The Best Damn IT Security Management Book Period

Chapter 37: BC/DR Checklists

Risk Assessment

Risk management includes the three elements of the risk assessment: threat assessment, vulnerability assessment, and impact analysis. This information is the input to the risk mitigation phase that concludes the risk assessment portion of the business continuity and disaster recovery project work.

The first step in business continuity and disaster recovery planning is the risk assessment. Included here are top-level items that should be included. You can modify this list to suit your specific needs. Refer to the specific chapters for detailed information on these topics.

Threat and Vulnerability Assessment

  1. Identify all natural threats.

  2. Identify all man-made threats.

  3. Identify all IT and technology-based threats.

  4. Identify all environmental/infrastructure threats.

  5. For each threat, identify threat sources.

  6. For each threat source, identify the likelihood of occurrence.

  7. Based on likelihood of occurrence, assess company's vulnerability to each threat source.

  8. Based on likelihood and vulnerability, prioritize list of threats to company.

Business Impact Analysis

  1. Based on prioritized list of threats, assess impact of each threat on business operations.

  2. Based on threats, perform upstream and downstream loss analysis.

  3. Prioritize business functions into mission-critical, important, minor (you can customize categories to suit your needs).

  4. For each mission-critical business function, assess the impact of the loss of this function.

  5. For each mission-critical business function, assess the impact of various threats to this function.

  6. Develop a prioritized list of mission-critical business functions with the highest business impact.

  7. For the highest priority functions, identify the recovery time requirements including maximum tolerable downtime (MTD).

  8. For business systems, business functions,...

UNLIMITED FREE
ACCESS
TO THE WORLD'S BEST IDEAS

SUBMIT
Already a GlobalSpec user? Log in.

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.

Customize Your GlobalSpec Experience

Category: Environmental Testing and Analysis Services
Finish!
Privacy Policy

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.