Business Continuity and Disaster Recovery - Risk Analysis and Control

In the risk evaluation phase, there are a number ofvulnerabilities which would have the greatest impact
key areas that must be covered. One of the moston your critical business processes and the
important is to understand probable threats. In anorganization. This starts to clarify and quantify
ideal world, which most of us have noticed does notpotential losses, which helps to establish
exist, we would identify and protect ourselvespriorities.Following the identification of the most
against all threats to ensure that our businessprobable threats and vulnerabilities, an analysis of
continues to survive. Obviously, we are constrainedexisting controls is needed. This spans physical
by other factors such as budgets, time and prioritiessecurity as well as people, processes, data,
and need to apply cost benefit analysis to ensure wecommunications and asset protection. Some controls
are protecting the most critical business functions.Asuch as physical security and data backup are
second important step is to identify all probableobvious. Other controls required are often less
threats and prioritize them. Threats, typically, can beobvious, but they can be identified through the risk
classified in several ways such as internal/external,evaluation process.Once the key building blocks of
man-made/natural, primary/secondary, accidentalcritical business functions, most probable threats,
intentional, controllable/not controllable, warning/novulnerabilities and controls are identified, the next
warning, frequency, duration, speed of onset etc.stage is to develop an understanding of the
While classifying threats is helpful in terms ofprobability of threats factored by the severity or
understanding their characteristics and potentialimpact of the threats. This leads to the business
controls, grouping and understanding by businessimpact analysis phase which establishes priorities for
impact is also important. Obviously, the same impactprotection.The goal is to minimize threats, impacts
can result from a number of differentand downtime and to mitigate any losses.
threats.Identifying mission critical business processesFundamentally, the goal is to protect your people,
and systems is another fundamental building block ofprotect your data, protect your vital communications,
the business continuity plan. After your criticalprotect your assets and to protect your brand and
business processes and systems and probablereputation. Overall, of course, the goal is to ensure
threats are established, the next step is to identifyyour business continues to operate and to do it in a
vulnerabilities and loss potential. This requires ancost-effective way meeting standards of reasonable
extensive scan of the organization to identifyand prudent judgment.
vulnerabilities and then analysis to understand those