BIA Operation
Before beginning a BIA, ensure that the BIA Setup has been completed to the organisation's requirements.
Identify Products, Services and Activities
The first steps of a BIA are to identifyOnce the above steps have been completed, the activity workflow can be followed, as described below.
Activity BIA
Abriska guides the users through an organisational defined workflow that meets the requirements of ISO 22301. The buttons available on the sidebar will increase depending on the activity work stage.Activity duration, frequency and operating times
To capture information regarding the criticality of an activity, the operating hours, approximate duration and frequency should be entered. To add this information, click ‘Activity Duration and Frequency’ from the ‘Activity’ page.Link to products and services
For each product and service that is loaded into Abriska (regardless of the division), each activity needs to specify whether it is required to deliver that product. To add this information, click ‘Products and Services’ from the ‘Activity’ page.
Activity inter-dependencies
An activity may rely on other activities for either data, or to complete its operational processes. These relationships need to be modelled within Abriska to understand what the recovery priority should be for each activity. To add this information, click ‘Identify Inter-dependencies’. The activity hierarchy will be shown and a checkbox will be visible next to each activity. When a checkbox is clicked, a further information panel will display which allows additional information to be entered about this relationship.Identify Assets' business as usual
To understand what an activity requires for business as usual, each activity can be linked to organisation resources. To add this information, click ‘Identify Resources’ from the ‘Activity’ page. Displayed is the resource hierarchy. Each resource with a checkbox allows the resource to be selected as “required for business as usual”.Abriska allows resources to be set up as ‘multiple’. If this flag is set, a textbox will be displayed to enter the amount of resources required by this activity.
Identify impact over time and MTPD
The MTPD must be defined for each activity. Abriska satisfies this by specifying the impact over time for each activity. Abriska then uses the organisation’s threshold for each impact to determine this time period. Each of the impacts that were specified at the organisation level need to be quantified against the timescale that was specified at the division level.To edit the profile of a specific impact, click ‘Identify Impacts’ from the ‘Activity’ page and click on the impact name. The timescale will be specific to this division and the impact level will be specific to this impact. For each timescale, specify what the impact would be. For example, if the reputational impact is moderate after 4 days then select the radio button labelled with that time period.
From the ‘Activity’ page, click on ‘Identify MTPD’. If none of the impacts reach the threshold within the timescale, the MTPD will need to be manually entered.
-
If an impact reaches the organisation’s threshold within the
timescale,timescale then the MTPD will be calculated.
- When entering the MTPD, it must be larger than the greatest impact time. This is required to enforce the impact threshold logic.
Figure 27 - Entering MTPD for Non-Critical Activities 2.3.7 Identify
Identify recovery resources, RPO and RTO
ISO 22301 requires that an organisation:If any of the selected resources have been set up as ‘RPO required’ then additional information will display within the resource detail sectionsection. (highlighted blue in Figure 29 - Resource RTO). This allows the data recovery requirements to be entered. Enter the amount that could be lost from this system but still allow the activity to operate. Note:
infobox: It may be that 24 hours could be tolerated with users re-keying the information in from manual hard