CompTIA SecurityX (CAS-005)Governance, Risk and ComplianceEasy

A security architect is performing a business impact analysis (BIA) for a critical e-commerce platform. During this process, they identify that a prolonged outage of the platform would result in significant reputational damage, customer churn, and potential regulatory fines, in addition to direct revenue loss. Which component of the BIA does this identification of indirect and non-financial losses primarily fall under?

  1. ARecovery Point Objective (RPO)
  2. BMaximum Tolerable Downtime (MTD)
  3. CRecovery Time Objective (RTO)
  4. DImpact Analysis
Show answer & explanation

Correct answer: D. Impact Analysis

Impact Analysis is a core component of the BIA where the potential effects of an interruption to business operations are identified and quantified (both financial and non-financial, direct and indirect). Reputational damage, customer churn, and regulatory fines are all types of impacts identified during this phase.

Why the other options are wrong

  • A. Recovery Point Objective (RPO) defines the maximum acceptable data loss in a disaster.
  • B. Maximum Tolerable Downtime (MTD) is the maximum period of time an organization can afford to have a system or function unavailable.
  • C. Recovery Time Objective (RTO) is the maximum acceptable delay from the point of interruption to restoration of service.

BIA Impact Analysis

The phase of a Business Impact Analysis (BIA) that identifies and quantifies the consequences of business disruptions.

  • Considers financial and non-financial impacts.
  • Includes direct and indirect losses.
  • Helps prioritize recovery efforts based on severity of impact.

Memory trick: Impact tells you 'how bad', RTO/RPO 'how fast'.

More Governance, Risk and Compliance questions