2. Why is a business impact analysis (BIA) an important first step in defining a business continuity plan (BCP)? The BIA identifies the critical and non-critical functions of the business. The BIA provides timeframes for critical functions to resume, for the business to become functional. The BIA estimates the cost related to the failure such as loss of cash flow, salaries for critical employees to recovery from a failure, and the cost of new equipment. The BIA provides framework to build the BCP upon.
3. How does risk management and risk assessment relate to a business impact analysis for an IT infrastructure? Identification of risk is necessary to establish the impact it will have on the IT infrastructure. The assessment gives the risk a category and priority. The process of prioritizing helps to manage the risk of high impact and probability of occurring.
4. What is the definition of recovery time objective (RTO)? is the duration of time and a service level within which a business process must be restored after a disaster (or disruption) in order to avoid unacceptable consequences associated with a break in business continuity. Why is this important to define in an IT Security Policy Definition as part of the Business Impact Analysis or Business Continuity Plan (BCP)?Because it provides the basis for identifying and analyzing viable strategies for inclusion in the business continuity plan.
5. True or False – If the recovery Point Objective (RPO) metric does not equal the recovery time objective (RTO), you may potentially lose data or not have data backed-up to recover. This represents a gap in potential lost or unrecoverable