SlideShare a Scribd company logo
1 of 18
PECB Webinar
2015-09-30
© 2015
Dr. Wolfgang H. Mahr, M.Sc., BBA, MBCI,
CISA
governance & continuuuity gmbh
CH-8408 Winterthur, Switzerland
www.continuuuity.ch
LinkedIn, XING, Twitter, YouTube
wolfgang.mahr@continuuuity.ch
Page1
PECB Webinar
2015-09-30
© 2015 Page2
 Why a BIA?
 Publication Status
 BIA in the BCM Life Cycle
 BIA in the BCMS Life Cycle
 Outcomes of the BIA
 BIA supporting BCM Goals
 BIA Critical Success Factors
 Challenges when doing a BIA
 ISO/TS 22317 on BIA
 Context of ISO/TS 22317
 BIA Life Cycle
 BIA Process
PECB Webinar
2015-09-30
© 2015 Page3
 BCM is a cyclic process
 BCM is based on continuous improvement
 BIA makes you know your processes better
 BIA is the base for the subsequent development of
one or more Business Continuity Strategies
 …
PECB Webinar
2015-09-30
© 2015 Page4
PECB Webinar
2015-09-30
© 2015
BIA in the BCM Life Cycle
Reference: The Business Continuity Institute
Page5
PECB Webinar
2015-09-30
© 2015
BIA in the BCMS Life Cycle
Reference: ISO 22301:2012
Page6
PECB Webinar
2015-09-30
© 2015
 Major outcomes include:
◦ Validation of the organisation’s BC programme scope
◦ Identification of requirements the organisation
◦ Determination of impacts, over time (of disruptions)
◦ Identification of relationships between
 Products/services
 Processes
 Activities
 Resources
◦ Resources needed to perform prioritised activities
 Such as facilities, people, assets, supplies, financial resources
◦ Dependencies and interrelationships
◦ …
Page7
PECB Webinar
2015-09-30
© 2015
 Protecting company value and reputation
 Safeguards the reputation and future of the
company in an emergency
 Increase shareholder value and
demonstrates commitment by management
 Assures the survival of the company in the
case of a serious incident
 Minimize financial losses in case of an
incident or emergency
BIA supporting BCM Goals
Page8
PECB Webinar
2015-09-30
© 2015
BIA Critical Success Factors
Page9
 Follow best practices such as
◦ BCI’s Good Practice Guidelines and/or
◦ ISO Standards such a ISO 22301, ISO 22313 and ISO/TS 22317
 Obtain top management commitment
 Apply project management methodologies
 Follow a BIA approach fit for the selected type of BIA
 Use an approach compatible with the company’s structure
 Deploy tools helping to obtain a “true and fair” representation of
products, services, priorities, dependencies and requirements
 Develop a hierarchical view on complex situations
 Use electronic representation, communication and archiving
PECB Webinar
2015-09-30
© 2015
 Commitment
 Level of effort
 “Right” effort
 Correctness /Completeness
 No excessive overlap / no white spots
Challenges when doing a BIA
Page10
PECB Webinar
2015-09-30
© 2015
 Developed by ISO TC292 (“Security and Resilience”), work started in ISO
TC223
 Published on 2015-09-17
 Based on ISO 22301, ISO 22313 and ISO 22300
 Focus on Performing the BIA:
◦ Project Planning and Management
◦ Product and Service Prioritisation
◦ Process Prioritisation
◦ Activity Prioritisation
◦ Analysis and Consolidation
◦ Top Management Endorsement of BIA Results
 Annexes on
◦ Terminology Mapping
◦ Information Collection Methods
ISO/TS 22317 on BIA
Page11
PECB Webinar
2015-09-30
© 2015
Context of ISO/TS 22317
Page12
ISO/TS 22317 (BIA Guidance)
ISO 22313 (BCMS Guidance)
ISO 22301(BCMS Specification)
PECB Webinar
2015-09-30
© 2015
BIA Life Cycle
Page13
 4 Prerequisites
 5.3 Product and Service Prioritization
 5.4 Process Prioritization
 5.5 Activity Prioritization
 5.6 Analysis & Consolidation
 5.7 Top Management Endorsement
 5.8 Proceed to BC Strategy
PECB Webinar
2015-09-30
© 2015
BIA Life Cycle Summary
Page14
PECB Webinar
2015-09-30
© 2015
BIA Process 1
Page15
 5.2 Based on Project Planning and Management
Stakeholders:
 5.3 Top Management: Product and Service Prioritization
 5.4 Process Owners: Process Prioritization
 5.5 Activity Managers: Activity Prioritization
PECB Webinar
2015-09-30
© 2015
BIA Process 2
Page16
 5.6 Analysis and Consolidation 
 5.7 Obtain Top Management Endorsement of BIA Results 
 5.8 After the BIA: Business Continuity Strategy Selection 
PECB Webinar
2015-09-30
© 2015
BIA Process Summary
Page17
PECB Webinar
2015-09-30
© 2015
Thank you
Page18

More Related Content

What's hot

Business Continuity Management
Business Continuity ManagementBusiness Continuity Management
Business Continuity Management
ECC International
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
PECB
 

What's hot (20)

Project plan for ISO 27001
Project plan for ISO 27001Project plan for ISO 27001
Project plan for ISO 27001
 
Business continuity management www.reconglobal.in
Business continuity management   www.reconglobal.inBusiness continuity management   www.reconglobal.in
Business continuity management www.reconglobal.in
 
Isaca crisc-courseware
Isaca crisc-coursewareIsaca crisc-courseware
Isaca crisc-courseware
 
27001 awareness Training
27001 awareness Training27001 awareness Training
27001 awareness Training
 
BCP Awareness
BCP Awareness BCP Awareness
BCP Awareness
 
Business Continuity - Business Risk & Management
Business Continuity - Business Risk & ManagementBusiness Continuity - Business Risk & Management
Business Continuity - Business Risk & Management
 
CRISC Course Preview
CRISC Course PreviewCRISC Course Preview
CRISC Course Preview
 
Improve Cybersecurity posture by using ISO/IEC 27032
Improve Cybersecurity posture by using ISO/IEC 27032Improve Cybersecurity posture by using ISO/IEC 27032
Improve Cybersecurity posture by using ISO/IEC 27032
 
How can the ISO 27701 help to design, implement, operate and improve a privac...
How can the ISO 27701 help to design, implement, operate and improve a privac...How can the ISO 27701 help to design, implement, operate and improve a privac...
How can the ISO 27701 help to design, implement, operate and improve a privac...
 
ISO 22301:2019 BCMS Awareness
ISO 22301:2019 BCMS AwarenessISO 22301:2019 BCMS Awareness
ISO 22301:2019 BCMS Awareness
 
CMMC, ISO/IEC 27701, and ISO/IEC 27001 — Best Practices and Differences
CMMC, ISO/IEC 27701, and ISO/IEC 27001 — Best Practices and DifferencesCMMC, ISO/IEC 27701, and ISO/IEC 27001 — Best Practices and Differences
CMMC, ISO/IEC 27701, and ISO/IEC 27001 — Best Practices and Differences
 
Business Continuity Workshop Final
Business Continuity Workshop   FinalBusiness Continuity Workshop   Final
Business Continuity Workshop Final
 
Assess Your Business Continuity Management Process
Assess Your Business Continuity Management ProcessAssess Your Business Continuity Management Process
Assess Your Business Continuity Management Process
 
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain timesPECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
PECB Webinar: ISO 31000 - The Benchmark for Risk Management in uncertain times
 
Business impact analysis
Business impact analysis Business impact analysis
Business impact analysis
 
BCM vs ERM: The Business Case for Integration..
BCM vs ERM: The Business Case for Integration..BCM vs ERM: The Business Case for Integration..
BCM vs ERM: The Business Case for Integration..
 
Business Continuity Management
Business Continuity ManagementBusiness Continuity Management
Business Continuity Management
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
 
Cyber Crisis Management - Kloudlearn
Cyber Crisis Management - KloudlearnCyber Crisis Management - Kloudlearn
Cyber Crisis Management - Kloudlearn
 
What is business continuity planning-bcp
What is business continuity planning-bcpWhat is business continuity planning-bcp
What is business continuity planning-bcp
 

Viewers also liked

02 Practical Strategies of Conducting BIA
02 Practical Strategies of Conducting BIA02 Practical Strategies of Conducting BIA
02 Practical Strategies of Conducting BIA
BCM Institute
 
Bbp change impact analysis sample_2009_v07
Bbp change impact analysis sample_2009_v07Bbp change impact analysis sample_2009_v07
Bbp change impact analysis sample_2009_v07
Muhammad_Abdelgawad
 
企业安全应急响应与渗透反击V0.04(程冲)
企业安全应急响应与渗透反击V0.04(程冲)企业安全应急响应与渗透反击V0.04(程冲)
企业安全应急响应与渗透反击V0.04(程冲)
WASecurity
 
Antal International Global Solutions
Antal International   Global SolutionsAntal International   Global Solutions
Antal International Global Solutions
Anshumangoel
 

Viewers also liked (19)

Building a business impact analysis (bia) process a hands on blueprint
Building a business impact analysis (bia) process a hands on blueprintBuilding a business impact analysis (bia) process a hands on blueprint
Building a business impact analysis (bia) process a hands on blueprint
 
Business continuity - 5 key steps to effective business impact analysis
Business continuity - 5 key steps to effective business impact analysisBusiness continuity - 5 key steps to effective business impact analysis
Business continuity - 5 key steps to effective business impact analysis
 
BIA - Example of Business Impact Analysis and Dependencies
BIA - Example of Business Impact Analysis and DependenciesBIA - Example of Business Impact Analysis and Dependencies
BIA - Example of Business Impact Analysis and Dependencies
 
Impact Analysis Template - Enterprise
Impact Analysis Template - EnterpriseImpact Analysis Template - Enterprise
Impact Analysis Template - Enterprise
 
Business Impact Analysis - Clause 4 Of BS25999 In Practice
Business Impact Analysis - Clause 4 Of BS25999 In PracticeBusiness Impact Analysis - Clause 4 Of BS25999 In Practice
Business Impact Analysis - Clause 4 Of BS25999 In Practice
 
02 Practical Strategies of Conducting BIA
02 Practical Strategies of Conducting BIA02 Practical Strategies of Conducting BIA
02 Practical Strategies of Conducting BIA
 
Bbp change impact analysis sample_2009_v07
Bbp change impact analysis sample_2009_v07Bbp change impact analysis sample_2009_v07
Bbp change impact analysis sample_2009_v07
 
Scope or: How to Manage Projects for Organization Success
Scope or: How to Manage Projects for Organization SuccessScope or: How to Manage Projects for Organization Success
Scope or: How to Manage Projects for Organization Success
 
Business Continuity Management (BCM, BCP) Smaple (Animations don't work in Sl...
Business Continuity Management (BCM, BCP) Smaple (Animations don't work in Sl...Business Continuity Management (BCM, BCP) Smaple (Animations don't work in Sl...
Business Continuity Management (BCM, BCP) Smaple (Animations don't work in Sl...
 
PCI DSS V2.0
PCI DSS V2.0PCI DSS V2.0
PCI DSS V2.0
 
企业安全应急响应与渗透反击V0.04(程冲)
企业安全应急响应与渗透反击V0.04(程冲)企业安全应急响应与渗透反击V0.04(程冲)
企业安全应急响应与渗透反击V0.04(程冲)
 
Antal International Global Solutions
Antal International   Global SolutionsAntal International   Global Solutions
Antal International Global Solutions
 
ISO 22301 Lead Implementer - Four Page Brochure
ISO 22301 Lead Implementer - Four Page BrochureISO 22301 Lead Implementer - Four Page Brochure
ISO 22301 Lead Implementer - Four Page Brochure
 
How to conduct a financial impact analysis
How to conduct a financial impact analysisHow to conduct a financial impact analysis
How to conduct a financial impact analysis
 
Business Resilience
Business ResilienceBusiness Resilience
Business Resilience
 
Kristopher Lovegrove resume
Kristopher Lovegrove  resumeKristopher Lovegrove  resume
Kristopher Lovegrove resume
 
6. business-case-iso-39001
6. business-case-iso-390016. business-case-iso-39001
6. business-case-iso-39001
 
ISO 39001 Lead Auditor - One Page Brochure
ISO 39001 Lead Auditor - One Page BrochureISO 39001 Lead Auditor - One Page Brochure
ISO 39001 Lead Auditor - One Page Brochure
 
ISO 39001 Lead Auditor - Four Page Brochure
ISO 39001 Lead Auditor - Four Page Brochure	ISO 39001 Lead Auditor - Four Page Brochure
ISO 39001 Lead Auditor - Four Page Brochure
 

Similar to PECB Webinar: Introduction to ISO 22317 – Business Impact Analysis (BIA)

Webinar Critical Chain Project Management - Marris Consulting - June 2020
Webinar Critical Chain Project Management  - Marris Consulting - June 2020Webinar Critical Chain Project Management  - Marris Consulting - June 2020
Webinar Critical Chain Project Management - Marris Consulting - June 2020
MARRIS Consulting
 
ISO 9001 Presentation for management dan staff
ISO 9001 Presentation for management dan staffISO 9001 Presentation for management dan staff
ISO 9001 Presentation for management dan staff
RifqiSufra1
 
COBIT® Presentation Package.ppt
COBIT® Presentation Package.pptCOBIT® Presentation Package.ppt
COBIT® Presentation Package.ppt
Emmacuet
 

Similar to PECB Webinar: Introduction to ISO 22317 – Business Impact Analysis (BIA) (20)

PECB Webinar: ISO/TS 22318: A New ISO Technical Specification on Supply Chain...
PECB Webinar: ISO/TS 22318: A New ISO Technical Specification on Supply Chain...PECB Webinar: ISO/TS 22318: A New ISO Technical Specification on Supply Chain...
PECB Webinar: ISO/TS 22318: A New ISO Technical Specification on Supply Chain...
 
Business Continuity Audit
Business Continuity AuditBusiness Continuity Audit
Business Continuity Audit
 
bsi BIM solutions | Ecobuild 2016
bsi BIM solutions | Ecobuild 2016bsi BIM solutions | Ecobuild 2016
bsi BIM solutions | Ecobuild 2016
 
Acnl2015 brian teunissen 2015 scaled agile maturity model
Acnl2015 brian teunissen 2015 scaled agile maturity modelAcnl2015 brian teunissen 2015 scaled agile maturity model
Acnl2015 brian teunissen 2015 scaled agile maturity model
 
Webinar Critical Chain Project Management - Marris Consulting - June 2020
Webinar Critical Chain Project Management  - Marris Consulting - June 2020Webinar Critical Chain Project Management  - Marris Consulting - June 2020
Webinar Critical Chain Project Management - Marris Consulting - June 2020
 
Internal Audits and Assessments with help of Enterprise SPiCE
Internal Audits and Assessments with help of Enterprise SPiCEInternal Audits and Assessments with help of Enterprise SPiCE
Internal Audits and Assessments with help of Enterprise SPiCE
 
Best Practices #5: Your first application is in production! Now what?
Best Practices #5: Your first application is in production! Now what?Best Practices #5: Your first application is in production! Now what?
Best Practices #5: Your first application is in production! Now what?
 
FCB Partners Webinar: Process 2020: The Cutting Edge of Process Innovation
FCB Partners Webinar: Process 2020: The Cutting Edge of Process Innovation FCB Partners Webinar: Process 2020: The Cutting Edge of Process Innovation
FCB Partners Webinar: Process 2020: The Cutting Edge of Process Innovation
 
COBIT®5 - Foundation
COBIT®5 - FoundationCOBIT®5 - Foundation
COBIT®5 - Foundation
 
Looking Forward In 2009
Looking Forward In 2009Looking Forward In 2009
Looking Forward In 2009
 
ISO 9001 Presentation for management dan staff
ISO 9001 Presentation for management dan staffISO 9001 Presentation for management dan staff
ISO 9001 Presentation for management dan staff
 
BICC Overview
BICC OverviewBICC Overview
BICC Overview
 
BICC Conceptual Overview
BICC Conceptual OverviewBICC Conceptual Overview
BICC Conceptual Overview
 
Benefits of Integrating ISO and CMMI Service Management System Frameworks
Benefits of Integrating ISO and CMMI Service Management System FrameworksBenefits of Integrating ISO and CMMI Service Management System Frameworks
Benefits of Integrating ISO and CMMI Service Management System Frameworks
 
Cobit 5 foundation v1.0 training -Visio Learning
Cobit 5 foundation v1.0 training -Visio LearningCobit 5 foundation v1.0 training -Visio Learning
Cobit 5 foundation v1.0 training -Visio Learning
 
COBIT® Presentation Package.ppt
COBIT® Presentation Package.pptCOBIT® Presentation Package.ppt
COBIT® Presentation Package.ppt
 
ISO 22301 | Business Continuity Awareness
ISO 22301 | Business Continuity Awareness ISO 22301 | Business Continuity Awareness
ISO 22301 | Business Continuity Awareness
 
Preview: Getting started with EA - Key factors for implementing EA successful...
Preview: Getting started with EA - Key factors for implementing EA successful...Preview: Getting started with EA - Key factors for implementing EA successful...
Preview: Getting started with EA - Key factors for implementing EA successful...
 
Dr Goh Moh Heng Building Your Organization Business Continuity Management Com...
Dr Goh Moh Heng Building Your Organization Business Continuity Management Com...Dr Goh Moh Heng Building Your Organization Business Continuity Management Com...
Dr Goh Moh Heng Building Your Organization Business Continuity Management Com...
 
Process Excellence Week Europe 2015
Process Excellence Week Europe 2015 Process Excellence Week Europe 2015
Process Excellence Week Europe 2015
 

More from PECB

Beyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactBeyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global Impact
PECB
 
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityDORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
PECB
 
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernanceSecuring the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
PECB
 
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
PECB
 
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
PECB
 
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
PECB
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
PECB
 
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
PECB
 
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsManaging ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
PECB
 
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
PECB
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
PECB
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
PECB
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
PECB
 
IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?
PECB
 
Student Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxStudent Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptx
PECB
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023
PECB
 
ISO 28000:2022 – Reduce risks and improve the security management system
ISO 28000:2022 – Reduce risks and improve the security management systemISO 28000:2022 – Reduce risks and improve the security management system
ISO 28000:2022 – Reduce risks and improve the security management system
PECB
 

More from PECB (20)

Beyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactBeyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global Impact
 
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityDORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
 
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernanceSecuring the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
 
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
 
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
 
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
 
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
 
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsManaging ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
 
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
 
Student Information Session University KTMC
Student Information Session University KTMC Student Information Session University KTMC
Student Information Session University KTMC
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
 
Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA
 
IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?
 
Information Session University Egybyte.pptx
Information Session University Egybyte.pptxInformation Session University Egybyte.pptx
Information Session University Egybyte.pptx
 
Student Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxStudent Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptx
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023
 
ISO 28000:2022 – Reduce risks and improve the security management system
ISO 28000:2022 – Reduce risks and improve the security management systemISO 28000:2022 – Reduce risks and improve the security management system
ISO 28000:2022 – Reduce risks and improve the security management system
 

Recently uploaded

Spellings Wk 4 and Wk 5 for Grade 4 at CAPS
Spellings Wk 4 and Wk 5 for Grade 4 at CAPSSpellings Wk 4 and Wk 5 for Grade 4 at CAPS
Spellings Wk 4 and Wk 5 for Grade 4 at CAPS
AnaAcapella
 

Recently uploaded (20)

TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...
 
NO1 Top Black Magic Specialist In Lahore Black magic In Pakistan Kala Ilam Ex...
NO1 Top Black Magic Specialist In Lahore Black magic In Pakistan Kala Ilam Ex...NO1 Top Black Magic Specialist In Lahore Black magic In Pakistan Kala Ilam Ex...
NO1 Top Black Magic Specialist In Lahore Black magic In Pakistan Kala Ilam Ex...
 
Exploring_the_Narrative_Style_of_Amitav_Ghoshs_Gun_Island.pptx
Exploring_the_Narrative_Style_of_Amitav_Ghoshs_Gun_Island.pptxExploring_the_Narrative_Style_of_Amitav_Ghoshs_Gun_Island.pptx
Exploring_the_Narrative_Style_of_Amitav_Ghoshs_Gun_Island.pptx
 
How to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POSHow to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POS
 
Spellings Wk 4 and Wk 5 for Grade 4 at CAPS
Spellings Wk 4 and Wk 5 for Grade 4 at CAPSSpellings Wk 4 and Wk 5 for Grade 4 at CAPS
Spellings Wk 4 and Wk 5 for Grade 4 at CAPS
 
How to Manage Call for Tendor in Odoo 17
How to Manage Call for Tendor in Odoo 17How to Manage Call for Tendor in Odoo 17
How to Manage Call for Tendor in Odoo 17
 
How to Create and Manage Wizard in Odoo 17
How to Create and Manage Wizard in Odoo 17How to Create and Manage Wizard in Odoo 17
How to Create and Manage Wizard in Odoo 17
 
Unit 3 Emotional Intelligence and Spiritual Intelligence.pdf
Unit 3 Emotional Intelligence and Spiritual Intelligence.pdfUnit 3 Emotional Intelligence and Spiritual Intelligence.pdf
Unit 3 Emotional Intelligence and Spiritual Intelligence.pdf
 
On_Translating_a_Tamil_Poem_by_A_K_Ramanujan.pptx
On_Translating_a_Tamil_Poem_by_A_K_Ramanujan.pptxOn_Translating_a_Tamil_Poem_by_A_K_Ramanujan.pptx
On_Translating_a_Tamil_Poem_by_A_K_Ramanujan.pptx
 
HMCS Vancouver Pre-Deployment Brief - May 2024 (Web Version).pptx
HMCS Vancouver Pre-Deployment Brief - May 2024 (Web Version).pptxHMCS Vancouver Pre-Deployment Brief - May 2024 (Web Version).pptx
HMCS Vancouver Pre-Deployment Brief - May 2024 (Web Version).pptx
 
dusjagr & nano talk on open tools for agriculture research and learning
dusjagr & nano talk on open tools for agriculture research and learningdusjagr & nano talk on open tools for agriculture research and learning
dusjagr & nano talk on open tools for agriculture research and learning
 
How to Add a Tool Tip to a Field in Odoo 17
How to Add a Tool Tip to a Field in Odoo 17How to Add a Tool Tip to a Field in Odoo 17
How to Add a Tool Tip to a Field in Odoo 17
 
80 ĐỀ THI THỬ TUYỂN SINH TIẾNG ANH VÀO 10 SỞ GD – ĐT THÀNH PHỐ HỒ CHÍ MINH NĂ...
80 ĐỀ THI THỬ TUYỂN SINH TIẾNG ANH VÀO 10 SỞ GD – ĐT THÀNH PHỐ HỒ CHÍ MINH NĂ...80 ĐỀ THI THỬ TUYỂN SINH TIẾNG ANH VÀO 10 SỞ GD – ĐT THÀNH PHỐ HỒ CHÍ MINH NĂ...
80 ĐỀ THI THỬ TUYỂN SINH TIẾNG ANH VÀO 10 SỞ GD – ĐT THÀNH PHỐ HỒ CHÍ MINH NĂ...
 
Our Environment Class 10 Science Notes pdf
Our Environment Class 10 Science Notes pdfOur Environment Class 10 Science Notes pdf
Our Environment Class 10 Science Notes pdf
 
AIM of Education-Teachers Training-2024.ppt
AIM of Education-Teachers Training-2024.pptAIM of Education-Teachers Training-2024.ppt
AIM of Education-Teachers Training-2024.ppt
 
UGC NET Paper 1 Unit 7 DATA INTERPRETATION.pdf
UGC NET Paper 1 Unit 7 DATA INTERPRETATION.pdfUGC NET Paper 1 Unit 7 DATA INTERPRETATION.pdf
UGC NET Paper 1 Unit 7 DATA INTERPRETATION.pdf
 
Wellbeing inclusion and digital dystopias.pptx
Wellbeing inclusion and digital dystopias.pptxWellbeing inclusion and digital dystopias.pptx
Wellbeing inclusion and digital dystopias.pptx
 
Understanding Accommodations and Modifications
Understanding  Accommodations and ModificationsUnderstanding  Accommodations and Modifications
Understanding Accommodations and Modifications
 
REMIFENTANIL: An Ultra short acting opioid.pptx
REMIFENTANIL: An Ultra short acting opioid.pptxREMIFENTANIL: An Ultra short acting opioid.pptx
REMIFENTANIL: An Ultra short acting opioid.pptx
 
Towards a code of practice for AI in AT.pptx
Towards a code of practice for AI in AT.pptxTowards a code of practice for AI in AT.pptx
Towards a code of practice for AI in AT.pptx
 

PECB Webinar: Introduction to ISO 22317 – Business Impact Analysis (BIA)

  • 1. PECB Webinar 2015-09-30 © 2015 Dr. Wolfgang H. Mahr, M.Sc., BBA, MBCI, CISA governance & continuuuity gmbh CH-8408 Winterthur, Switzerland www.continuuuity.ch LinkedIn, XING, Twitter, YouTube wolfgang.mahr@continuuuity.ch Page1
  • 2. PECB Webinar 2015-09-30 © 2015 Page2  Why a BIA?  Publication Status  BIA in the BCM Life Cycle  BIA in the BCMS Life Cycle  Outcomes of the BIA  BIA supporting BCM Goals  BIA Critical Success Factors  Challenges when doing a BIA  ISO/TS 22317 on BIA  Context of ISO/TS 22317  BIA Life Cycle  BIA Process
  • 3. PECB Webinar 2015-09-30 © 2015 Page3  BCM is a cyclic process  BCM is based on continuous improvement  BIA makes you know your processes better  BIA is the base for the subsequent development of one or more Business Continuity Strategies  …
  • 5. PECB Webinar 2015-09-30 © 2015 BIA in the BCM Life Cycle Reference: The Business Continuity Institute Page5
  • 6. PECB Webinar 2015-09-30 © 2015 BIA in the BCMS Life Cycle Reference: ISO 22301:2012 Page6
  • 7. PECB Webinar 2015-09-30 © 2015  Major outcomes include: ◦ Validation of the organisation’s BC programme scope ◦ Identification of requirements the organisation ◦ Determination of impacts, over time (of disruptions) ◦ Identification of relationships between  Products/services  Processes  Activities  Resources ◦ Resources needed to perform prioritised activities  Such as facilities, people, assets, supplies, financial resources ◦ Dependencies and interrelationships ◦ … Page7
  • 8. PECB Webinar 2015-09-30 © 2015  Protecting company value and reputation  Safeguards the reputation and future of the company in an emergency  Increase shareholder value and demonstrates commitment by management  Assures the survival of the company in the case of a serious incident  Minimize financial losses in case of an incident or emergency BIA supporting BCM Goals Page8
  • 9. PECB Webinar 2015-09-30 © 2015 BIA Critical Success Factors Page9  Follow best practices such as ◦ BCI’s Good Practice Guidelines and/or ◦ ISO Standards such a ISO 22301, ISO 22313 and ISO/TS 22317  Obtain top management commitment  Apply project management methodologies  Follow a BIA approach fit for the selected type of BIA  Use an approach compatible with the company’s structure  Deploy tools helping to obtain a “true and fair” representation of products, services, priorities, dependencies and requirements  Develop a hierarchical view on complex situations  Use electronic representation, communication and archiving
  • 10. PECB Webinar 2015-09-30 © 2015  Commitment  Level of effort  “Right” effort  Correctness /Completeness  No excessive overlap / no white spots Challenges when doing a BIA Page10
  • 11. PECB Webinar 2015-09-30 © 2015  Developed by ISO TC292 (“Security and Resilience”), work started in ISO TC223  Published on 2015-09-17  Based on ISO 22301, ISO 22313 and ISO 22300  Focus on Performing the BIA: ◦ Project Planning and Management ◦ Product and Service Prioritisation ◦ Process Prioritisation ◦ Activity Prioritisation ◦ Analysis and Consolidation ◦ Top Management Endorsement of BIA Results  Annexes on ◦ Terminology Mapping ◦ Information Collection Methods ISO/TS 22317 on BIA Page11
  • 12. PECB Webinar 2015-09-30 © 2015 Context of ISO/TS 22317 Page12 ISO/TS 22317 (BIA Guidance) ISO 22313 (BCMS Guidance) ISO 22301(BCMS Specification)
  • 13. PECB Webinar 2015-09-30 © 2015 BIA Life Cycle Page13  4 Prerequisites  5.3 Product and Service Prioritization  5.4 Process Prioritization  5.5 Activity Prioritization  5.6 Analysis & Consolidation  5.7 Top Management Endorsement  5.8 Proceed to BC Strategy
  • 14. PECB Webinar 2015-09-30 © 2015 BIA Life Cycle Summary Page14
  • 15. PECB Webinar 2015-09-30 © 2015 BIA Process 1 Page15  5.2 Based on Project Planning and Management Stakeholders:  5.3 Top Management: Product and Service Prioritization  5.4 Process Owners: Process Prioritization  5.5 Activity Managers: Activity Prioritization
  • 16. PECB Webinar 2015-09-30 © 2015 BIA Process 2 Page16  5.6 Analysis and Consolidation   5.7 Obtain Top Management Endorsement of BIA Results   5.8 After the BIA: Business Continuity Strategy Selection 
  • 17. PECB Webinar 2015-09-30 © 2015 BIA Process Summary Page17