• Log In
  • Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

Protection of Information Assets

Temple University

Protection of Information Assets

MIS 5206.001 ■ Fall 2021 ■ David Lanter
  • HomePage
  • Instructor
  • Syllabus
  • Schedule
    • First Half of the Semester
      • Unit #1: Understanding an Organization’s Risk Environment
      • Unit #2: Case Study 1 – Snowfall and stolen laptop
      • Unit #2: Data Classification Process and Models
      • Unit #3: Risk Evaluation
      • Unit #4 Case #2: Autopsy of a Data Breach: The Target Case
      • Unit #5: Creating a Security Aware Organization
      • Unit #6: Physical and Environmental Security
    • Second Half of the Semester
      • Unit #8 Case Study 3 – A Hospital Catches the “Millennium Bug”
      • Unit #9: Business Continuity and Disaster Recovery Planning
      • Unit #10: Network Security
      • Unit #11: Cryptography, Public Key Encryption and Digital Signatures
      • Unit #12: Identity Management and Access Control
      • Unit #13: Computer Application Security
  • Deliverables
    • Weekly Deliverables
      • “In the News” Articles
      • Answers to Reading Discussion Questions
      • Comments on Reading Discussion Question and Other Students’ Answers
    • Case Studies
    • Team Project
  • Class Capture Videos
  • Gradebook

Question 3

October 14, 2021 by David Lanter 7 Comments

What is the relationship between business impact analysis, a disaster recovery plan and business continuity management?

Filed Under: Unit 09: Business Continuity and Disaster Recovery Tagged With:

Reader Interactions

Comments

  1. Shubham Patil says

    October 16, 2021 at 9:53 pm

    BIA and DRP are two important aspects for creating a Business Continuity Plan. BIA is carried out before DRP as it identifies and helps understand the critical business processes. While disaster recovery refers to the way data, servers, files, software applications, and operating systems are restored following a damaging event. In contrast, business continuity refers to the way a business maintains operations during a time of technological malfunction or outage. In other words, Business impact analysis identifies critical aspects in the infrastructure so that the disaster or data recovery plan dictates how a business should respond to a disaster and how they can safeguard and re-create that infrastructure while a business continuity plan dictates how a business can continue to operate throughout a disaster. BCP is amalgamation of both the strategies.

    Log in to Reply
    • Elizabeth Gutierrez says

      October 18, 2021 at 6:54 pm

      Hi Shubham,

      I agree with your description on how business impact analysis, a disaster recovery plan and business continuity management are interconnected. An observation that I could interesting was how certain events can force organizations to review their disaster recovery plans, especially with the evolution of new technology. For example, in the wake of September 11, 2001, as organizations began to build through the process of responding, reconstructing, restoring and recovering, they realized that classic recovery planning that focused on how to restore centralized data centers was far from adequate for contemporary businesses. Due to national security concerns, at the national level, the Presidential Policy Directive 21, Critical Infrastructure Security, and Resilience, established policy and organized public and private sectors into 16 critical infrastructures which we have previously discussed in class.

      Log in to Reply
  2. Elizabeth Gutierrez says

    October 16, 2021 at 10:46 pm

    After reviewing the content within our readings of the week, I definitely can see how business impact analysis (BIA), disaster recovery plans (DRP), and business continuity management overlap. To begin, a BIA sets the foundation for an effective business continuity plan and prepares an organization for the effort needed to recover from a business disruption. On the other hand, a business continuity plan (BCP) outlines the steps that must be taken in the event of an outage or disruption. In other words, a BIA informs a business’ continuity plan and when both are in place, it enables an organization to minimize downtime and ensure workforce productivity in case an unforeseen event occurs. Similarly, our readings describe BIA data as the building blocks of disaster discovery plans. Vacca Chapter 37 mentions, “A good DRP, utilizing the BIA, will identify critical assets, processes, and functions and recommend a course of action to preserve the business’s viability even during catastrophic events.” As for business continuity and disaster recovery planning, they differ in terms of when the plan takes effect. For example, business continuity requires you to keep operations functional during the event and immediately after while disaster recovery focuses on how you respond after the event has completed and how you return to normal. There is a relationship between the two because disaster recovery is driven by business continuity requirements and is an integral part of a business continuity management.

    Log in to Reply
    • Yangyuan Lin says

      October 20, 2021 at 1:45 pm

      Hi Elizabet,

      I like your explanation. I would say that BCP must include a comprehensive written plan to maintain or resume business operations in the event of natural or cyber security incidents. BCP focuses on implementing risk management strategies in the IT department and elsewhere, setting clear goals and standards for measuring success. BCP should adopt alternative solutions to ensure that customer service is maintained and data continues to be protected even in the event of a catastrophic event. And, a disaster recovery plan (DRP) can help an organization transition from alternate business process backups to normal processes.

      Log in to Reply
  3. Oluwaseun Soyomokun says

    October 19, 2021 at 12:15 pm

    The Business Continuity Management (BCM) describes what steps must be taken or developed to help assure the organization’s ability to maintain, resume, and recover the business in case of an outage or disruptions.
    It is not just about recovering information technology capabilities
    • Planning focuses on the entire enterprise’s mission critical infrastructure
    1. People
    2. Processes
    3. Technology

    Relationship between business impact analysis helps identify and prioritize information systems and components critical to supporting the organization’s mission/business processes. Disaster recovery plan provides procedures for relocating critical information systems operations to an alternative location after a significant disruption caused by a natural or human-induced disaster.

    A thorough business impact analysis (BIA) and risk assessment identifies the risk that could prompt the outage as well as the critical business functions and effective business continuity plan and prepares an organization for the inevitable effort required to recover from a business disruption. BCPs not only focus on technical operations (hardware/software issues) but also take into account the personnel and other resources associated with business continuity.

    • Business Continuity Plan effectiveness must be swift to respond to new risk and challenges if put in place and must be validated periodically, reviewed and updated annually through testing and practical application

    Log in to Reply
    • Shubham Patil says

      October 19, 2021 at 12:27 pm

      Oluwaseun,

      A DRP is a response to a particular event, and therefore, a tactical process, whereas business continuity plans or business recovery plans are strategic: they address repair to a damaged facility, disruption in the supply chain, and the flow of goods and services to customers, The true value of the BIA is the unbiased look at process, loss, and cost

      Log in to Reply
  4. Yangyuan Lin says

    October 20, 2021 at 1:41 pm

    The business continuity plan (BCP) is designed to ensure that key business functions can continue to work with minimal downtime in the event of an interruption, while the disaster recovery plan (DRP) considers how to restore business processes within a certain period of time in the event of a disaster. A BCP most often starts with a business impact analysis (BIA determines the scope of the plan); determines legal, contractual, and regulatory obligations; and provides a basis for planning and justifying the cost of the BCP. A BIA is often connected in series for risk assessment. It also considers the impact that a disaster may have on your business if it hits your service provider.

    Log in to Reply

Leave a Reply Cancel reply

You must be logged in to post a comment.

Primary Sidebar

Weekly Discussions

  • Unit 01: Understanding an Organization's Risk Environment (5)
  • Unit 02: Case Study 1 – Snowfall and a stolen laptop (6)
  • Unit 02: Data Classification Process and Models (6)
  • Unit 03: Risk Evaluation (6)
  • Unit 04: Case Study 2 – Autopsy of a Data Breach – The Target Case (4)
  • Unit 05: Creating a Security Aware Organization (6)
  • Unit 06: Physical and Environmental Security (6)
  • Unit 08: Case Study 3 – A Hospital Catches the "Millennium Bug" (6)
  • Unit 09: Business Continuity and Disaster Recovery (6)
  • Unit 10: Network Security (6)
  • Unit 11: Cryptography, Public Key Encryption and Digital Signature (6)
  • Unit 12: Identity Management and Access Control (6)
  • Unit 13: Computer Application Security (6)
  • Welcome (1)

Copyright © 2025 · Course News Pro on Genesis Framework · WordPress · Log in