Once an organization has conducted a thorough inventory of all its critical information technology assets, it must assess the impact that a cybersecurity incident would have on them. This will help the organization rank its IT assets according to criticality and prioritize them for cybersecurity controls. The Business Impact Analysis (BIA) is the document that accomplishes this.
A Business Impact Analysis should be conducted by qualified individuals within the organization. To make the analysis as thorough as possible, all relevant departments should be involved in the process. A good BIA requires the organization to understand how technology supports every business process and how those processes affect the organization as a whole. The basic principle is that the more critical processes an asset supports, the greater the impact a cyberattack on that asset will have on the organization’s bottom line.
To conduct a Business Impact Analysis (BIA), organizations should use the following basic steps:
1. Identify Key Processes & Functions
This step was already conducted in Stage 1: Identify & Document of this framework. Organizations must understand the key processes that power the organization, as well as the individual functions that support those processes. Everything from communication with clients and third parties to nightly backups of organizational data must be accounted for.
2. Identify Assets
This step was also conducted in Stage 1. The organization must maintain a full and complete inventory of every IT asset, both internal and external. Endpoints, servers, networking devices, cloud platforms, digital identities and accounts, data stores, and third-party technology services should all be accounted for. Details about the location, purpose, cost, and assigned users of each asset should be included.
Assets must then be reconciled with the key business processes and functions they support, creating a complete map of IT's role within the organization.
3. Compile Data
In addition to maintaining a basic inventory of IT assets and their roles within the organization, there must be a thorough understanding of more specific attributes. These include interdependencies between assets, system boundaries in relation to business processes, and the resources required to keep assets operational.
Organizations should also maintain data on the current security measures in place for every applicable asset. This includes both physical and logical controls. Much of the information required for this step should have already been gathered during various activities in Stage 1.
4. Analyze Potential Impacts
Now that the organization understands the importance of each IT asset, it can begin analyzing the effect that a cyberattack—or a loss of confidentiality, integrity, or availability—would have on each asset. The level of impact is derived from the criticality of the asset to the organization's business processes and functions. The more critical processes and functions an asset supports, the higher the impact.
Organizations should never underestimate the criticality of certain assets. Some assets may appear basic or unimportant in the grand scheme of operations when, in reality, they play a vital role in supporting critical business functions.
There are several categories of impact that should be assessed. Each measures a different potential consequence to the organization:
- Operational Impact: The effect of a cybersecurity incident on the organization's day-to-day operational performance.
- Financial Impact: The potential financial losses the organization may incur as a result of a cyberattack affecting the asset.
- Reputational Impact: The effect of a cybersecurity incident on the organization's reputation with stakeholders, clients, and the general public.
- Compliance Impact: Potential compliance issues arising from a cybersecurity incident, which may result in regulatory penalties or legal consequences.
Each asset should receive an impact rating for each of the categories above. The standard format for assigning impact ratings is the Low, Medium, High scale. The organization's interpretation of these ratings should be as follows:
- Low: The effect is noticeable and requires remediation, but the overall impact on the organization's bottom line is minimal.
- Medium: The effect significantly impacts one or more business functions or processes, potentially reducing productivity and posing a meaningful threat to the organization's bottom line.
- High: The effect critically impacts the majority of business functions and processes, severely disrupting productivity and posing an existential threat to the organization's bottom line.
After assigning a Low, Medium, or High rating to each impact category, an overall impact rating should be assigned to the asset. The overall impact rating should reflect the highest rating assigned among all impact categories.
For example, if a public-facing company web server has the following impact ratings:
- Operational Impact: Low
- Financial Impact: Medium
- Reputational Impact: High
- Compliance Impact: Low
The overall impact rating for the public-facing web server would be High.
5. Determine MTD, RTO, and RPO
To further understand the criticality of each IT asset, several recovery metrics should be established:
- Maximum Tolerable Downtime (MTD): The absolute maximum amount of time an asset can remain offline or non-operational before causing severe harm to the organization's operations, finances, reputation, or compliance status.
- Recovery Time Objective (RTO): The acceptable amount of time required to recover an asset before operational, financial, reputational, or compliance damage begins to occur. The RTO must always be equal to or less than the MTD.
- Recovery Point Objective (RPO): The maximum amount of data loss the organization can tolerate, measured in time. To better understand this concept, consider how far back in time a system could be restored before the resulting data loss becomes unacceptable. If one hour of data is lost, how difficult would it be to recover? What about an entire day?
6. Finalization & Presentation
At the conclusion of the Business Impact Analysis, a professional document should be prepared containing the results. Each IT asset should be listed along with its operational, financial, reputational, and compliance impact ratings, as well as its overall impact rating. Each asset should also include its MTD, RTO, and RPO metrics.
Once all assets have been assessed, the document should provide a final business criticality ranking of all assets. The ranking should be presented in descending order, with the most critical assets listed first and the least critical assets listed last.
The most critical assets are generally systems, services, and data repositories that support multiple important business processes or a single process that is essential to the organization's survival. For example, a database containing personally identifiable information (PII) for all clients may only participate in a relatively simple input/output process, yet the value of the data it contains is critical to the organization's survival. If that data were breached or lost, the resulting reputational, financial, and compliance impacts could be catastrophic.
Conversely, an Ethernet switch may not store sensitive data, but it serves as a critical dependency for many of the organization's digital processes and services. Its failure could disrupt operations across the entire organization.
The least critical assets are generally those that provide convenience or supplemental functionality but have little or no meaningful impact on the organization's operational, financial, reputational, or compliance well-being. For example, a television in a breakroom displaying news and weather information to employees.
Once the Business Impact Analysis has undergone final review and approval, it should be shared with senior management and all applicable members of the IT and cybersecurity teams. Its contents will be used to guide future risk assessments, business continuity planning efforts, disaster recovery planning, and security control selection.
