horizon 2020: UK Bio-based Industries Joint Undertaking Information and Broke...
Horizon 2020: UK Bio-based Industries Joint Undertaking Information and Broke...
 
Strategy analysis
Strategy analysisStrategy analysis
Strategy analysis
 
JISC Beyond the Business Intelligence Programme
JISC Beyond the Business Intelligence ProgrammeJISC Beyond the Business Intelligence Programme
JISC Beyond the Business Intelligence Programme
 
Module 4.2 - Performance management
Module 4.2 - Performance managementModule 4.2 - Performance management
Module 4.2 - Performance management
 
Dynamic Duos
Dynamic DuosDynamic Duos
Dynamic Duos
 
organizational culture
organizational culture organizational culture
organizational culture
 
ToC_training slide_set_Sniffer Aug 2015 v2 num-sm
ToC_training slide_set_Sniffer Aug 2015 v2 num-smToC_training slide_set_Sniffer Aug 2015 v2 num-sm
ToC_training slide_set_Sniffer Aug 2015 v2 num-sm
 
Monitoring and Evaluation of International Development Assistance to the Priv...
Monitoring and Evaluation of International Development Assistance to the Priv...Monitoring and Evaluation of International Development Assistance to the Priv...
Monitoring and Evaluation of International Development Assistance to the Priv...
 
Keynote Address: Robbie Atabaigi, Manager Advisory Information Protection, KP...
Keynote Address: Robbie Atabaigi, Manager Advisory Information Protection, KP...Keynote Address: Robbie Atabaigi, Manager Advisory Information Protection, KP...
Keynote Address: Robbie Atabaigi, Manager Advisory Information Protection, KP...
 
Assessing the Impact of a Disruption: Building an Effective Business Impact A...
Assessing the Impact of a Disruption: Building an Effective Business Impact A...Assessing the Impact of a Disruption: Building an Effective Business Impact A...
Assessing the Impact of a Disruption: Building an Effective Business Impact A...
 
BAs IIBA and the BABOK
BAs IIBA and the BABOKBAs IIBA and the BABOK
BAs IIBA and the BABOK
 

More from PECB

DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityDORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityPECB
 
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernanceSecuring the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernancePECB
 
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...PECB
 
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...PECB
 
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyPECB
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...PECB
 
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationPECB
 
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsManaging ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsPECB
 
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?PECB
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...PECB
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...PECB
 
Student Information Session University KTMC
Student Information Session University KTMC Student Information Session University KTMC
Student Information Session University KTMC PECB
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...PECB
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...PECB
 
Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA PECB
 
IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?PECB
 
Information Session University Egybyte.pptx
Information Session University Egybyte.pptxInformation Session University Egybyte.pptx
Information Session University Egybyte.pptxPECB
 
Student Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxStudent Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxPECB
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023PECB
 
ISO 28000:2022 – Reduce risks and improve the security management system
ISO 28000:2022 – Reduce risks and improve the security management systemISO 28000:2022 – Reduce risks and improve the security management system
ISO 28000:2022 – Reduce risks and improve the security management systemPECB
 

More from PECB (20)

DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityDORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
 
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernanceSecuring the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
 
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
 
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
 
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
 
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
 
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsManaging ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
 
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
 
Student Information Session University KTMC
Student Information Session University KTMC Student Information Session University KTMC
Student Information Session University KTMC
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
 
Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA
 
IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?
 
Information Session University Egybyte.pptx
Information Session University Egybyte.pptxInformation Session University Egybyte.pptx
Information Session University Egybyte.pptx
 
Student Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxStudent Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptx
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023
 
ISO 28000:2022 – Reduce risks and improve the security management system
ISO 28000:2022 – Reduce risks and improve the security management systemISO 28000:2022 – Reduce risks and improve the security management system
ISO 28000:2022 – Reduce risks and improve the security management system
 

Recently uploaded

4.18.24 Movement Legacies, Reflection, and Review.pptx
4.18.24 Movement Legacies, Reflection, and Review.pptx4.18.24 Movement Legacies, Reflection, and Review.pptx
4.18.24 Movement Legacies, Reflection, and Review.pptxmary850239
 
ClimART Action | eTwinning Project
ClimART Action    |    eTwinning ProjectClimART Action    |    eTwinning Project
ClimART Action | eTwinning Projectjordimapav
 
ENG 5 Q4 WEEk 1 DAY 1 Restate sentences heard in one’s own words. Use appropr...
ENG 5 Q4 WEEk 1 DAY 1 Restate sentences heard in one’s own words. Use appropr...ENG 5 Q4 WEEk 1 DAY 1 Restate sentences heard in one’s own words. Use appropr...
ENG 5 Q4 WEEk 1 DAY 1 Restate sentences heard in one’s own words. Use appropr...JojoEDelaCruz
 
Transaction Management in Database Management System
Transaction Management in Database Management SystemTransaction Management in Database Management System
Transaction Management in Database Management SystemChristalin Nelson
 
How to do quick user assign in kanban in Odoo 17 ERP
How to do quick user assign in kanban in Odoo 17 ERPHow to do quick user assign in kanban in Odoo 17 ERP
How to do quick user assign in kanban in Odoo 17 ERPCeline George
 
GRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTS
GRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTSGRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTS
GRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTSJoshuaGantuangco2
 
Keynote by Prof. Wurzer at Nordex about IP-design
Keynote by Prof. Wurzer at Nordex about IP-designKeynote by Prof. Wurzer at Nordex about IP-design
Keynote by Prof. Wurzer at Nordex about IP-designMIPLM
 
EMBODO Lesson Plan Grade 9 Law of Sines.docx
EMBODO Lesson Plan Grade 9 Law of Sines.docxEMBODO Lesson Plan Grade 9 Law of Sines.docx
EMBODO Lesson Plan Grade 9 Law of Sines.docxElton John Embodo
 
Visit to a blind student's school🧑‍🦯🧑‍🦯(community medicine)
Visit to a blind student's school🧑‍🦯🧑‍🦯(community medicine)Visit to a blind student's school🧑‍🦯🧑‍🦯(community medicine)
Visit to a blind student's school🧑‍🦯🧑‍🦯(community medicine)lakshayb543
 
Inclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdf
Inclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdfInclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdf
Inclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdfTechSoup
 
Daily Lesson Plan in Mathematics Quarter 4
Daily Lesson Plan in Mathematics Quarter 4Daily Lesson Plan in Mathematics Quarter 4
Daily Lesson Plan in Mathematics Quarter 4JOYLYNSAMANIEGO
 
Expanded definition: technical and operational
Expanded definition: technical and operationalExpanded definition: technical and operational
Expanded definition: technical and operationalssuser3e220a
 
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATIONTHEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATIONHumphrey A Beña
 
USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...
USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...
USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...Postal Advocate Inc.
 
Choosing the Right CBSE School A Comprehensive Guide for Parents
Choosing the Right CBSE School A Comprehensive Guide for ParentsChoosing the Right CBSE School A Comprehensive Guide for Parents
Choosing the Right CBSE School A Comprehensive Guide for Parentsnavabharathschool99
 
Oppenheimer Film Discussion for Philosophy and Film
Oppenheimer Film Discussion for Philosophy and FilmOppenheimer Film Discussion for Philosophy and Film
Oppenheimer Film Discussion for Philosophy and FilmStan Meyer
 
How to Add Barcode on PDF Report in Odoo 17
How to Add Barcode on PDF Report in Odoo 17How to Add Barcode on PDF Report in Odoo 17
How to Add Barcode on PDF Report in Odoo 17Celine George
 
Textual Evidence in Reading and Writing of SHS
Textual Evidence in Reading and Writing of SHSTextual Evidence in Reading and Writing of SHS
Textual Evidence in Reading and Writing of SHSMae Pangan
 

Recently uploaded (20)

4.18.24 Movement Legacies, Reflection, and Review.pptx
4.18.24 Movement Legacies, Reflection, and Review.pptx4.18.24 Movement Legacies, Reflection, and Review.pptx
4.18.24 Movement Legacies, Reflection, and Review.pptx
 
ClimART Action | eTwinning Project
ClimART Action    |    eTwinning ProjectClimART Action    |    eTwinning Project
ClimART Action | eTwinning Project
 
Paradigm shift in nursing research by RS MEHTA
Paradigm shift in nursing research by RS MEHTAParadigm shift in nursing research by RS MEHTA
Paradigm shift in nursing research by RS MEHTA
 
YOUVE GOT EMAIL_FINALS_EL_DORADO_2024.pptx
YOUVE GOT EMAIL_FINALS_EL_DORADO_2024.pptxYOUVE GOT EMAIL_FINALS_EL_DORADO_2024.pptx
YOUVE GOT EMAIL_FINALS_EL_DORADO_2024.pptx
 
ENG 5 Q4 WEEk 1 DAY 1 Restate sentences heard in one’s own words. Use appropr...
ENG 5 Q4 WEEk 1 DAY 1 Restate sentences heard in one’s own words. Use appropr...ENG 5 Q4 WEEk 1 DAY 1 Restate sentences heard in one’s own words. Use appropr...
ENG 5 Q4 WEEk 1 DAY 1 Restate sentences heard in one’s own words. Use appropr...
 
Transaction Management in Database Management System
Transaction Management in Database Management SystemTransaction Management in Database Management System
Transaction Management in Database Management System
 
How to do quick user assign in kanban in Odoo 17 ERP
How to do quick user assign in kanban in Odoo 17 ERPHow to do quick user assign in kanban in Odoo 17 ERP
How to do quick user assign in kanban in Odoo 17 ERP
 
GRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTS
GRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTSGRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTS
GRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTS
 
Keynote by Prof. Wurzer at Nordex about IP-design
Keynote by Prof. Wurzer at Nordex about IP-designKeynote by Prof. Wurzer at Nordex about IP-design
Keynote by Prof. Wurzer at Nordex about IP-design
 
EMBODO Lesson Plan Grade 9 Law of Sines.docx
EMBODO Lesson Plan Grade 9 Law of Sines.docxEMBODO Lesson Plan Grade 9 Law of Sines.docx
EMBODO Lesson Plan Grade 9 Law of Sines.docx
 
Visit to a blind student's school🧑‍🦯🧑‍🦯(community medicine)
Visit to a blind student's school🧑‍🦯🧑‍🦯(community medicine)Visit to a blind student's school🧑‍🦯🧑‍🦯(community medicine)
Visit to a blind student's school🧑‍🦯🧑‍🦯(community medicine)
 
Inclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdf
Inclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdfInclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdf
Inclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdf
 
Daily Lesson Plan in Mathematics Quarter 4
Daily Lesson Plan in Mathematics Quarter 4Daily Lesson Plan in Mathematics Quarter 4
Daily Lesson Plan in Mathematics Quarter 4
 
Expanded definition: technical and operational
Expanded definition: technical and operationalExpanded definition: technical and operational
Expanded definition: technical and operational
 
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATIONTHEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
 
USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...
USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...
USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...
 
Choosing the Right CBSE School A Comprehensive Guide for Parents
Choosing the Right CBSE School A Comprehensive Guide for ParentsChoosing the Right CBSE School A Comprehensive Guide for Parents
Choosing the Right CBSE School A Comprehensive Guide for Parents
 
Oppenheimer Film Discussion for Philosophy and Film
Oppenheimer Film Discussion for Philosophy and FilmOppenheimer Film Discussion for Philosophy and Film
Oppenheimer Film Discussion for Philosophy and Film
 
How to Add Barcode on PDF Report in Odoo 17
How to Add Barcode on PDF Report in Odoo 17How to Add Barcode on PDF Report in Odoo 17
How to Add Barcode on PDF Report in Odoo 17
 
Textual Evidence in Reading and Writing of SHS
Textual Evidence in Reading and Writing of SHSTextual Evidence in Reading and Writing of SHS
Textual Evidence in Reading and Writing of SHS
 

PECB Webinar: The importance of business impact analysis

  • 1.
  • 2. The Business Impact Analysis (BIA) as Foundation of the BCM Approach Dr. Wolfgang H. Mahr, M.Sc., BBA, MBCI, CISA governance & continuuuity gmbh CH-8408 Winterthur, Switzerland www.continuuuity.ch LinkedIn, XING, Twitter wolfgang.mahr@continuuuity.ch
  • 3. Contents  Why a BIA?  BIA in the BCM Lifecycle  Outcomes of the BIA  BIA supporting BCM Goals  ISO 22317 on the BIA  BIA Approaches  Challenges when doing a BIA  Sokrates Maps –what’s this?  Sokrates Maps Benefits and Applications  Sokrates Maps for the BIA  BIA Critical Success Factors
  • 4. Abstract • This contribution underlines the fundamental importance of the one of the most important phases in the BCM lifecycle – the BIA. • Other - subsequent - phases such as selecting one or more business continuity strategies or the formulation of a BC plan, exhibit a much smaller space of choices than the BIA, which is primarily an information gathering stage, charged with understanding the business. • Critically important information needs to be unearthed and, ideally, not one important aspect must be omitted or forgotten. This is the reason why ISO TC 292 (formerly 223), after developing ISO 22301 and ISO 22313, has embarked on developing a standard on the BIA: ISO 22317. It is being presented in another contribution at this conference. • This paper focuses on a visualization and presentation method newly applied to the BIA process, in order to better understand a company’s processes, resources and their interdependencies.
  • 5. Why a BIA? • BCM is a cyclic process • BCM is based on continuous improvement • BIA makes you know your processes better • BIA is the base for the subsequent development of one or more Business Continuity Strategies • …
  • 6. Why a BIA? • Increasing the efficiency of the organisation • Evaluate alternative strategic planning options • Assist in long-term strategy decision making • Assist in developing a risk analysis • …
  • 7. BIA in the BCM lifecycle Reference: The Business Continuity Institute
  • 8. BIA in the BCM lifecycle Reference: ISO 22301:2012
  • 9. Outcomes of the BIA • Major outcomes include: – Validation of the organisation’s BC programme scope – Identification of requirements the organisation – Determination of impacts, over time (of disruptions) – Identification of relationships between • Products/services • Processes • Activities • Resources – Resources needed to perform prioritised activities – Such as facilities, people, assets, supplies, financial resources – Dependencies and interrelationships – …
  • 10. BIA supporting BCM Goals • Protecting company value and reputation • Safeguards the reputation and future of the company in an emergency • Increase shareholder value and demonstrates commitment by management • Assures the survival of the company in the case of a serious incident • Minimize financial losses in case of an incident or emergency
  • 11. ISO/TS 22317 on BIA • Developed by ISO TC292 (“Security and Resilience”) • Currently as DTS (Draft Technical Specification) • To be published within the next couple of months • Based on ISO 22301, ISO 22313 and ISO 22300 • Focus on Performing the BIA: – Project Planning and Management – Product and Service Prioritisation – Process Prioritisation – Activity Prioritisation – Analysis and Consolidation – Top Management Endorsement of BIA Results • Annexes on – Terminology Mapping – Information Collection Methods
  • 12. BIA Approaches • Gold, Silver, Bronze • Strategic / Tactical • Iterations • Questionnaires • Workshops • Interviews – Middle Management – Process Owners
  • 13. Challenges when doing a BIA • Commitment • Level of effort • “Right” effort • Correctness /Completeness • No excessive overlap / no white spots
  • 14. Sokrates Maps – what’s this?
  • 15. Sokrates Maps – what’s this?
  • 16. Sokrates Maps – what’s this?
  • 17. Sokrates Maps – Benefits • Benefits – Foundation of method – Psychological background – Common view across hierarchies and disciplines – Discover new: • Ideas • Facts • Relationships • Dependencies • Communicate & visualize • Hierarchical view on complex situations • Electronic representation, communication and archiving
  • 18. Sokrates Maps - Applications
  • 19. Sokrates Maps - Applications  Board Level view of a hospital:  Get the big picture ◦ Based on details
  • 20. Sokrates Maps - Applications
  • 21. Sokrates Maps for BIA • Visualisation of the standards (psychological foundation) – ISO 22301, ISO 22317 (maturity model) • Assessment tool, BIA support tool – Presentation of BIA findings (electronic representation, communication and archiving) – Usage as questionnaire (maturity model, psychological foundation) • Single person or in workshops – Visualisation (hierarchical, common view across disciplines) • Overlaps (discover ideas, facts, relationships, dependencies) • Gaps (discover ideas, facts, relationships, dependencies) • Redundancies (discover ideas, facts, relationships, dependencies) –  Enhanced BIA quality and maturity
  • 22. BIA Critical Success Factors • Follow best practices such as – BCI’s Good Practice Guidelines and/or – ISO Standards such a ISO 22301, ISO 22313 and ISO/TS 22317 • Obtain top management commitment • Apply project management methodologies • Follow a BIA approach fit for the selected type of BIA • Use an approach compatible with the company’s structure • Deploy tools helping to obtain a “true and fair” representation of products, services, priorities, dependencies and requirements • Develop a hierarchical view on complex situations • Use electronic representation, communication and archiving