• Log In
  • Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

Protection of Information Assets

Temple University

Protection of Information Assets

MIS 5206.001 ■ Fall 2021 ■ David Lanter
  • HomePage
  • Instructor
  • Syllabus
  • Schedule
    • First Half of the Semester
      • Unit #1: Understanding an Organization’s Risk Environment
      • Unit #2: Case Study 1 – Snowfall and stolen laptop
      • Unit #2: Data Classification Process and Models
      • Unit #3: Risk Evaluation
      • Unit #4 Case #2: Autopsy of a Data Breach: The Target Case
      • Unit #5: Creating a Security Aware Organization
      • Unit #6: Physical and Environmental Security
    • Second Half of the Semester
      • Unit #8 Case Study 3 – A Hospital Catches the “Millennium Bug”
      • Unit #9: Business Continuity and Disaster Recovery Planning
      • Unit #10: Network Security
      • Unit #11: Cryptography, Public Key Encryption and Digital Signatures
      • Unit #12: Identity Management and Access Control
      • Unit #13: Computer Application Security
  • Deliverables
    • Weekly Deliverables
      • “In the News” Articles
      • Answers to Reading Discussion Questions
      • Comments on Reading Discussion Question and Other Students’ Answers
    • Case Studies
    • Team Project
  • Class Capture Videos
  • Gradebook

Question 2

October 14, 2021 by David Lanter 8 Comments

What is a business impact analysis?  Why is it needed?

Filed Under: Unit 09: Business Continuity and Disaster Recovery Tagged With:

Reader Interactions

Comments

  1. Shubham Patil says

    October 16, 2021 at 9:24 pm

    A business impact analysis is a solution that determines critical business processes based on their impact during a disruption. An organization must define resilience requirements, justify business continuity investments, and identify a robust risk mitigation strategy.

    It is needed because unplanned disruptions can be costly, resulting in major losses, customer dissatisfaction, and compliance issues. To counter such risks, developing an effective, end-to-end business resilience plan is a necessary component to business continuity and recovery solutions. An organization must have a thorough understanding of the critical business processes and the tolerance of a business outage to define objectives to succeed in the event of an outage. A successful solution employs a vertical and horizontal, or top-down approach to understand, identify, and map critical business processes, functions, IT systems, resource dependencies, and delivery channels.

    Log in to Reply
    • Elizabeth Gutierrez says

      October 18, 2021 at 5:22 pm

      Hi Shubham,

      I appreciate your inclusion of successful solutions and your mention of the approaches that could be used like vertical / horizontal and top-down. To expand more on how a BIA determines its critical business processes — it quantifies the impacts of disruptions on service delivery, risks to service delivery, as well as RTOs and RPOs. What I found interesting is that the true value of the BIA is the unbiased look at process, loss, and cost. So regardless if a tornado damages the office building, or the disaster is a result of fire or flood, the BIA provides a look at the loss of function irrespective of the cause.

      Log in to Reply
  2. Elizabeth Gutierrez says

    October 16, 2021 at 9:52 pm

    A business impact analysis also known as BIA is a process to identify critical business systems and predict and quantify the impact of a disruption. In the process, information is gathered to develop recovery strategies and limit the potential loss; potential loss scenarios are identified during a risk assessment. According to Vacca Chapter 37, Bia examines examines every division of the company and details the following key items: how long the organization can survive without critical assets, identify business functions then prioritize and identify which they are, vulnerability, specifically which business functions are susceptible to natural disasters, and estimated cost of loss for business functions over time. Since unplanned disruptions can be costly and the consequences could potentially include major losses, customer dissatisfaction, and compliance issues, an effective resilience plan is necessary for business continuity and recovery solutions.

    Log in to Reply
    • Shubham Patil says

      October 19, 2021 at 12:15 pm

      Elizabeth,

      You mentioned about how long the organization can survive without critical assets, identify business functions then prioritize and identify which they are. I would also like to add that the organizations must analyze the cost of disruptions and place them into resilience tiers to assist in defining operational availability and DR requirements from a business perspective.

      Log in to Reply
  3. Oluwaseun Soyomokun says

    October 19, 2021 at 12:09 pm

    A business impact analysis (BIA) is the process of determining the criticality of business activities and associated resource requirements to ensure operational resilience and continuity of operations during and after a business disruption.
    From John Vacca’s content – Business impact analysis must be performed in every organization to determine exactly which business process is deemed mission-critical and which processes would not seriously hamper business operations should they be unavailable for some time. An important part of a business impact analysis is the recovery strategy that is usually defined at the end of the process. If a thorough business impact analysis is performed, there should be a clear picture of the priority of each organization’s highest- impact, therefore risky, business processes and assets as well as a clear strategy to recover from an interruption in one of these areas.
    According to NIST’s “SP 800-34, Rev. 1,” the CPMT conducts the BIA in three stages listed as follow8:
    1. Determine mission/business processes and recovery criticality.
    2. Identify resource requirements.
    3. Identify recovery priorities for system resources

    Log in to Reply
    • Yangyuan Lin says

      October 19, 2021 at 9:40 pm

      Hi Oluwaseun,

      I like how you mention CPMT conducts BIA in three stages. The organization determines the mission/business process and the importance of recovery. The BIA checks the time the company can continue to operate in an emergency, determines resource requirements and ranks business functions according to their importance and their likelihood of being affected by natural disasters. After determining the priority, the enterprise can use the BIA to inform the tactical execution of the disaster recovery plan.

      Log in to Reply
  4. Yangyuan Lin says

    October 19, 2021 at 9:26 pm

    Business impact analysis (BIA) is a risk management process used to study and identify areas that may be affected by major disruptions. It collects useful information about possible problems and how to recover from difficult situations, and it also predicts any financial losses that may result from it.

    The purpose of performing a BIA is to obtain input from the business users of the application on the impact of a long-term application interruption (for example, in the event of a disaster) on the business to determine backup and recovery requirements. This promotes the engineering design of application disaster recovery mechanisms. Organizations can use it to discover, avoid, and mitigate risks. This is because such processes play a huge role in risk management and disaster planning and recovery.

    Log in to Reply
    • Oluwaseun Soyomokun says

      October 19, 2021 at 10:05 pm

      Yin,
      Business Impact Analysis is the right first step as part of disaster recovery and business continuity planning is about and rather than just guessing what might happen to an affected business by an unforeseen catastrophic impact of its IT operations if something fails or is disrupted, Business Impact Analysis is a formal process that looks to quantify the potential impact of a service disruption.

      Log in to Reply

Leave a Reply Cancel reply

You must be logged in to post a comment.

Primary Sidebar

Weekly Discussions

  • Unit 01: Understanding an Organization's Risk Environment (5)
  • Unit 02: Case Study 1 – Snowfall and a stolen laptop (6)
  • Unit 02: Data Classification Process and Models (6)
  • Unit 03: Risk Evaluation (6)
  • Unit 04: Case Study 2 – Autopsy of a Data Breach – The Target Case (4)
  • Unit 05: Creating a Security Aware Organization (6)
  • Unit 06: Physical and Environmental Security (6)
  • Unit 08: Case Study 3 – A Hospital Catches the "Millennium Bug" (6)
  • Unit 09: Business Continuity and Disaster Recovery (6)
  • Unit 10: Network Security (6)
  • Unit 11: Cryptography, Public Key Encryption and Digital Signature (6)
  • Unit 12: Identity Management and Access Control (6)
  • Unit 13: Computer Application Security (6)
  • Welcome (1)

Copyright © 2025 · Course News Pro on Genesis Framework · WordPress · Log in