Business Impact Analysis Template v3.9.4

You might also like

Download as xls, pdf, or txt
Download as xls, pdf, or txt
You are on page 1of 27

Department: [Insert]

IMPACT AND RES

What is the maximum time the


activity can be disrupted before the
impacts become unacceptable?
This is known as the Maximum
Acceptable Outage (MAO)
Name of
product(s) or
Ref service(s) Process Activities

4
Completed by:

IMPACT AND RESUMPTION TIMESCALES DELIVERABLES

How quickly should the activity be


resumed following an incident? Brief description of the Normal working
Seasonal Variations
This is known as the Recovery Time justification for the maximum patterns for
Identify peak time of
Objective and must be less than the acceptable outage and the delivering the month/year
MAO in order to avoid an recovery time objective activity
unacceptable impact

Once you have completed the Business Impact Analysis, please update the 'Date last reviewed' & 'Complete
Date last reviewed:

WHAT RESOURCES DO YOU NEED TO MAINTAIN THE ACTIVITY


RABLES STAKEHOLDERS
UNAC

Service Level Who are the Who are the


Staff roles required
Agreements internal external Name of building(s)
Time schedules stakeholders stakeholders to deliver activity

ast reviewed' & 'Completed by', then email to x: [insert email address and ext. number]
NEED TO MAINTAIN THE ACTIVITY AT AN AGREED LEVEL WITHIN THE RECOVERY TIME OBJECTIVE TO AVOID AN
UNACCEPTABLE IMPACT?

Information and
Specialist
IT hardware and data Desk phones/work Partners &
equipment and/or
applications Physical records mobiles consumables Suppliers
and Electronic data
BUSINESS IMPACT DEFINITIONS
INSERT. E.g. BUSINESS OBJECTIVES INSERT. E.g. LEGAL, REGULATORY AND CONTRACTUAL
§
No Impact § No Impact

Minor § Minor
§
§
Moderate § Moderate

§
Major § Major

§
Critical Critical
§
INSERT. E.g. FINANCIAL INSERT. E.g. REPUTATIONAL

No Impact No Impact

Minor Minor

Moderate Moderate

Major Major

Critical Critical

6 / 27
7 / 27
Name of activity: Insert

Time
BUSINESS OBJECTIVES
<4 hrs <1 day <2 days <3 DAYS <1 WEEK >1 WEEK 1 MONTH
No Impact x
I
M Minor x
P
A
Moderate x
C Major x
T
Critical X x x

LEGAL, REGULATORY & Time


CONTRACTUAL <4 hrs <1 day <2 days <3 Days <1 week >1 week 1 month
No Impact
I
M Minor
P
A Moderate
C Major
T
Critical

Time
PEOPLE WELFARE
<4 hrs <1 day <2 days <3 Days <1 week >1 week 1 month
No Impact
I
M Minor
P
A Moderate
C Major
T
Critical

Time
FINANCIAL
<4 hrs <1 day <2 days <3 Days <1 week >1 week 1 month
No Impact
I
M Minor
P
A
Moderate
C Major
T
Critical

Time
REPUTATIONAL
<4 hrs <1 day <2 days <3 Days <1 week >1 week 1 month
No Impact
I
M Minor
P
A Moderate
C Major
T
Critical
Maximum Acceptable
Outage

Unacceptable level of impact (to be customised by the organizati


Justification No Impact
Minor
Business Objectives Moderate
Major
Critical
No Impact
Minor
Contractual Moderate
Justification Major
Critical
No Impact
Minor
People Welfare Moderate
Major
Critical
No Impact
Justification Minor
Financial Moderate
Major
Critical
No Impact
Minor
Reputational Moderate
Major
Justification Critical

The Maximum Acceptable Outage is determined by the shortest time of


unacceptable level of impact to either:
• Business Objectives
• Legal, Regulatory and Contractual
• People Welfare
• Financial

Justification
Recovery Time Objective

be customised by the organization)

ermined by the shortest time of an


Purpose
What is the application used for?

Business continuity solution exists?


Name Yes / No

Impact over time if this application was unavailable


<4 hrs <1 day <2 days <3 DAYS <1 WEEK >1 WEEK
No Impact x
I
M Minor x
P
A Moderate x
C Major x
T
Critical x x
Recovery Time Objective Recovery Point Objective

Purpose
What is the application used for?

Business continuity solution exists?


Name Yes / No

Impact over time if this application was unavailable


<4 hrs <1 day <2 days <3 Days <1 week >1 week
No Impact
I
M Minor
P
A Moderate
C Major
T
Critical

Recovery Time Objective Recovery Point Objective

Purpose
What is the application used for?

Business continuity solution exists?


Name Yes / No

Impact over time if this application was unavailable


<4 hrs <1 day <2 days <3 Days <1 week >1 week
No Impact
I
M Minor
P
A Moderate
C Major
T
Critical
Recovery Time Objective Recovery Point Objective

Purpose
What is the application used for?

Name Business continuity solution exists?


Yes / No

Impact over time if this application was unavailable


<4 hrs <1 day <2 days <3 Days <1 week >1 week
No Impact
I
M Minor
P
A Moderate
C Major
T
Critical
Recovery Time Objective Recovery Point Objective

Purpose
What is the application used for?

Business continuity solution exists?


Name Yes / No

Impact over time if this application was unavailable


<4 hrs <1 day <2 days <3 Days <1 week >1 week
No Impact
I
M Minor
P
A Moderate
C Major
T
Critical
Recovery Time Objective Recovery Point Objective
The findings of the IT Applications impact assessm
to review prioritized applications that support
business products and services. The register can
support further risk assessment and/or to priori
vailable continuity planning and/or disaster recover
1 MONTH Justification

x
ery Point Objective

vailable
1 month Justification

ery Point Objective

vailable
1 month Justification
ery Point Objective

vailable
1 month Justification

ery Point Objective

vailable
1 month Justification

ery Point Objective


he IT Applications impact assessment can be used
oritized applications that support the delivery of
ucts and services. The register can also be used to
er risk assessment and/or to prioritize IT business
planning and/or disaster recovery planning.
Purpose
How does the supplier support the delivery of the activity?

Business continuity solution exists?


Name of supplier Yes / No

Impact over time if the Supplier's service was unavailable


<4 hrs <1 day <2 days <3 DAYS <1 WEEK >1 WEEK 1 MONTH
No Impact x
I
M Minor x
P
A Moderate x
C Major x x
T
Critical x x

Purpose
How does the supplier support the delivery of the activity?

Business continuity solution exists?


Name of supplier Yes / No

Impact over time if the Supplier's service was unavailable


<4 hrs <1 day <2 days <3 Days <1 week >1 week 1 month
No Impact
I
M Minor
P
A Moderate
C Major
T
Critical
Any supplier with an unacceptable impact within x days will ne
reviewed to check their level of resilience.

For new potential suppliers, this may involve doing due diligience
the supplier's business continuity plan before signing a contract. T
you to investigate whether the supplier has business continuity s
place that resume their service to you within your required reco
Justification objective.

Findings may be incorporated into a business continuity schedule i


Level Agreement with the supplier. Your organization may also w
your own business continuity arrangements in place, such as dua
resource to reduce risk of disruption.

For existing suppliers, you may want to review the Service Level A
you are aware of risk and can amend the contract in the next rev
appropriate).

Justification
le impact within x days will need to be
their level of resilience.

y involve doing due diligience to evaluate


n before signing a contract. This will allow
plier has business continuity solutions in
you within your required recovery time
jective.

business continuity schedule in the Service


Your organization may also want to put
gements in place, such as dual source the
uce risk of disruption.

to review the Service Level Agreement so


nd the contract in the next review (where
ropriate).
Recovery Time
Objective Activity

<4 hours

<1 day

<2 days

<3 days

<1 week

>1 week

<1 month

Department organization chart located here:


Insert the minimum resources you wou

Name of building(s) Staff roles required to deliver activity

§
§
§
§
§

§
§
§
§
§

§
§
§
§
§

§
§
§
§
§

§
§
§
§
§

§
§
§
§
§

§
§
§
§
§

Department organization chart located here:


mum resources you would require over time in order to continue your activities within their recovery time objective

Information and data


IT hardware and applications
Physical records and Electronic data
activities within their recovery time objective

Desk phones/work mobiles Specialist equipment and/or consumables


Partners & Suppliers

You might also like