Which of the following is an objective approach that assesses the organisational activities?
Business Impact Analysis (BIA) is an objective approach that assesses the organisational activities and determines their criticality, dependencies, and recovery priorities. BIA is a key process in developing a business continuity management system (BCMS) according to ISO 22301. BIA helps to identify the potential impacts of disruptions to the organisation's critical functions and processes, such as financial losses, reputational damage, legal liabilities, regulatory penalties, customer dissatisfaction, etc. BIA also helps to determine the recovery time objectives (RTOs), recovery point objectives (RPOs), and minimum business continuity objectives (MBCOs) for each critical function and process. BIA provides the basis for developing business continuity strategies and plans that ensure the continuity and resilience of the organisation.Reference:
ISO 22301 Auditing eBook, Chapter 2: Business Continuity Concepts and Principles, Section 2.3: Business Impact Analysis1
ISO/TS 22317:2021(en), Security and resilience --- Business continuity management systems --- Guidelines for business impact analysis2
Which BCMS process analyzes the adequacy of the business continuity capability using defined targets and performance indicators?
Performance evaluation is the BCMS process that analyzes the adequacy of the business continuity capability using defined targets and performance indicators. It involves monitoring, measuring, analyzing, and evaluating the BCMS performance and effectiveness, as well as conducting internal audits and management reviews. Performance evaluation helps to identify the strengths and weaknesses of the BCMS, as well as the opportunities for improvement and corrective actions.Performance evaluation is one of the key requirements of ISO 22301, as it demonstrates the organization's commitment to continual improvement and customer satisfaction.Reference: ISO 22301 Auditing eBook, page 191; ISO 22301:2019, clause 92
Which role is associated with specialist services offered by third parties?
Suppliers are the role associated with specialist services offered by third parties, such as consultants, trainers, auditors, or certification bodies. Suppliers can provide external support and expertise to the organization in developing, implementing, maintaining, and improving its BCMS. Suppliers can also help the organization to demonstrate its conformance and competence to interested parties, such as customers, regulators, or investors.Suppliers are one of the key stakeholders of the BCMS, as they can influence or be influenced by the organization's business continuity performance and objectives.Reference: ISO 22301 Auditing eBook, page 121; ISO 22301:2019, clause 4.22
Most government policies have direct influences on how organizations shape their business strategies and plans.
Most government policies have direct influences on how organizations shape their business strategies and plans, as they affect the legal, regulatory, economic, and social environment in which the organizations operate. Government policies can create opportunities or threats for the organizations, depending on their nature and impact. For example, government policies can affect the taxation, trade, security, environmental, and human rights aspects of the organizations' activities. Therefore, organizations need to monitor and analyze the government policies that are relevant to their business objectives and interests, and adapt their business strategies and plans accordingly.This is also important for the business continuity management system (BCMS), as it helps the organizations to identify and address the risks and opportunities related to the government policies, and to ensure the compliance and resilience of their BCMS.Reference: ISO 22301 Auditing eBook, page 131; ISO 22301:2019, clause 4.12
Which strategy supports the recovery needs of each critical product and service?
Strategy option evaluation and selection is the strategy that supports the recovery needs of each critical product and service. This strategy involves the following steps:
Identify the recovery options: Based on the results of the business impact analysis (BIA) and the risk assessment, identify the possible recovery options for each critical product and service. Recovery options are the alternative ways of resuming the delivery of the product or service within the recovery time objective (RTO) and the recovery point objective (RPO). Examples of recovery options are: relocating to an alternate site, activating a mutual aid agreement, using a cloud-based backup, outsourcing to a third-party provider, etc.
Evaluate the recovery options: Assess the feasibility, effectiveness, and efficiency of each recovery option, using criteria such as: cost, availability, scalability, compatibility, security, compliance, etc. Compare the advantages and disadvantages of each option and rank them according to their suitability for meeting the recovery needs.
Select the recovery options: Choose the best recovery option for each critical product and service, based on the evaluation results and the available resources. Ensure that the selected option aligns with the organization's business continuity objectives, policies, and strategies. Document the rationale and justification for the selection and communicate it to the relevant stakeholders.
Strategy option evaluation and selection is the strategy that supports the recovery needs of each critical product and service, as it enables the organization to identify, evaluate, and select the most appropriate recovery option for each critical product and service, based on the BIA and the risk assessment results. This strategy helps the organization to ensure the continuity and resilience of its critical products and services in the event of a disruption, and to optimize the use of its resources and capabilities.Reference:
ISO 22301 Auditing eBook, Chapter 3: Business Continuity Management System, Section 3.4.2: Business Continuity Strategy, Page 19
ISO 22301 Auditing eBook, Chapter 5: Business Continuity Management System Audit Activities, Section 5.3.2: Audit of Business Continuity Strategy, Page 37
ISO 22301:2019, Clause 8.3: Business Continuity Strategies and Solutions, Page 18
Ashley Jones
5 days agoChristopher Jones
21 days agoCrystal Torres
1 month agoLinda Garcia
2 months agoDonna Robinson
2 months agoGary Robinson
3 months agoAndrew Phillips
3 months agoLisa Flores
4 months agoMaria Johnson
4 months agoStephen Lee
5 months agoAnthony Torres
5 months agoRonald Moore
5 months agoPatricia Torres
5 months agoJoshua Carter
5 months agoJessica Bell
5 months agoPhyliss
5 months agoMeghan
6 months agoAmos
6 months agoTomoko
6 months agoSherman
6 months agoAnnita
7 months agoEun
7 months agoStephaine
7 months agoTamesha
8 months agoJunita
8 months agoRegenia
8 months agoRikki
8 months agoHeike
9 months agoAnnabelle
9 months agoLouvenia
9 months agoWilford
9 months agoRaymon
9 months agoMaryann
10 months agoKirk
10 months agoKing
10 months agoCarlee
11 months agoGayla
11 months agoJerry
11 months agoStaci
11 months agoKenneth
12 months agoAmos
12 months agoWalker
12 months agoNicolette
1 year agoJaclyn
1 year agoDonette
1 year agoReita
1 year agoEdwin
1 year agoBoris
1 year agoSilva
2 years agoChanel
2 years agoNydia
2 years agoRuthann
2 years agoErasmo
2 years agoYen
2 years agoNieves
2 years agoIluminada
2 years agoSharita
2 years agoLakeesha
2 years agoPaulene
2 years agoCordelia
2 years agoJavier
2 years agoMicaela
2 years agoOliva
2 years agoCyril
2 years agoWillis
2 years agoCherry
2 years agoPenney
2 years agoGeraldo
2 years agoJacinta
2 years agoKristofer
2 years agoDaniel
2 years agoLouisa
2 years agoYasuko
2 years agoStephen
2 years agoMonroe
3 years ago