BCR-02: Are criteria for developing business continuity and operational resiliency
strategies and capabilities established based on business disruption and risk
impacts?
The business impact analysis (BIA) should incorporate the following components: a. Identification of critical products and services with their inherent risks. b. The likelihood and impact of each risk. c. The organization's risk appetite and tolerance. d. The identification of risk dependencies. e. The identification of appropriate and relevant countermeasures to prevent, detect, and react to the identified risks.
The impact analysis should incorporate the following elements: f. The immediate and ongoing impacts resulting from disruptions. g. A recovery time objective (RTO) and recovery point objective (RPO). h. The estimated internal and external resources required for recovery and resumption.
Control implemented
Control ownership
Description
Determine the impact of business disruptions and risks to establish
criteria for developing business continuity and operational resilience strategies
and capabilities.