Visitors Edition
Membership Help?
Need help? Our Trial Membership program will get you help on any IT project you're working on. You'll get access to our research, tools, advice and project help.
Start your free trial membership now:
Want to learn more about our membership options, pricing, or to get a product demo? Get in touch with one of our reps using an option below.
Learn more About Info-Tech
Click to Chat

Business Impact and Risk Assessment

The purpose of a Business Impact and Risk Assessment is to determine the approximate business value of IT assets, to assess the impact the loss of those assets would have on business units, and to assign recovery priorities to the assets.

The Business Impact and Risk Assessment involves seven steps:

  1. Assess threats and risks.
  2. Assess data center vulnerabilities.
  3. Document DRP basics.
  4. Assign value to IT assets.
  5. Assign prioritization to assets.
  6. Determine costs versus risk tradeoff.
  7. Maintain risk plans.

When a Business Impact and Risk Assessment is completed, you will have a complete list of the risks specific to each IT asset, as well as risk reports and profiles for the business impact analysis. Consider revisiting your Business Impact and Risk Assessment annually.

Advanced

Steps Tools Related Research
Step 1: Assess Threats and Risks
Core 1.1 Inventory Corporate Assets
Word Document Corporate Asset Inventory
  1. Information Risk Management: Leaping Beyond IT Security
  2. Chief Risk Officer: A New Role for Your Enterprise
  3. Automated Tools Practical Choice for Managing Software Assets
  4. Where Does It Hurt? Perform a Risk and Business Impact Analysis
Core 1.2 Identify Threats/Risks Specific to Assets
Word Document Potential Risk Checklists
 
Core 1.3 Identify Existing Mitigation
Word Document DRP Operational Analysis
 
Core 1.4 Summarize the Operational Analysis
Word Document Operational Analysis Summary
 
Step 2: Assess Data Center Vulnerabilities
Core 2.1 Conduct An Audit of the Data Center
Excel Document Data Center Security Audit
Excel Document Data Center Security Audit (Core)
 
Core 2.2 Conduct Probability Assessments
Word Document Data Center Risk Probabilities
 
Step 3: Confirm DRP/Business Context
Core 3.1 Document Business Structure and Key Stakeholders
Excel Document Disaster Recovery Planning Workbook
Word Document Call Tree
 
Step 4: Assign Value to IT Assets
Core 4.1 Plan Against Downtime/Loss of Asset
Word Document Downtime Policy
 
Core 4.2 Conduct a Business Impact Analysis
Excel Document Risk and Business Impact Analysis Worksheet
Word Document Technical Risk Analysis Report
  1. How to Calculate Downtime
Step 5: Assign Prioritization to Assets
Core 5.1 Prioritize Recovery by Impact to Business Units
Word Document Business Unit Prioritization
  1. Calculate IRR to Quickly Prioritize Lengthy Project Lists
Core 5.2 Document Prioritized Recovery List
Word Document Recovery Prioritization Meeting
 
Step 6: Determine Costs vs. Risk Tradeoff
Advanced 6.1 Conduct ROI Studies
Excel Document Mitigation Project ROI & Prioritization Tool
Excel Document Return on Security Investment Calculator
  1. Total Cost of Ownership (TCO) Calculator
  2. Virtual Servers Lower Business Continuity Costs
  3. Cost/Benefit Analysis Tool
Step 7: Maintain Risk Plans
Core 7.1 Create Asset-Specific Risk Reports
Word Document Asset Risk Report
 
Core 7.2 Document, Track, and Manage Risks
Excel Document Request Trend and Analysis Tool