ISC2 Certified in Cybersecurity (CC)Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) ConceptsMedium
During a Business Impact Analysis (BIA), a cybersecurity analyst is tasked with identifying the financial and operational consequences of a disruption to the organization's critical e-commerce platform. Which of the following is a primary objective of this phase of the BIA?
- ATo determine the Recovery Time Objective (RTO) for all IT systems.
- BTo quantify the impact of disruptions and prioritize business functions.
- CTo select appropriate disaster recovery vendors and solutions.
- DTo develop detailed incident response procedures for cyberattacks.
Show answer & explanationAnswer & explanation
Correct answer: B. To quantify the impact of disruptions and prioritize business functions.
A primary objective of the BIA is to quantify the potential financial and operational impacts of disruptions and then use this information to prioritize critical business functions for recovery planning.
Why the other options are wrong
- A. RTOs are derived from the BIA's findings, but determining them for ALL systems isn't the BIA's sole primary objective.
- C. Vendor selection occurs after requirements are defined, which the BIA helps inform, but it's not a primary BIA objective.
- D. Developing incident response procedures is part of incident response planning, not the BIA's primary objective.
Business Impact Analysis (BIA)
A systematic process to determine and evaluate the potential effects of an interruption to critical business operations as a result of a disaster, accident, or emergency.
- Identifies critical business functions and processes.
- Quantifies the impact of disruptions (financial, operational, reputational).
- Helps determine RTOs and RPOs.
Memory trick: BIA: Business's Impact Assessed, Always.