SlideShare a Scribd company logo
ISO27002: 2022
Information security, cybersecurity and privacy protection — Information
security controls
Requirement Number 5.30
Ensure the Availability of the organization including 3rd party vendor which
is connected to our information assets during disruption. In aspect of that,
Conducting BIA (Business Impact Analysis) would be important.
BIA (Business Impact Analysis)
Date of BIA 2020/MAR/3 Date of BIA 2020/MAR/2 Date of BIA 2020/MAR/2
Location Tokyo, JAPAN Location India Location Hong Kong
Date of Review 2020/JUN/3 13:00 (JST) Date of Review 2020/JUN/3 9:30 (IndiaTime) Date of Review 2020/JUN/3 12:00 (HK Time)
Data Onwer (Info Owner)
Name Sato, Jason
Applicateion Owner
Name Newf, Swere
Risk Owner Name
Marry, Jane
Department IT Risk department Department xxx Application department Department xxx Application department
Role BCP Manager Role Project Manager Role Project Manager
BIA Version RA-BIA-v3
Activities and scenarios reviewed
Risk Reviewed Function responsible Activity importance Max time to restart Time to normal service Comment
Critical service App team Vital 1 24
Failier of system necessary
Critical service desired
Failier of system necessary
Critical service Critial
BIA per scenario
Impact over time
#1 Critical service High Medium Low 1hour 2hour 12hour 24 hour Comment
Impact of disruption x H H H H
Sales Staff × M H H H
Operation Staff × L H H H
Procurement staff
×
L H H H
Support team × L H H H
Infosec team × L H H H
Financial × L H H H
Service level × L H H H
Customers × H H H H
BIA Summary
Activity reviewed #1 Function owned by Activity importance Risk treatment Recovery Sequence
Max time to restart
(hours)
Time to normal
service level
Comment
Shift deployeing planning Critical Acceptance 1 72 7
review of service in schedule Critical Acceptance 2
Critical Business Continuity 3
Critical Business Continuity 4
Activity reviewed #2 Function owned by Activity importance Risk treatment Recovery Sequence
Max time to restart
(hours)
Time to normal
service level
Comment
Shift deployeing planning Critical Acceptance 1 72 7
review of service in schedule 2
Business Continuity 3
Business Continuity 4
Activity name #1
Activity frequency more than hourly
activity owner title
Date of operation every day
Number of FTEs
involved
hours of operation 8 hours
Daily peak details
weekly peak details
Monthly peak details
Annual peak details
Activity name #2
Activity frequency more than hourly
activity owner title
Date of operation every day
Number of FTEs
involved
hours of operation 8 hours
Daily peak details
weekly peak details
Monthly peak details
Annual peak details
Dependencies
a) Internal Independencies of Activity b) External Interdependencies of Activity
Internal Independencies External Independencies
Owner Owner
Internal Independencies External Independencies
Owner Owner
Internal Independencies External Independencies
Owner Owner
Internal Independencies External Independencies
Owner Owner
People Impact
Day1 Day2 Day3 Day4 Day8 Day15 1 month Comments
Customer
Staff
Security
Operation
Customer service
IT
Business Impact
Day1 Day2 Day3 Day4 Day8 Day15 1 month Comments
Financial
Service Levels
Contractual
agreements
Reputation
Helth and Safety
Resources required to restart activity and reach normal service level
Headcount Restart Normal
Skill as restart
knowledge
IT
Importance of activity
Agreed level of importance of activity of key business services and
objectives.
Critical
Completed by
Positions
Date
Signature
Senior Management agreement that the fundings detailed above are a true reflection of the organization
Completed by
Positions
Date
Signature
Sooma, Jerimi
Senor VP
2021/JUL/3
CEO
2021/JUL/3
Mwema, Adsf
Impact - Business Function Information
How long can the activity operate in manual mode?
Are there any written processes/ procedures for operation in manual
mode?
When were the processes / procedures for operating in manual mode
last updated?
What additioanl respurces are required for operating in manual mode?
In the event of a disruption there will be lost data / transactions. Can
they be recovered?
How will lost data be recovered?
Are there any written processes / procefures for recovering lost data?
When were the processes / procedures for recovering list data last
updated?
What would be the impact if the data cannot be recovered?
Does the activity reply on information that is not electronic? (Specify
data and media)
How will lost (non electronic) information be recovered?
What specialised equipment is required to perform the activity?
CIO

More Related Content

Similar to Business Impact Analysis 【My Continuous Learning】

Best Practices for the Service Cloud
Best Practices for the Service CloudBest Practices for the Service Cloud
Best Practices for the Service CloudRoss Bauer
 
PDD Template.docx
PDD Template.docxPDD Template.docx
PDD Template.docx
VladBucatariu
 
Business Impact Analysis
Business Impact AnalysisBusiness Impact Analysis
Business Impact Analysis
dlfrench
 
Cyber Security and Business Continuity an Integrated Discipline
Cyber Security and Business Continuity an Integrated DisciplineCyber Security and Business Continuity an Integrated Discipline
Cyber Security and Business Continuity an Integrated Discipline
Graeme Parker
 
Sample audit plan
Sample audit planSample audit plan
Sample audit plan
Maher Manan
 
Nintex Workflow for Sharepoint - Return on Investment Whitepaper by Forrester...
Nintex Workflow for Sharepoint - Return on Investment Whitepaper by Forrester...Nintex Workflow for Sharepoint - Return on Investment Whitepaper by Forrester...
Nintex Workflow for Sharepoint - Return on Investment Whitepaper by Forrester...
David J Rosenthal
 
Puneet Green Belt(13th feb).pptx
Puneet Green Belt(13th feb).pptxPuneet Green Belt(13th feb).pptx
Puneet Green Belt(13th feb).pptx
Puneet Gupta
 
Planning For Long-Term Success Of A Business
Planning For Long-Term Success Of A BusinessPlanning For Long-Term Success Of A Business
Planning For Long-Term Success Of A Business
Liz Sims
 
ExpoGestão 2018 Palestra Peter Walker
ExpoGestão 2018 Palestra Peter WalkerExpoGestão 2018 Palestra Peter Walker
ExpoGestão 2018 Palestra Peter Walker
ExpoGestão
 
Ascent overview deck_sep_25_2013
Ascent overview deck_sep_25_2013Ascent overview deck_sep_25_2013
Ascent overview deck_sep_25_2013Bindu Rathore
 
1. Automated Business Process
1. Automated Business Process1. Automated Business Process
1. Automated Business Process
Ashish Desai
 
Disa Itsm V1.3
Disa Itsm V1.3Disa Itsm V1.3
Disa Itsm V1.3
djaehnig
 
2010 06 gartner avoiding audit fatigue in nine steps 1d
2010 06 gartner   avoiding audit fatigue in nine steps 1d2010 06 gartner   avoiding audit fatigue in nine steps 1d
2010 06 gartner avoiding audit fatigue in nine steps 1d
Gene Kim
 
Developing IT Strategy
Developing IT StrategyDeveloping IT Strategy
Developing IT Strategy
Mario Navarro
 
Topic 3 Accounting System And Control
Topic 3 Accounting System And ControlTopic 3 Accounting System And Control
Topic 3 Accounting System And Controlmandalina landy
 
Behavioral Safety Leadership in Oil & Gas construction
Behavioral Safety Leadership in Oil & Gas constructionBehavioral Safety Leadership in Oil & Gas construction
Behavioral Safety Leadership in Oil & Gas construction
B-Safe Management Solutions Inc.
 
EIS Amendments CA INTER
EIS Amendments CA INTEREIS Amendments CA INTER
EIS Amendments CA INTER
Raj Kumar
 
New Zealand - Data use and frameworks.
New Zealand - Data use and frameworks.New Zealand - Data use and frameworks.
New Zealand - Data use and frameworks.
Corporate Registers Forum
 

Similar to Business Impact Analysis 【My Continuous Learning】 (20)

Best Practices for the Service Cloud
Best Practices for the Service CloudBest Practices for the Service Cloud
Best Practices for the Service Cloud
 
PDD Template.docx
PDD Template.docxPDD Template.docx
PDD Template.docx
 
Business Impact Analysis
Business Impact AnalysisBusiness Impact Analysis
Business Impact Analysis
 
Cyber Security and Business Continuity an Integrated Discipline
Cyber Security and Business Continuity an Integrated DisciplineCyber Security and Business Continuity an Integrated Discipline
Cyber Security and Business Continuity an Integrated Discipline
 
Sample audit plan
Sample audit planSample audit plan
Sample audit plan
 
Sapna Resume
Sapna ResumeSapna Resume
Sapna Resume
 
Nintex Workflow for Sharepoint - Return on Investment Whitepaper by Forrester...
Nintex Workflow for Sharepoint - Return on Investment Whitepaper by Forrester...Nintex Workflow for Sharepoint - Return on Investment Whitepaper by Forrester...
Nintex Workflow for Sharepoint - Return on Investment Whitepaper by Forrester...
 
Puneet Green Belt(13th feb).pptx
Puneet Green Belt(13th feb).pptxPuneet Green Belt(13th feb).pptx
Puneet Green Belt(13th feb).pptx
 
Planning For Long-Term Success Of A Business
Planning For Long-Term Success Of A BusinessPlanning For Long-Term Success Of A Business
Planning For Long-Term Success Of A Business
 
SINDHU RESUME RECENT
SINDHU RESUME RECENTSINDHU RESUME RECENT
SINDHU RESUME RECENT
 
ExpoGestão 2018 Palestra Peter Walker
ExpoGestão 2018 Palestra Peter WalkerExpoGestão 2018 Palestra Peter Walker
ExpoGestão 2018 Palestra Peter Walker
 
Ascent overview deck_sep_25_2013
Ascent overview deck_sep_25_2013Ascent overview deck_sep_25_2013
Ascent overview deck_sep_25_2013
 
1. Automated Business Process
1. Automated Business Process1. Automated Business Process
1. Automated Business Process
 
Disa Itsm V1.3
Disa Itsm V1.3Disa Itsm V1.3
Disa Itsm V1.3
 
2010 06 gartner avoiding audit fatigue in nine steps 1d
2010 06 gartner   avoiding audit fatigue in nine steps 1d2010 06 gartner   avoiding audit fatigue in nine steps 1d
2010 06 gartner avoiding audit fatigue in nine steps 1d
 
Developing IT Strategy
Developing IT StrategyDeveloping IT Strategy
Developing IT Strategy
 
Topic 3 Accounting System And Control
Topic 3 Accounting System And ControlTopic 3 Accounting System And Control
Topic 3 Accounting System And Control
 
Behavioral Safety Leadership in Oil & Gas construction
Behavioral Safety Leadership in Oil & Gas constructionBehavioral Safety Leadership in Oil & Gas construction
Behavioral Safety Leadership in Oil & Gas construction
 
EIS Amendments CA INTER
EIS Amendments CA INTEREIS Amendments CA INTER
EIS Amendments CA INTER
 
New Zealand - Data use and frameworks.
New Zealand - Data use and frameworks.New Zealand - Data use and frameworks.
New Zealand - Data use and frameworks.
 

More from Jerimi Soma

IRCA ISMS Auditor Certification for Version 2022 (Since 2017)
IRCA ISMS Auditor Certification for Version 2022 (Since 2017)IRCA ISMS Auditor Certification for Version 2022 (Since 2017)
IRCA ISMS Auditor Certification for Version 2022 (Since 2017)
Jerimi Soma
 
Another ITIL4 story of a Japanese business hotel
Another ITIL4 story of a Japanese business hotelAnother ITIL4 story of a Japanese business hotel
Another ITIL4 story of a Japanese business hotel
Jerimi Soma
 
Japan Data Privacy Auditor Certification (Since Jan. 2021)
Japan Data Privacy Auditor Certification (Since Jan. 2021)Japan Data Privacy Auditor Certification (Since Jan. 2021)
Japan Data Privacy Auditor Certification (Since Jan. 2021)
Jerimi Soma
 
ITILv3 /2011 Edition Case Study
ITILv3 /2011 Edition Case StudyITILv3 /2011 Edition Case Study
ITILv3 /2011 Edition Case Study
Jerimi Soma
 
ITIL4 Managing Professtioal
ITIL4 Managing ProfesstioalITIL4 Managing Professtioal
ITIL4 Managing Professtioal
Jerimi Soma
 
JRCA ISO27017 Cloud Security Training & Exam
JRCA ISO27017 Cloud  Security Training & ExamJRCA ISO27017 Cloud  Security Training & Exam
JRCA ISO27017 Cloud Security Training & Exam
Jerimi Soma
 
ITIL v2011 Expert 6 exams
ITIL v2011 Expert 6 examsITIL v2011 Expert 6 exams
ITIL v2011 Expert 6 exams
Jerimi Soma
 
QSA training & exam in 2017, 2018, 2019, 2020, 2021 and PCIP in 2022 - 2025
QSA training & exam in 2017, 2018, 2019, 2020, 2021 and PCIP in 2022 - 2025QSA training & exam in 2017, 2018, 2019, 2020, 2021 and PCIP in 2022 - 2025
QSA training & exam in 2017, 2018, 2019, 2020, 2021 and PCIP in 2022 - 2025
Jerimi Soma
 
ISO20000-1 Training Completion in 2022
ISO20000-1 Training Completion in 2022ISO20000-1 Training Completion in 2022
ISO20000-1 Training Completion in 2022
Jerimi Soma
 
Six Sigma Black Belt
Six Sigma Black BeltSix Sigma Black Belt
Six Sigma Black Belt
Jerimi Soma
 
IRCA BCMS Lead Auditor Training & Exam
IRCA BCMS Lead Auditor Training & ExamIRCA BCMS Lead Auditor Training & Exam
IRCA BCMS Lead Auditor Training & Exam
Jerimi Soma
 
BSI ISO27001 Lead Implementer ENR-00775738
BSI ISO27001 Lead Implementer ENR-00775738BSI ISO27001 Lead Implementer ENR-00775738
BSI ISO27001 Lead Implementer ENR-00775738
Jerimi Soma
 
IRCA QMS Lead Auditor 5-day training & exam
IRCA QMS Lead Auditor 5-day training & examIRCA QMS Lead Auditor 5-day training & exam
IRCA QMS Lead Auditor 5-day training & exam
Jerimi Soma
 
IRCA ISMS Lead Auditor Training & Exam in 2014
IRCA ISMS Lead Auditor Training & Exam in 2014IRCA ISMS Lead Auditor Training & Exam in 2014
IRCA ISMS Lead Auditor Training & Exam in 2014
Jerimi Soma
 
Henry James Study
Henry James StudyHenry James Study
Henry James Study
Jerimi Soma
 
My Gap analysis results between ISO27001: 2022 and 2013 version as of 2022 fall.
My Gap analysis results between ISO27001: 2022 and 2013 version as of 2022 fall.My Gap analysis results between ISO27001: 2022 and 2013 version as of 2022 fall.
My Gap analysis results between ISO27001: 2022 and 2013 version as of 2022 fall.
Jerimi Soma
 
ISO20000-1 Auditors note 【My Continuous Learning】
ISO20000-1 Auditors note 【My Continuous Learning】ISO20000-1 Auditors note 【My Continuous Learning】
ISO20000-1 Auditors note 【My Continuous Learning】
Jerimi Soma
 
BCMS Audit Report【My Continuous Learning】
BCMS Audit  Report【My Continuous Learning】BCMS Audit  Report【My Continuous Learning】
BCMS Audit Report【My Continuous Learning】
Jerimi Soma
 
SixSigma 【Continuous Study】
SixSigma 【Continuous Study】SixSigma 【Continuous Study】
SixSigma 【Continuous Study】
Jerimi Soma
 
Use Cases for ISO20000-1 based on ITIL in English 【Continuous Study】
Use Cases for ISO20000-1 based on ITIL in English 【Continuous Study】Use Cases for ISO20000-1 based on ITIL in English 【Continuous Study】
Use Cases for ISO20000-1 based on ITIL in English 【Continuous Study】
Jerimi Soma
 

More from Jerimi Soma (20)

IRCA ISMS Auditor Certification for Version 2022 (Since 2017)
IRCA ISMS Auditor Certification for Version 2022 (Since 2017)IRCA ISMS Auditor Certification for Version 2022 (Since 2017)
IRCA ISMS Auditor Certification for Version 2022 (Since 2017)
 
Another ITIL4 story of a Japanese business hotel
Another ITIL4 story of a Japanese business hotelAnother ITIL4 story of a Japanese business hotel
Another ITIL4 story of a Japanese business hotel
 
Japan Data Privacy Auditor Certification (Since Jan. 2021)
Japan Data Privacy Auditor Certification (Since Jan. 2021)Japan Data Privacy Auditor Certification (Since Jan. 2021)
Japan Data Privacy Auditor Certification (Since Jan. 2021)
 
ITILv3 /2011 Edition Case Study
ITILv3 /2011 Edition Case StudyITILv3 /2011 Edition Case Study
ITILv3 /2011 Edition Case Study
 
ITIL4 Managing Professtioal
ITIL4 Managing ProfesstioalITIL4 Managing Professtioal
ITIL4 Managing Professtioal
 
JRCA ISO27017 Cloud Security Training & Exam
JRCA ISO27017 Cloud  Security Training & ExamJRCA ISO27017 Cloud  Security Training & Exam
JRCA ISO27017 Cloud Security Training & Exam
 
ITIL v2011 Expert 6 exams
ITIL v2011 Expert 6 examsITIL v2011 Expert 6 exams
ITIL v2011 Expert 6 exams
 
QSA training & exam in 2017, 2018, 2019, 2020, 2021 and PCIP in 2022 - 2025
QSA training & exam in 2017, 2018, 2019, 2020, 2021 and PCIP in 2022 - 2025QSA training & exam in 2017, 2018, 2019, 2020, 2021 and PCIP in 2022 - 2025
QSA training & exam in 2017, 2018, 2019, 2020, 2021 and PCIP in 2022 - 2025
 
ISO20000-1 Training Completion in 2022
ISO20000-1 Training Completion in 2022ISO20000-1 Training Completion in 2022
ISO20000-1 Training Completion in 2022
 
Six Sigma Black Belt
Six Sigma Black BeltSix Sigma Black Belt
Six Sigma Black Belt
 
IRCA BCMS Lead Auditor Training & Exam
IRCA BCMS Lead Auditor Training & ExamIRCA BCMS Lead Auditor Training & Exam
IRCA BCMS Lead Auditor Training & Exam
 
BSI ISO27001 Lead Implementer ENR-00775738
BSI ISO27001 Lead Implementer ENR-00775738BSI ISO27001 Lead Implementer ENR-00775738
BSI ISO27001 Lead Implementer ENR-00775738
 
IRCA QMS Lead Auditor 5-day training & exam
IRCA QMS Lead Auditor 5-day training & examIRCA QMS Lead Auditor 5-day training & exam
IRCA QMS Lead Auditor 5-day training & exam
 
IRCA ISMS Lead Auditor Training & Exam in 2014
IRCA ISMS Lead Auditor Training & Exam in 2014IRCA ISMS Lead Auditor Training & Exam in 2014
IRCA ISMS Lead Auditor Training & Exam in 2014
 
Henry James Study
Henry James StudyHenry James Study
Henry James Study
 
My Gap analysis results between ISO27001: 2022 and 2013 version as of 2022 fall.
My Gap analysis results between ISO27001: 2022 and 2013 version as of 2022 fall.My Gap analysis results between ISO27001: 2022 and 2013 version as of 2022 fall.
My Gap analysis results between ISO27001: 2022 and 2013 version as of 2022 fall.
 
ISO20000-1 Auditors note 【My Continuous Learning】
ISO20000-1 Auditors note 【My Continuous Learning】ISO20000-1 Auditors note 【My Continuous Learning】
ISO20000-1 Auditors note 【My Continuous Learning】
 
BCMS Audit Report【My Continuous Learning】
BCMS Audit  Report【My Continuous Learning】BCMS Audit  Report【My Continuous Learning】
BCMS Audit Report【My Continuous Learning】
 
SixSigma 【Continuous Study】
SixSigma 【Continuous Study】SixSigma 【Continuous Study】
SixSigma 【Continuous Study】
 
Use Cases for ISO20000-1 based on ITIL in English 【Continuous Study】
Use Cases for ISO20000-1 based on ITIL in English 【Continuous Study】Use Cases for ISO20000-1 based on ITIL in English 【Continuous Study】
Use Cases for ISO20000-1 based on ITIL in English 【Continuous Study】
 

Recently uploaded

1.Seydhcuxhxyxhccuuxuxyxyxmisolids 2019.pptx
1.Seydhcuxhxyxhccuuxuxyxyxmisolids 2019.pptx1.Seydhcuxhxyxhccuuxuxyxyxmisolids 2019.pptx
1.Seydhcuxhxyxhccuuxuxyxyxmisolids 2019.pptx
Tiktokethiodaily
 
一比一原版(BU毕业证)波士顿大学毕业证成绩单
一比一原版(BU毕业证)波士顿大学毕业证成绩单一比一原版(BU毕业证)波士顿大学毕业证成绩单
一比一原版(BU毕业证)波士顿大学毕业证成绩单
ewymefz
 
一比一原版(NYU毕业证)纽约大学毕业证成绩单
一比一原版(NYU毕业证)纽约大学毕业证成绩单一比一原版(NYU毕业证)纽约大学毕业证成绩单
一比一原版(NYU毕业证)纽约大学毕业证成绩单
ewymefz
 
Chatty Kathy - UNC Bootcamp Final Project Presentation - Final Version - 5.23...
Chatty Kathy - UNC Bootcamp Final Project Presentation - Final Version - 5.23...Chatty Kathy - UNC Bootcamp Final Project Presentation - Final Version - 5.23...
Chatty Kathy - UNC Bootcamp Final Project Presentation - Final Version - 5.23...
John Andrews
 
【社内勉強会資料_Octo: An Open-Source Generalist Robot Policy】
【社内勉強会資料_Octo: An Open-Source Generalist Robot Policy】【社内勉強会資料_Octo: An Open-Source Generalist Robot Policy】
【社内勉強会資料_Octo: An Open-Source Generalist Robot Policy】
NABLAS株式会社
 
一比一原版(CU毕业证)卡尔顿大学毕业证成绩单
一比一原版(CU毕业证)卡尔顿大学毕业证成绩单一比一原版(CU毕业证)卡尔顿大学毕业证成绩单
一比一原版(CU毕业证)卡尔顿大学毕业证成绩单
yhkoc
 
一比一原版(QU毕业证)皇后大学毕业证成绩单
一比一原版(QU毕业证)皇后大学毕业证成绩单一比一原版(QU毕业证)皇后大学毕业证成绩单
一比一原版(QU毕业证)皇后大学毕业证成绩单
enxupq
 
社内勉強会資料_LLM Agents                              .
社内勉強会資料_LLM Agents                              .社内勉強会資料_LLM Agents                              .
社内勉強会資料_LLM Agents                              .
NABLAS株式会社
 
SOCRadar Germany 2024 Threat Landscape Report
SOCRadar Germany 2024 Threat Landscape ReportSOCRadar Germany 2024 Threat Landscape Report
SOCRadar Germany 2024 Threat Landscape Report
SOCRadar
 
Jpolillo Amazon PPC - Bid Optimization Sample
Jpolillo Amazon PPC - Bid Optimization SampleJpolillo Amazon PPC - Bid Optimization Sample
Jpolillo Amazon PPC - Bid Optimization Sample
James Polillo
 
Business update Q1 2024 Lar España Real Estate SOCIMI
Business update Q1 2024 Lar España Real Estate SOCIMIBusiness update Q1 2024 Lar España Real Estate SOCIMI
Business update Q1 2024 Lar España Real Estate SOCIMI
AlejandraGmez176757
 
tapal brand analysis PPT slide for comptetive data
tapal brand analysis PPT slide for comptetive datatapal brand analysis PPT slide for comptetive data
tapal brand analysis PPT slide for comptetive data
theahmadsaood
 
Algorithmic optimizations for Dynamic Levelwise PageRank (from STICD) : SHORT...
Algorithmic optimizations for Dynamic Levelwise PageRank (from STICD) : SHORT...Algorithmic optimizations for Dynamic Levelwise PageRank (from STICD) : SHORT...
Algorithmic optimizations for Dynamic Levelwise PageRank (from STICD) : SHORT...
Subhajit Sahu
 
Criminal IP - Threat Hunting Webinar.pdf
Criminal IP - Threat Hunting Webinar.pdfCriminal IP - Threat Hunting Webinar.pdf
Criminal IP - Threat Hunting Webinar.pdf
Criminal IP
 
Best best suvichar in gujarati english meaning of this sentence as Silk road ...
Best best suvichar in gujarati english meaning of this sentence as Silk road ...Best best suvichar in gujarati english meaning of this sentence as Silk road ...
Best best suvichar in gujarati english meaning of this sentence as Silk road ...
AbhimanyuSinha9
 
一比一原版(UVic毕业证)维多利亚大学毕业证成绩单
一比一原版(UVic毕业证)维多利亚大学毕业证成绩单一比一原版(UVic毕业证)维多利亚大学毕业证成绩单
一比一原版(UVic毕业证)维多利亚大学毕业证成绩单
ukgaet
 
Adjusting primitives for graph : SHORT REPORT / NOTES
Adjusting primitives for graph : SHORT REPORT / NOTESAdjusting primitives for graph : SHORT REPORT / NOTES
Adjusting primitives for graph : SHORT REPORT / NOTES
Subhajit Sahu
 
一比一原版(CBU毕业证)卡普顿大学毕业证成绩单
一比一原版(CBU毕业证)卡普顿大学毕业证成绩单一比一原版(CBU毕业证)卡普顿大学毕业证成绩单
一比一原版(CBU毕业证)卡普顿大学毕业证成绩单
nscud
 
Investigate & Recover / StarCompliance.io / Crypto_Crimes
Investigate & Recover / StarCompliance.io / Crypto_CrimesInvestigate & Recover / StarCompliance.io / Crypto_Crimes
Investigate & Recover / StarCompliance.io / Crypto_Crimes
StarCompliance.io
 
一比一原版(TWU毕业证)西三一大学毕业证成绩单
一比一原版(TWU毕业证)西三一大学毕业证成绩单一比一原版(TWU毕业证)西三一大学毕业证成绩单
一比一原版(TWU毕业证)西三一大学毕业证成绩单
ocavb
 

Recently uploaded (20)

1.Seydhcuxhxyxhccuuxuxyxyxmisolids 2019.pptx
1.Seydhcuxhxyxhccuuxuxyxyxmisolids 2019.pptx1.Seydhcuxhxyxhccuuxuxyxyxmisolids 2019.pptx
1.Seydhcuxhxyxhccuuxuxyxyxmisolids 2019.pptx
 
一比一原版(BU毕业证)波士顿大学毕业证成绩单
一比一原版(BU毕业证)波士顿大学毕业证成绩单一比一原版(BU毕业证)波士顿大学毕业证成绩单
一比一原版(BU毕业证)波士顿大学毕业证成绩单
 
一比一原版(NYU毕业证)纽约大学毕业证成绩单
一比一原版(NYU毕业证)纽约大学毕业证成绩单一比一原版(NYU毕业证)纽约大学毕业证成绩单
一比一原版(NYU毕业证)纽约大学毕业证成绩单
 
Chatty Kathy - UNC Bootcamp Final Project Presentation - Final Version - 5.23...
Chatty Kathy - UNC Bootcamp Final Project Presentation - Final Version - 5.23...Chatty Kathy - UNC Bootcamp Final Project Presentation - Final Version - 5.23...
Chatty Kathy - UNC Bootcamp Final Project Presentation - Final Version - 5.23...
 
【社内勉強会資料_Octo: An Open-Source Generalist Robot Policy】
【社内勉強会資料_Octo: An Open-Source Generalist Robot Policy】【社内勉強会資料_Octo: An Open-Source Generalist Robot Policy】
【社内勉強会資料_Octo: An Open-Source Generalist Robot Policy】
 
一比一原版(CU毕业证)卡尔顿大学毕业证成绩单
一比一原版(CU毕业证)卡尔顿大学毕业证成绩单一比一原版(CU毕业证)卡尔顿大学毕业证成绩单
一比一原版(CU毕业证)卡尔顿大学毕业证成绩单
 
一比一原版(QU毕业证)皇后大学毕业证成绩单
一比一原版(QU毕业证)皇后大学毕业证成绩单一比一原版(QU毕业证)皇后大学毕业证成绩单
一比一原版(QU毕业证)皇后大学毕业证成绩单
 
社内勉強会資料_LLM Agents                              .
社内勉強会資料_LLM Agents                              .社内勉強会資料_LLM Agents                              .
社内勉強会資料_LLM Agents                              .
 
SOCRadar Germany 2024 Threat Landscape Report
SOCRadar Germany 2024 Threat Landscape ReportSOCRadar Germany 2024 Threat Landscape Report
SOCRadar Germany 2024 Threat Landscape Report
 
Jpolillo Amazon PPC - Bid Optimization Sample
Jpolillo Amazon PPC - Bid Optimization SampleJpolillo Amazon PPC - Bid Optimization Sample
Jpolillo Amazon PPC - Bid Optimization Sample
 
Business update Q1 2024 Lar España Real Estate SOCIMI
Business update Q1 2024 Lar España Real Estate SOCIMIBusiness update Q1 2024 Lar España Real Estate SOCIMI
Business update Q1 2024 Lar España Real Estate SOCIMI
 
tapal brand analysis PPT slide for comptetive data
tapal brand analysis PPT slide for comptetive datatapal brand analysis PPT slide for comptetive data
tapal brand analysis PPT slide for comptetive data
 
Algorithmic optimizations for Dynamic Levelwise PageRank (from STICD) : SHORT...
Algorithmic optimizations for Dynamic Levelwise PageRank (from STICD) : SHORT...Algorithmic optimizations for Dynamic Levelwise PageRank (from STICD) : SHORT...
Algorithmic optimizations for Dynamic Levelwise PageRank (from STICD) : SHORT...
 
Criminal IP - Threat Hunting Webinar.pdf
Criminal IP - Threat Hunting Webinar.pdfCriminal IP - Threat Hunting Webinar.pdf
Criminal IP - Threat Hunting Webinar.pdf
 
Best best suvichar in gujarati english meaning of this sentence as Silk road ...
Best best suvichar in gujarati english meaning of this sentence as Silk road ...Best best suvichar in gujarati english meaning of this sentence as Silk road ...
Best best suvichar in gujarati english meaning of this sentence as Silk road ...
 
一比一原版(UVic毕业证)维多利亚大学毕业证成绩单
一比一原版(UVic毕业证)维多利亚大学毕业证成绩单一比一原版(UVic毕业证)维多利亚大学毕业证成绩单
一比一原版(UVic毕业证)维多利亚大学毕业证成绩单
 
Adjusting primitives for graph : SHORT REPORT / NOTES
Adjusting primitives for graph : SHORT REPORT / NOTESAdjusting primitives for graph : SHORT REPORT / NOTES
Adjusting primitives for graph : SHORT REPORT / NOTES
 
一比一原版(CBU毕业证)卡普顿大学毕业证成绩单
一比一原版(CBU毕业证)卡普顿大学毕业证成绩单一比一原版(CBU毕业证)卡普顿大学毕业证成绩单
一比一原版(CBU毕业证)卡普顿大学毕业证成绩单
 
Investigate & Recover / StarCompliance.io / Crypto_Crimes
Investigate & Recover / StarCompliance.io / Crypto_CrimesInvestigate & Recover / StarCompliance.io / Crypto_Crimes
Investigate & Recover / StarCompliance.io / Crypto_Crimes
 
一比一原版(TWU毕业证)西三一大学毕业证成绩单
一比一原版(TWU毕业证)西三一大学毕业证成绩单一比一原版(TWU毕业证)西三一大学毕业证成绩单
一比一原版(TWU毕业证)西三一大学毕业证成绩单
 

Business Impact Analysis 【My Continuous Learning】

  • 1. ISO27002: 2022 Information security, cybersecurity and privacy protection — Information security controls Requirement Number 5.30 Ensure the Availability of the organization including 3rd party vendor which is connected to our information assets during disruption. In aspect of that, Conducting BIA (Business Impact Analysis) would be important. BIA (Business Impact Analysis) Date of BIA 2020/MAR/3 Date of BIA 2020/MAR/2 Date of BIA 2020/MAR/2 Location Tokyo, JAPAN Location India Location Hong Kong Date of Review 2020/JUN/3 13:00 (JST) Date of Review 2020/JUN/3 9:30 (IndiaTime) Date of Review 2020/JUN/3 12:00 (HK Time) Data Onwer (Info Owner) Name Sato, Jason Applicateion Owner Name Newf, Swere Risk Owner Name Marry, Jane Department IT Risk department Department xxx Application department Department xxx Application department Role BCP Manager Role Project Manager Role Project Manager BIA Version RA-BIA-v3
  • 2. Activities and scenarios reviewed Risk Reviewed Function responsible Activity importance Max time to restart Time to normal service Comment Critical service App team Vital 1 24 Failier of system necessary Critical service desired Failier of system necessary Critical service Critial BIA per scenario Impact over time #1 Critical service High Medium Low 1hour 2hour 12hour 24 hour Comment Impact of disruption x H H H H Sales Staff × M H H H Operation Staff × L H H H Procurement staff × L H H H Support team × L H H H Infosec team × L H H H Financial × L H H H Service level × L H H H Customers × H H H H
  • 3. BIA Summary Activity reviewed #1 Function owned by Activity importance Risk treatment Recovery Sequence Max time to restart (hours) Time to normal service level Comment Shift deployeing planning Critical Acceptance 1 72 7 review of service in schedule Critical Acceptance 2 Critical Business Continuity 3 Critical Business Continuity 4 Activity reviewed #2 Function owned by Activity importance Risk treatment Recovery Sequence Max time to restart (hours) Time to normal service level Comment Shift deployeing planning Critical Acceptance 1 72 7 review of service in schedule 2 Business Continuity 3 Business Continuity 4
  • 4. Activity name #1 Activity frequency more than hourly activity owner title Date of operation every day Number of FTEs involved hours of operation 8 hours Daily peak details weekly peak details Monthly peak details Annual peak details Activity name #2 Activity frequency more than hourly activity owner title Date of operation every day Number of FTEs involved hours of operation 8 hours Daily peak details weekly peak details Monthly peak details Annual peak details
  • 5. Dependencies a) Internal Independencies of Activity b) External Interdependencies of Activity Internal Independencies External Independencies Owner Owner Internal Independencies External Independencies Owner Owner Internal Independencies External Independencies Owner Owner Internal Independencies External Independencies Owner Owner People Impact Day1 Day2 Day3 Day4 Day8 Day15 1 month Comments Customer Staff Security Operation Customer service IT Business Impact Day1 Day2 Day3 Day4 Day8 Day15 1 month Comments Financial Service Levels Contractual agreements Reputation Helth and Safety
  • 6. Resources required to restart activity and reach normal service level Headcount Restart Normal Skill as restart knowledge IT Importance of activity Agreed level of importance of activity of key business services and objectives. Critical Completed by Positions Date Signature Senior Management agreement that the fundings detailed above are a true reflection of the organization Completed by Positions Date Signature Sooma, Jerimi Senor VP 2021/JUL/3 CEO 2021/JUL/3 Mwema, Adsf Impact - Business Function Information How long can the activity operate in manual mode? Are there any written processes/ procedures for operation in manual mode? When were the processes / procedures for operating in manual mode last updated? What additioanl respurces are required for operating in manual mode? In the event of a disruption there will be lost data / transactions. Can they be recovered? How will lost data be recovered? Are there any written processes / procefures for recovering lost data? When were the processes / procedures for recovering list data last updated? What would be the impact if the data cannot be recovered? Does the activity reply on information that is not electronic? (Specify data and media) How will lost (non electronic) information be recovered? What specialised equipment is required to perform the activity? CIO