The organization shall conduct a comprehensive Business Impact Analysis (BIA) to identify and assess the criticality and interdependencies of business processes, supporting ICT systems, services, and assets, and to support the development and validation of ICT response and recovery plans.
The BIA must:
- Identify and classify critical and important functions
- Define maximum tolerable downtimes (MTD) and recovery time objectives (RTO) and recovery point objectives (RPO)
- Evaluate operational, financial, legal and reputational impacts of ICT service disruption
- Map dependencies on ICT systems, data, infrastructure, and third-party services
- Be regularly reviewed and updated (e.g., annually or after major changes)
Integration with ICT Recovery Planning:
The results of the BIA must directly inform the structure and priorities of ICT response and recovery plans
Recovery plans must reflect:
- Which systems/services require the fastest recovery
- The sequence of restoration
- Acceptable data loss and downtime thresholds
- Plan testing must be based on plausible disruption scenarios that target high-impact systems/functions identified in the BIA
- Recovery plans must be evaluated against BIA expectations during incident exercises and updated accordingly