2 cissp ® Official Study Guide Eighth Edition


Business Unit and Functional Priorities



Download 19,3 Mb.
Pdf ko'rish
bet763/881
Sana08.04.2023
Hajmi19,3 Mb.
#925879
1   ...   759   760   761   762   763   764   765   766   ...   881
Bog'liq
(CISSP) Mike Chapple, James Michael Stewart, Darril Gibson - CISSP Official Study Guide-Sybex (2018)

Business Unit and Functional Priorities
To recover your business operations with the greatest possible efficiency, you must engineer 
your disaster recovery plan so that those business units with the highest priority are recov-
ered first. You must identify and prioritize critical business functions as well so you can 
define which functions you want to restore after a disaster or failure and in what order.
To achieve this goal, the DRP team must first identify those business units and agree on 
an order of prioritization, and they must do likewise with business functions. (And take 
note: Not all critical business functions will necessarily be carried out in critical business 
units, so the final results of this analysis will very probably comprise a superset of critical 
business units plus other select units.)
If this process sounds familiar, it should! This is very like the prioritization task the BCP 
team performs during the business impact assessment discussed in Chapter 3. In fact, most 


Recovery Strategy 
819
organizations will complete a business impact assessment (BIA) as part of their business 
continuity planning process. This analysis identifies vulnerabilities, develops strategies to 
minimize risk, and ultimately produces a BIA report that describes the potential risks that 
an organization faces and identifies critical business units and functions. A BIA also identi-
fies costs related to failures that include loss of cash flow, equipment replacement, salaries 
paid to clear work backlogs, profit losses, opportunity costs from the inability to attract 
new business, and so forth. Such failures are assessed in terms of potential impacts on 
finances, personnel, safety, legal compliance, contract fulfillment, and quality assurance, 
preferably in monetary terms to make impacts comparable and to set budgetary expecta-
tions. With all this BIA information in hand, you should use the resulting documentation as 
the basis for this prioritization task.
At a minimum, the output from this task should be a simple listing of business units in 
priority order. However, a more detailed list, broken down into specific business processes 
listed in order of priority, would be a much more useful deliverable. This business process–
oriented list is more reflective of real-world conditions, but it requires considerable addi-
tional effort. It will, however, greatly assist in the recovery effort—after all, not every task 
performed by the highest-priority business unit will be of the highest priority. You might 
find that it would be best to restore the highest-priority unit to 50 percent capacity and then 
move on to lower-priority units to achieve some minimum operating capacity across the 
organization before attempting a full recovery effort.
By the same token, the same exercise must be completed for critical business processes 
and functions. Not only can these things involve multiple business units and cross the 
lines between them, but they also define the operational elements that must be restored 
in the wake of a disaster or other business interruption. Here also, the final result should 
be a checklist of items in priority order, each with its own risk and cost assessment, and a 
corresponding set of mean time to recovery (MTTR) and related recovery objectives and 
milestones. These include a metric known as the maximum tolerable outage (MTO). This 
is the maximum amount of time that the business can withstand the unavailability of a 
service without experiencing significant disruption. Business continuity planners can com-
pare MTTR and MTO values to identify situations that require intervention and additional 
controls.

Download 19,3 Mb.

Do'stlaringiz bilan baham:
1   ...   759   760   761   762   763   764   765   766   ...   881




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish