SlideShare a Scribd company logo
1 of 23
The Business Impact
Analysis (BIA) as
Foundation of the BCM
Approach
Dr. Wolfgang H. Mahr, M.Sc., BBA, MBCI, CISA
governance & continuuuity gmbh
CH-8408 Winterthur, Switzerland
www.continuuuity.ch
LinkedIn, XING, Twitter
wolfgang.mahr@continuuuity.ch
Contents
 Why a BIA?
 BIA in the BCM Lifecycle
 Outcomes of the BIA
 BIA supporting BCM Goals
 ISO 22317 on the BIA
 BIA Approaches
 Challenges when doing a BIA
 Sokrates Maps –what’s this?
 Sokrates Maps Benefits and Applications
 Sokrates Maps for the BIA
 BIA Critical Success Factors
Abstract
• This contribution underlines the fundamental importance of the one of
the most important phases in the BCM lifecycle – the BIA.
• Other - subsequent - phases such as selecting one or more business
continuity strategies or the formulation of a BC plan, exhibit a much
smaller space of choices than the BIA, which is primarily an information
gathering stage, charged with understanding the business.
• Critically important information needs to be unearthed and, ideally, not
one important aspect must be omitted or forgotten. This is the reason
why ISO TC 292 (formerly 223), after developing ISO 22301 and ISO
22313, has embarked on developing a standard on the BIA: ISO 22317.
It is being presented in another contribution at this conference.
• This paper focuses on a visualization and presentation method newly
applied to the BIA process, in order to better understand a company’s
processes, resources and their interdependencies.
Why a BIA?
• BCM is a cyclic process
• BCM is based on continuous improvement
• BIA makes you know your processes better
• BIA is the base for the subsequent development of one
or more Business Continuity Strategies
• …
Why a BIA?
• Increasing the efficiency of the organisation
• Evaluate alternative strategic planning options
• Assist in long-term strategy decision making
• Assist in developing a risk analysis
• …
BIA in the BCM lifecycle
Reference: The Business Continuity Institute
BIA in the BCM lifecycle
Reference: ISO 22301:2012
Outcomes of the BIA
• Major outcomes include:
– Validation of the organisation’s BC programme scope
– Identification of requirements the organisation
– Determination of impacts, over time (of disruptions)
– Identification of relationships between
• Products/services
• Processes
• Activities
• Resources
– Resources needed to perform prioritised activities
– Such as facilities, people, assets, supplies, financial resources
– Dependencies and interrelationships
– …
BIA supporting BCM Goals
• Protecting company value and reputation
• Safeguards the reputation and future of the company in an
emergency
• Increase shareholder value and demonstrates commitment by
management
• Assures the survival of the company in the case of a serious incident
• Minimize financial losses in case of an incident or emergency
ISO/TS 22317 on BIA
• Developed by ISO TC292 (“Security and Resilience”)
• Currently as DTS (Draft Technical Specification)
• To be published within the next couple of months
• Based on ISO 22301, ISO 22313 and ISO 22300
• Focus on Performing the BIA:
– Project Planning and Management
– Product and Service Prioritisation
– Process Prioritisation
– Activity Prioritisation
– Analysis and Consolidation
– Top Management Endorsement of BIA Results
• Annexes on
– Terminology Mapping
– Information Collection Methods
BIA Approaches
• Gold, Silver, Bronze
• Strategic / Tactical
• Iterations
• Questionnaires
• Workshops
• Interviews
– Middle Management
– Process Owners
Challenges when doing a BIA
• Commitment
• Level of effort
• “Right” effort
• Correctness /Completeness
• No excessive overlap / no white spots
Sokrates Maps – what’s this?
Sokrates Maps – what’s this?
Sokrates Maps – what’s this?
Sokrates Maps – Benefits
• Benefits
– Foundation of method
– Psychological background
– Common view across hierarchies and disciplines
– Discover new:
• Ideas
• Facts
• Relationships
• Dependencies
• Communicate & visualize
• Hierarchical view on complex situations
• Electronic representation, communication and archiving
Sokrates Maps - Applications
Sokrates Maps - Applications
 Board Level view of a
hospital:
 Get the big picture
◦ Based on details
Sokrates Maps - Applications
Sokrates Maps for BIA
• Visualisation of the standards (psychological foundation)
– ISO 22301, ISO 22317 (maturity model)
• Assessment tool, BIA support tool
– Presentation of BIA findings (electronic representation, communication and
archiving)
– Usage as questionnaire (maturity model, psychological foundation)
• Single person or in workshops
– Visualisation (hierarchical, common view across disciplines)
• Overlaps (discover ideas, facts, relationships, dependencies)
• Gaps (discover ideas, facts, relationships, dependencies)
• Redundancies (discover ideas, facts, relationships, dependencies)
–  Enhanced BIA quality and maturity
BIA Critical Success Factors
• Follow best practices such as
– BCI’s Good Practice Guidelines and/or
– ISO Standards such a ISO 22301, ISO 22313 and ISO/TS 22317
• Obtain top management commitment
• Apply project management methodologies
• Follow a BIA approach fit for the selected type of BIA
• Use an approach compatible with the company’s structure
• Deploy tools helping to obtain a “true and fair” representation
of products, services, priorities, dependencies and
requirements
• Develop a hierarchical view on complex situations
• Use electronic representation, communication and archiving
Thank you

More Related Content

What's hot

Business Impact Analysis - Clause 4 Of BS25999 In Practice
Business Impact Analysis - Clause 4 Of BS25999 In PracticeBusiness Impact Analysis - Clause 4 Of BS25999 In Practice
Business Impact Analysis - Clause 4 Of BS25999 In PracticeDipankar Ghosh
 
Business Continuity Planning Presentation Overview
Business Continuity Planning Presentation OverviewBusiness Continuity Planning Presentation Overview
Business Continuity Planning Presentation OverviewBob Winkler
 
Business impact.analysis based on ISO 22301
Business impact.analysis based on ISO 22301Business impact.analysis based on ISO 22301
Business impact.analysis based on ISO 22301mascot4u
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planningalanlund
 
ISO 22301: The New Standard for Business Continuity Best Practice
ISO 22301: The New Standard for Business Continuity Best PracticeISO 22301: The New Standard for Business Continuity Best Practice
ISO 22301: The New Standard for Business Continuity Best PracticeMissionMode
 
Business Continuity Management PowerPoint Presentation Slides
Business Continuity Management PowerPoint Presentation SlidesBusiness Continuity Management PowerPoint Presentation Slides
Business Continuity Management PowerPoint Presentation SlidesSlideTeam
 
Assessing the Impact of a Disruption: Building an Effective Business Impact A...
Assessing the Impact of a Disruption: Building an Effective Business Impact A...Assessing the Impact of a Disruption: Building an Effective Business Impact A...
Assessing the Impact of a Disruption: Building an Effective Business Impact A...PECB
 
Bcm Framework PowerPoint Presentation Slides
Bcm Framework PowerPoint Presentation SlidesBcm Framework PowerPoint Presentation Slides
Bcm Framework PowerPoint Presentation SlidesSlideTeam
 
Disaster Recovery Planning
Disaster Recovery PlanningDisaster Recovery Planning
Disaster Recovery PlanningJohn Wilson
 
Business continuity planning and disaster recovery
Business continuity planning and disaster recoveryBusiness continuity planning and disaster recovery
Business continuity planning and disaster recoveryKrutiShah114
 
Business Impact Analysis - The Most Important Step during BCMS Implementation
Business Impact Analysis - The Most Important Step during BCMS ImplementationBusiness Impact Analysis - The Most Important Step during BCMS Implementation
Business Impact Analysis - The Most Important Step during BCMS ImplementationPECB
 
Governance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management SolutionGovernance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management SolutionRishabh Software
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity PlanningDipankar Ghosh
 
Business continuity & Disaster recovery planing
Business continuity & Disaster recovery planingBusiness continuity & Disaster recovery planing
Business continuity & Disaster recovery planingHanaysha
 
BCI ISO 22301 Benchmarking Report
BCI ISO 22301 Benchmarking ReportBCI ISO 22301 Benchmarking Report
BCI ISO 22301 Benchmarking ReportNQA
 

What's hot (20)

Business Impact Analysis - Clause 4 Of BS25999 In Practice
Business Impact Analysis - Clause 4 Of BS25999 In PracticeBusiness Impact Analysis - Clause 4 Of BS25999 In Practice
Business Impact Analysis - Clause 4 Of BS25999 In Practice
 
Business Continuity Planning Presentation Overview
Business Continuity Planning Presentation OverviewBusiness Continuity Planning Presentation Overview
Business Continuity Planning Presentation Overview
 
Awareness iso 22301 danang suryo
Awareness iso 22301 danang suryoAwareness iso 22301 danang suryo
Awareness iso 22301 danang suryo
 
Business impact.analysis based on ISO 22301
Business impact.analysis based on ISO 22301Business impact.analysis based on ISO 22301
Business impact.analysis based on ISO 22301
 
Business Continuity Management
Business Continuity ManagementBusiness Continuity Management
Business Continuity Management
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planning
 
ISO 22301: The New Standard for Business Continuity Best Practice
ISO 22301: The New Standard for Business Continuity Best PracticeISO 22301: The New Standard for Business Continuity Best Practice
ISO 22301: The New Standard for Business Continuity Best Practice
 
Business Continuity Management PowerPoint Presentation Slides
Business Continuity Management PowerPoint Presentation SlidesBusiness Continuity Management PowerPoint Presentation Slides
Business Continuity Management PowerPoint Presentation Slides
 
Assessing the Impact of a Disruption: Building an Effective Business Impact A...
Assessing the Impact of a Disruption: Building an Effective Business Impact A...Assessing the Impact of a Disruption: Building an Effective Business Impact A...
Assessing the Impact of a Disruption: Building an Effective Business Impact A...
 
Bcm Framework PowerPoint Presentation Slides
Bcm Framework PowerPoint Presentation SlidesBcm Framework PowerPoint Presentation Slides
Bcm Framework PowerPoint Presentation Slides
 
Disaster Recovery Planning
Disaster Recovery PlanningDisaster Recovery Planning
Disaster Recovery Planning
 
Business continuity planning and disaster recovery
Business continuity planning and disaster recoveryBusiness continuity planning and disaster recovery
Business continuity planning and disaster recovery
 
Business Impact Analysis - The Most Important Step during BCMS Implementation
Business Impact Analysis - The Most Important Step during BCMS ImplementationBusiness Impact Analysis - The Most Important Step during BCMS Implementation
Business Impact Analysis - The Most Important Step during BCMS Implementation
 
Business Continuity Planning Presentation
Business Continuity Planning PresentationBusiness Continuity Planning Presentation
Business Continuity Planning Presentation
 
Governance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management SolutionGovernance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management Solution
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planning
 
Business continuity & Disaster recovery planing
Business continuity & Disaster recovery planingBusiness continuity & Disaster recovery planing
Business continuity & Disaster recovery planing
 
BCI ISO 22301 Benchmarking Report
BCI ISO 22301 Benchmarking ReportBCI ISO 22301 Benchmarking Report
BCI ISO 22301 Benchmarking Report
 
Introduction to Business Continuity Management
Introduction to Business Continuity ManagementIntroduction to Business Continuity Management
Introduction to Business Continuity Management
 
Bcp drp
Bcp drpBcp drp
Bcp drp
 

Similar to PECB Webinar: The importance of business impact analysis

Development of business strategies and business models for associations
Development of business strategies and business models for associationsDevelopment of business strategies and business models for associations
Development of business strategies and business models for associationsajcortese
 
ITSM Academy Webinar - Establishing A Business Process Group
ITSM Academy Webinar - Establishing A Business Process GroupITSM Academy Webinar - Establishing A Business Process Group
ITSM Academy Webinar - Establishing A Business Process GroupITSM Academy, Inc.
 
SOEDS, 11th April 2022 How to Evaluate CSR Projects and Programmes.pptx
SOEDS, 11th April 2022 How to Evaluate CSR Projects and Programmes.pptxSOEDS, 11th April 2022 How to Evaluate CSR Projects and Programmes.pptx
SOEDS, 11th April 2022 How to Evaluate CSR Projects and Programmes.pptxRAKESHNANDAN7
 
itSMF 2020 - Business Analyzis
itSMF 2020 - Business AnalyzisitSMF 2020 - Business Analyzis
itSMF 2020 - Business AnalyzisitSMF Belgium
 
Operationalisng SROI
Operationalisng SROIOperationalisng SROI
Operationalisng SROISWF
 
NFP Strategic Initiatives Process 2012
NFP Strategic Initiatives Process  2012NFP Strategic Initiatives Process  2012
NFP Strategic Initiatives Process 2012chaberkorn
 
Harnessing cpd a road map for the future by Luke Stevens
Harnessing cpd a road map for the future by Luke Stevens Harnessing cpd a road map for the future by Luke Stevens
Harnessing cpd a road map for the future by Luke Stevens L2Lproject
 
Charles Rygula: Value Beyond Words
Charles Rygula: Value Beyond WordsCharles Rygula: Value Beyond Words
Charles Rygula: Value Beyond WordsJack Molisani
 
Framgångsfaktorer för Agil Utveckling av Mycket Stora Programvaruprodukter
Framgångsfaktorer för Agil Utveckling av Mycket Stora ProgramvaruprodukterFramgångsfaktorer för Agil Utveckling av Mycket Stora Programvaruprodukter
Framgångsfaktorer för Agil Utveckling av Mycket Stora ProgramvaruprodukterHansoft AB
 
Horizon 2020: UK Bio-based Industries Joint Undertaking Information and Broke...
Horizon 2020: UK Bio-based Industries Joint Undertaking Information and Broke...Horizon 2020: UK Bio-based Industries Joint Undertaking Information and Broke...
Horizon 2020: UK Bio-based Industries Joint Undertaking Information and Broke...KTN
 
JISC Beyond the Business Intelligence Programme
JISC Beyond the Business Intelligence ProgrammeJISC Beyond the Business Intelligence Programme
JISC Beyond the Business Intelligence Programmemylesdanson
 
Module 4.2 - Performance management
Module 4.2 - Performance managementModule 4.2 - Performance management
Module 4.2 - Performance managementszpinter
 
organizational culture
organizational culture organizational culture
organizational culture karan992457
 
ToC_training slide_set_Sniffer Aug 2015 v2 num-sm
ToC_training slide_set_Sniffer Aug 2015 v2 num-smToC_training slide_set_Sniffer Aug 2015 v2 num-sm
ToC_training slide_set_Sniffer Aug 2015 v2 num-smDr Seán Doolan, MBA
 
Monitoring and Evaluation of International Development Assistance to the Priv...
Monitoring and Evaluation of International Development Assistance to the Priv...Monitoring and Evaluation of International Development Assistance to the Priv...
Monitoring and Evaluation of International Development Assistance to the Priv...CesToronto
 
Keynote Address: Robbie Atabaigi, Manager Advisory Information Protection, KP...
Keynote Address: Robbie Atabaigi, Manager Advisory Information Protection, KP...Keynote Address: Robbie Atabaigi, Manager Advisory Information Protection, KP...
Keynote Address: Robbie Atabaigi, Manager Advisory Information Protection, KP...NICSA
 
Effective Reporting SAP Australian User Group Presentation
Effective Reporting SAP Australian User Group PresentationEffective Reporting SAP Australian User Group Presentation
Effective Reporting SAP Australian User Group Presentationpaul.hawking
 

Similar to PECB Webinar: The importance of business impact analysis (20)

Development of business strategies and business models for associations
Development of business strategies and business models for associationsDevelopment of business strategies and business models for associations
Development of business strategies and business models for associations
 
ITSM Academy Webinar - Establishing A Business Process Group
ITSM Academy Webinar - Establishing A Business Process GroupITSM Academy Webinar - Establishing A Business Process Group
ITSM Academy Webinar - Establishing A Business Process Group
 
SOEDS, 11th April 2022 How to Evaluate CSR Projects and Programmes.pptx
SOEDS, 11th April 2022 How to Evaluate CSR Projects and Programmes.pptxSOEDS, 11th April 2022 How to Evaluate CSR Projects and Programmes.pptx
SOEDS, 11th April 2022 How to Evaluate CSR Projects and Programmes.pptx
 
itSMF 2020 - Business Analyzis
itSMF 2020 - Business AnalyzisitSMF 2020 - Business Analyzis
itSMF 2020 - Business Analyzis
 
Operationalisng SROI
Operationalisng SROIOperationalisng SROI
Operationalisng SROI
 
NFP Strategic Initiatives Process 2012
NFP Strategic Initiatives Process  2012NFP Strategic Initiatives Process  2012
NFP Strategic Initiatives Process 2012
 
Harnessing cpd a road map for the future by Luke Stevens
Harnessing cpd a road map for the future by Luke Stevens Harnessing cpd a road map for the future by Luke Stevens
Harnessing cpd a road map for the future by Luke Stevens
 
Charles Rygula: Value Beyond Words
Charles Rygula: Value Beyond WordsCharles Rygula: Value Beyond Words
Charles Rygula: Value Beyond Words
 
Framgångsfaktorer för Agil Utveckling av Mycket Stora Programvaruprodukter
Framgångsfaktorer för Agil Utveckling av Mycket Stora ProgramvaruprodukterFramgångsfaktorer för Agil Utveckling av Mycket Stora Programvaruprodukter
Framgångsfaktorer för Agil Utveckling av Mycket Stora Programvaruprodukter
 
Horizon 2020: UK Bio-based Industries Joint Undertaking Information and Broke...
Horizon 2020: UK Bio-based Industries Joint Undertaking Information and Broke...Horizon 2020: UK Bio-based Industries Joint Undertaking Information and Broke...
Horizon 2020: UK Bio-based Industries Joint Undertaking Information and Broke...
 
Strategy analysis
Strategy analysisStrategy analysis
Strategy analysis
 
JISC Beyond the Business Intelligence Programme
JISC Beyond the Business Intelligence ProgrammeJISC Beyond the Business Intelligence Programme
JISC Beyond the Business Intelligence Programme
 
Module 4.2 - Performance management
Module 4.2 - Performance managementModule 4.2 - Performance management
Module 4.2 - Performance management
 
Dynamic Duos
Dynamic DuosDynamic Duos
Dynamic Duos
 
organizational culture
organizational culture organizational culture
organizational culture
 
ToC_training slide_set_Sniffer Aug 2015 v2 num-sm
ToC_training slide_set_Sniffer Aug 2015 v2 num-smToC_training slide_set_Sniffer Aug 2015 v2 num-sm
ToC_training slide_set_Sniffer Aug 2015 v2 num-sm
 
Monitoring and Evaluation of International Development Assistance to the Priv...
Monitoring and Evaluation of International Development Assistance to the Priv...Monitoring and Evaluation of International Development Assistance to the Priv...
Monitoring and Evaluation of International Development Assistance to the Priv...
 
Keynote Address: Robbie Atabaigi, Manager Advisory Information Protection, KP...
Keynote Address: Robbie Atabaigi, Manager Advisory Information Protection, KP...Keynote Address: Robbie Atabaigi, Manager Advisory Information Protection, KP...
Keynote Address: Robbie Atabaigi, Manager Advisory Information Protection, KP...
 
BAs IIBA and the BABOK
BAs IIBA and the BABOKBAs IIBA and the BABOK
BAs IIBA and the BABOK
 
Effective Reporting SAP Australian User Group Presentation
Effective Reporting SAP Australian User Group PresentationEffective Reporting SAP Australian User Group Presentation
Effective Reporting SAP Australian User Group Presentation
 

More from PECB

DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityDORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityPECB
 
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernanceSecuring the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernancePECB
 
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...PECB
 
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...PECB
 
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyPECB
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...PECB
 
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationPECB
 
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsManaging ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsPECB
 
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?PECB
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...PECB
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...PECB
 
Student Information Session University KTMC
Student Information Session University KTMC Student Information Session University KTMC
Student Information Session University KTMC PECB
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...PECB
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...PECB
 
Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA PECB
 
IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?PECB
 
Information Session University Egybyte.pptx
Information Session University Egybyte.pptxInformation Session University Egybyte.pptx
Information Session University Egybyte.pptxPECB
 
Student Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxStudent Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxPECB
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023PECB
 
ISO 28000:2022 – Reduce risks and improve the security management system
ISO 28000:2022 – Reduce risks and improve the security management systemISO 28000:2022 – Reduce risks and improve the security management system
ISO 28000:2022 – Reduce risks and improve the security management systemPECB
 

More from PECB (20)

DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityDORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
 
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernanceSecuring the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
 
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
 
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
 
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
 
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
 
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsManaging ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
 
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
 
Student Information Session University KTMC
Student Information Session University KTMC Student Information Session University KTMC
Student Information Session University KTMC
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
 
Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA
 
IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?
 
Information Session University Egybyte.pptx
Information Session University Egybyte.pptxInformation Session University Egybyte.pptx
Information Session University Egybyte.pptx
 
Student Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxStudent Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptx
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023
 
ISO 28000:2022 – Reduce risks and improve the security management system
ISO 28000:2022 – Reduce risks and improve the security management systemISO 28000:2022 – Reduce risks and improve the security management system
ISO 28000:2022 – Reduce risks and improve the security management system
 

Recently uploaded

Difference Between Search & Browse Methods in Odoo 17
Difference Between Search & Browse Methods in Odoo 17Difference Between Search & Browse Methods in Odoo 17
Difference Between Search & Browse Methods in Odoo 17Celine George
 
ENGLISH6-Q4-W3.pptxqurter our high choom
ENGLISH6-Q4-W3.pptxqurter our high choomENGLISH6-Q4-W3.pptxqurter our high choom
ENGLISH6-Q4-W3.pptxqurter our high choomnelietumpap1
 
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...JhezDiaz1
 
USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...
USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...
USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...Postal Advocate Inc.
 
Inclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdf
Inclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdfInclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdf
Inclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdfTechSoup
 
ECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptx
ECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptxECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptx
ECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptxiammrhaywood
 
What is Model Inheritance in Odoo 17 ERP
What is Model Inheritance in Odoo 17 ERPWhat is Model Inheritance in Odoo 17 ERP
What is Model Inheritance in Odoo 17 ERPCeline George
 
ANG SEKTOR NG agrikultura.pptx QUARTER 4
ANG SEKTOR NG agrikultura.pptx QUARTER 4ANG SEKTOR NG agrikultura.pptx QUARTER 4
ANG SEKTOR NG agrikultura.pptx QUARTER 4MiaBumagat1
 
How to Add Barcode on PDF Report in Odoo 17
How to Add Barcode on PDF Report in Odoo 17How to Add Barcode on PDF Report in Odoo 17
How to Add Barcode on PDF Report in Odoo 17Celine George
 
Proudly South Africa powerpoint Thorisha.pptx
Proudly South Africa powerpoint Thorisha.pptxProudly South Africa powerpoint Thorisha.pptx
Proudly South Africa powerpoint Thorisha.pptxthorishapillay1
 
ACC 2024 Chronicles. Cardiology. Exam.pdf
ACC 2024 Chronicles. Cardiology. Exam.pdfACC 2024 Chronicles. Cardiology. Exam.pdf
ACC 2024 Chronicles. Cardiology. Exam.pdfSpandanaRallapalli
 
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdf
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdfGrade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdf
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdfJemuel Francisco
 
Keynote by Prof. Wurzer at Nordex about IP-design
Keynote by Prof. Wurzer at Nordex about IP-designKeynote by Prof. Wurzer at Nordex about IP-design
Keynote by Prof. Wurzer at Nordex about IP-designMIPLM
 
Transaction Management in Database Management System
Transaction Management in Database Management SystemTransaction Management in Database Management System
Transaction Management in Database Management SystemChristalin Nelson
 
Culture Uniformity or Diversity IN SOCIOLOGY.pptx
Culture Uniformity or Diversity IN SOCIOLOGY.pptxCulture Uniformity or Diversity IN SOCIOLOGY.pptx
Culture Uniformity or Diversity IN SOCIOLOGY.pptxPoojaSen20
 
ISYU TUNGKOL SA SEKSWLADIDA (ISSUE ABOUT SEXUALITY
ISYU TUNGKOL SA SEKSWLADIDA (ISSUE ABOUT SEXUALITYISYU TUNGKOL SA SEKSWLADIDA (ISSUE ABOUT SEXUALITY
ISYU TUNGKOL SA SEKSWLADIDA (ISSUE ABOUT SEXUALITYKayeClaireEstoconing
 
INTRODUCTION TO CATHOLIC CHRISTOLOGY.pptx
INTRODUCTION TO CATHOLIC CHRISTOLOGY.pptxINTRODUCTION TO CATHOLIC CHRISTOLOGY.pptx
INTRODUCTION TO CATHOLIC CHRISTOLOGY.pptxHumphrey A Beña
 

Recently uploaded (20)

Difference Between Search & Browse Methods in Odoo 17
Difference Between Search & Browse Methods in Odoo 17Difference Between Search & Browse Methods in Odoo 17
Difference Between Search & Browse Methods in Odoo 17
 
YOUVE GOT EMAIL_FINALS_EL_DORADO_2024.pptx
YOUVE GOT EMAIL_FINALS_EL_DORADO_2024.pptxYOUVE GOT EMAIL_FINALS_EL_DORADO_2024.pptx
YOUVE GOT EMAIL_FINALS_EL_DORADO_2024.pptx
 
ENGLISH6-Q4-W3.pptxqurter our high choom
ENGLISH6-Q4-W3.pptxqurter our high choomENGLISH6-Q4-W3.pptxqurter our high choom
ENGLISH6-Q4-W3.pptxqurter our high choom
 
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...
 
USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...
USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...
USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...
 
Inclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdf
Inclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdfInclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdf
Inclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdf
 
ECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptx
ECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptxECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptx
ECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptx
 
What is Model Inheritance in Odoo 17 ERP
What is Model Inheritance in Odoo 17 ERPWhat is Model Inheritance in Odoo 17 ERP
What is Model Inheritance in Odoo 17 ERP
 
ANG SEKTOR NG agrikultura.pptx QUARTER 4
ANG SEKTOR NG agrikultura.pptx QUARTER 4ANG SEKTOR NG agrikultura.pptx QUARTER 4
ANG SEKTOR NG agrikultura.pptx QUARTER 4
 
How to Add Barcode on PDF Report in Odoo 17
How to Add Barcode on PDF Report in Odoo 17How to Add Barcode on PDF Report in Odoo 17
How to Add Barcode on PDF Report in Odoo 17
 
Proudly South Africa powerpoint Thorisha.pptx
Proudly South Africa powerpoint Thorisha.pptxProudly South Africa powerpoint Thorisha.pptx
Proudly South Africa powerpoint Thorisha.pptx
 
YOUVE_GOT_EMAIL_PRELIMS_EL_DORADO_2024.pptx
YOUVE_GOT_EMAIL_PRELIMS_EL_DORADO_2024.pptxYOUVE_GOT_EMAIL_PRELIMS_EL_DORADO_2024.pptx
YOUVE_GOT_EMAIL_PRELIMS_EL_DORADO_2024.pptx
 
Raw materials used in Herbal Cosmetics.pptx
Raw materials used in Herbal Cosmetics.pptxRaw materials used in Herbal Cosmetics.pptx
Raw materials used in Herbal Cosmetics.pptx
 
ACC 2024 Chronicles. Cardiology. Exam.pdf
ACC 2024 Chronicles. Cardiology. Exam.pdfACC 2024 Chronicles. Cardiology. Exam.pdf
ACC 2024 Chronicles. Cardiology. Exam.pdf
 
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdf
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdfGrade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdf
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdf
 
Keynote by Prof. Wurzer at Nordex about IP-design
Keynote by Prof. Wurzer at Nordex about IP-designKeynote by Prof. Wurzer at Nordex about IP-design
Keynote by Prof. Wurzer at Nordex about IP-design
 
Transaction Management in Database Management System
Transaction Management in Database Management SystemTransaction Management in Database Management System
Transaction Management in Database Management System
 
Culture Uniformity or Diversity IN SOCIOLOGY.pptx
Culture Uniformity or Diversity IN SOCIOLOGY.pptxCulture Uniformity or Diversity IN SOCIOLOGY.pptx
Culture Uniformity or Diversity IN SOCIOLOGY.pptx
 
ISYU TUNGKOL SA SEKSWLADIDA (ISSUE ABOUT SEXUALITY
ISYU TUNGKOL SA SEKSWLADIDA (ISSUE ABOUT SEXUALITYISYU TUNGKOL SA SEKSWLADIDA (ISSUE ABOUT SEXUALITY
ISYU TUNGKOL SA SEKSWLADIDA (ISSUE ABOUT SEXUALITY
 
INTRODUCTION TO CATHOLIC CHRISTOLOGY.pptx
INTRODUCTION TO CATHOLIC CHRISTOLOGY.pptxINTRODUCTION TO CATHOLIC CHRISTOLOGY.pptx
INTRODUCTION TO CATHOLIC CHRISTOLOGY.pptx
 

PECB Webinar: The importance of business impact analysis

  • 1.
  • 2. The Business Impact Analysis (BIA) as Foundation of the BCM Approach Dr. Wolfgang H. Mahr, M.Sc., BBA, MBCI, CISA governance & continuuuity gmbh CH-8408 Winterthur, Switzerland www.continuuuity.ch LinkedIn, XING, Twitter wolfgang.mahr@continuuuity.ch
  • 3. Contents  Why a BIA?  BIA in the BCM Lifecycle  Outcomes of the BIA  BIA supporting BCM Goals  ISO 22317 on the BIA  BIA Approaches  Challenges when doing a BIA  Sokrates Maps –what’s this?  Sokrates Maps Benefits and Applications  Sokrates Maps for the BIA  BIA Critical Success Factors
  • 4. Abstract • This contribution underlines the fundamental importance of the one of the most important phases in the BCM lifecycle – the BIA. • Other - subsequent - phases such as selecting one or more business continuity strategies or the formulation of a BC plan, exhibit a much smaller space of choices than the BIA, which is primarily an information gathering stage, charged with understanding the business. • Critically important information needs to be unearthed and, ideally, not one important aspect must be omitted or forgotten. This is the reason why ISO TC 292 (formerly 223), after developing ISO 22301 and ISO 22313, has embarked on developing a standard on the BIA: ISO 22317. It is being presented in another contribution at this conference. • This paper focuses on a visualization and presentation method newly applied to the BIA process, in order to better understand a company’s processes, resources and their interdependencies.
  • 5. Why a BIA? • BCM is a cyclic process • BCM is based on continuous improvement • BIA makes you know your processes better • BIA is the base for the subsequent development of one or more Business Continuity Strategies • …
  • 6. Why a BIA? • Increasing the efficiency of the organisation • Evaluate alternative strategic planning options • Assist in long-term strategy decision making • Assist in developing a risk analysis • …
  • 7. BIA in the BCM lifecycle Reference: The Business Continuity Institute
  • 8. BIA in the BCM lifecycle Reference: ISO 22301:2012
  • 9. Outcomes of the BIA • Major outcomes include: – Validation of the organisation’s BC programme scope – Identification of requirements the organisation – Determination of impacts, over time (of disruptions) – Identification of relationships between • Products/services • Processes • Activities • Resources – Resources needed to perform prioritised activities – Such as facilities, people, assets, supplies, financial resources – Dependencies and interrelationships – …
  • 10. BIA supporting BCM Goals • Protecting company value and reputation • Safeguards the reputation and future of the company in an emergency • Increase shareholder value and demonstrates commitment by management • Assures the survival of the company in the case of a serious incident • Minimize financial losses in case of an incident or emergency
  • 11. ISO/TS 22317 on BIA • Developed by ISO TC292 (“Security and Resilience”) • Currently as DTS (Draft Technical Specification) • To be published within the next couple of months • Based on ISO 22301, ISO 22313 and ISO 22300 • Focus on Performing the BIA: – Project Planning and Management – Product and Service Prioritisation – Process Prioritisation – Activity Prioritisation – Analysis and Consolidation – Top Management Endorsement of BIA Results • Annexes on – Terminology Mapping – Information Collection Methods
  • 12. BIA Approaches • Gold, Silver, Bronze • Strategic / Tactical • Iterations • Questionnaires • Workshops • Interviews – Middle Management – Process Owners
  • 13. Challenges when doing a BIA • Commitment • Level of effort • “Right” effort • Correctness /Completeness • No excessive overlap / no white spots
  • 14. Sokrates Maps – what’s this?
  • 15. Sokrates Maps – what’s this?
  • 16. Sokrates Maps – what’s this?
  • 17. Sokrates Maps – Benefits • Benefits – Foundation of method – Psychological background – Common view across hierarchies and disciplines – Discover new: • Ideas • Facts • Relationships • Dependencies • Communicate & visualize • Hierarchical view on complex situations • Electronic representation, communication and archiving
  • 18. Sokrates Maps - Applications
  • 19. Sokrates Maps - Applications  Board Level view of a hospital:  Get the big picture ◦ Based on details
  • 20. Sokrates Maps - Applications
  • 21. Sokrates Maps for BIA • Visualisation of the standards (psychological foundation) – ISO 22301, ISO 22317 (maturity model) • Assessment tool, BIA support tool – Presentation of BIA findings (electronic representation, communication and archiving) – Usage as questionnaire (maturity model, psychological foundation) • Single person or in workshops – Visualisation (hierarchical, common view across disciplines) • Overlaps (discover ideas, facts, relationships, dependencies) • Gaps (discover ideas, facts, relationships, dependencies) • Redundancies (discover ideas, facts, relationships, dependencies) –  Enhanced BIA quality and maturity
  • 22. BIA Critical Success Factors • Follow best practices such as – BCI’s Good Practice Guidelines and/or – ISO Standards such a ISO 22301, ISO 22313 and ISO/TS 22317 • Obtain top management commitment • Apply project management methodologies • Follow a BIA approach fit for the selected type of BIA • Use an approach compatible with the company’s structure • Deploy tools helping to obtain a “true and fair” representation of products, services, priorities, dependencies and requirements • Develop a hierarchical view on complex situations • Use electronic representation, communication and archiving