After completing a business impact analysis, the next step is to identify resources for business recovery . The BIA identifies critical business processes, recovery priorities, impacts over time, recovery time objectives, and recovery point objectives. Once these requirements are known, the organization must determine the resources needed to meet them, such as personnel, facilities, technology, data, applications, vendors, and alternate processing capabilities. Developing a business continuity plan occurs after recovery requirements and resources are understood. Evaluating the disaster recovery plan would generally occur after plans have been developed and tested. Developing requirements for the incident response plan is related to incident management, but it is not the next step after a BIA in continuity planning. CISM program management emphasizes that BIA outputs drive recovery strategy development, and resource identification is a necessary bridge between impact analysis and actionable continuity plans. Therefore, identifying resources for business recovery is the appropriate next activity after the BIA.
[References:, ISACA CISM Review Manual, Information Security Program Development and Management — BIA outputs and continuity strategy development, ISACA CISM Exam Content Outline, Domain 3: Information Security Program Development and Management, , ]
Submit