Business impact analysis
Which activities matter most, how quickly each must be recovered, what it depends on and what its loss costs over time.
How the register reads it
| Also called | BIA, recovery time objectives |
|---|---|
| Family | Resilience and incidents |
| Document type | Record. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted. |
| Folds into | The regimes accept it folded into the business continuity plan; when neither is listed, the gap is counted once, under the parent. |
| Expected owner | The business continuity manager or COO. |
| Review cadence | Annual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period). |
| On the gap list when | ISO 22301 is ticked and no line resolves to it or to its parent (DORA requires it too, inside a parent document, so it does not list it separately). |
| Template | Business impact analysis template. |
Which standards require it, and what each expects it to contain
2 requiring clauses, 2 regimesShown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.
ISO 22301:2019
ISO 22301 8.2.2 Business impact analysisUse the impact analysis process to set continuity priorities and requirements: define the impact types and criteria relevant to the organization's context, identify the activities supporting delivery of products and services, assess impacts over time from disrupting those activities, fix the point at which non resumption becomes unacceptable, set prioritized time frames within that point for resuming activities at a specified minimum acceptable capacity, identify the prioritized activities, and determine the resources, dependencies and interdependencies they rely on including partners and suppliers.
Common gap: Recovery time frames set by aspiration and never reconciled to the impact analysis that should produce them
Source: ISO 22301:2019
DORA (Regulation (EU) 2022/2554)
DORA Art. 11 Response and recoveryFinancial entities shall put in place an ICT business continuity policy and ICT response and recovery plans (including measures, procedures and arrangements) to ensure continuity of critical or important functions, quickly contain damage, resume activities and recover, subject to regular testing.
Common gap: No ICT continuity/response/recovery plans
Source: DORA (Regulation (EU) 2022/2554)
Do this for every document on your list
Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.
Build a register