You are on page 1of 6

Part I: Business Area Impact (Sample BIA questionnaire)

This questionnaire must be filled out for each business area within ABC Co.
(Note: Excess form blanks compressed to save space)
Function:
Business area:
Departments contained within this area:
Area manager:
Overall functional priority (to be added by CPMT):
Date of BIA questionnaire:
Questionnaire completed by:
Area Description: Describe the corporate mission of this area.
What functions are conducted within this area?
What changes have occurred within this area since the last BIA review?
What changes are expected within this area before the next BIA review?

Impact Assessment
Select the statement that best describes the effect on this business area should
there be an unplanned interruption of normal operations:
ABC Co. will feel an impact within:
[ ] 8 hours of an interruption
[ ] 24 hours of an interruption
[ ] 3 days of an interruption
[ ] 5 days of an interruption
[ ] 10 days of an interruption
[ ] 30 days of an interruption
What is the estimated recovery time objective (RTO) for this area (time after
interruption before operations are critically impacted)?
[ ] Tier 1 (012 hours) This business area is vital.
[ ] Tier 2 (1224 hours) This business area is critical.
[ ] Tier 3 (2448 hours) This business area is essential.
[ ] Tier 4 (4872 hours) This business area is important.
[ ] Tier 5 (7296 hours) This business area is noncritical.
[ ] Tier 6 (more than 96 hours) This business unit/cost center is deferrable.

What is the estimated recovery point objective (RPO) for this function (point in time
by which function must be recovered to support operations)?
[ ] Point 1 (less than 6 hours) [ ] Point 2 (less than 24 hours)
[ ] Point 3 (less than 48 hours) [ ] Point 4 (less than 72 hours)
[ ] Point 5 (more than 72 hours)
Identify the extent of exposure that would be incurred by the business area and/or
ABC Co. should an unplanned interruption occur.
Additional expense
Assets:
Customer service:
Revenue loss per day:
Productivity loss per day:
Financial exposure:
Goodwill:
Regulatory/legal:
What is the estimated dollar loss for the company from this business area should
an interruption occur for a period of more than: (select one range)
<$20,0 $20,0 $50,000 $100,000 $250,000
00 00 to<$100,0 to or more
to< 00 <$250,000
$50,0
00
1 business day
2 business days
3 business days
4 business days
5 business days
2 weeks
3 weeks
4 weeks
2 months
3 months

Dependencies
List key functions that define the functionality of this business unit/cost center.
Identify input, source, input frequency (F1), how manipulated, output, recipient, and
output frequency (F2) for each.
Frequency (F): H Hourly W
Weekly Q
Quarterly
D Daily M Monthly A Annually

Functio Input Source F1 Manipula Output Recipi F2


n ted ent

Identify any networks (LAN, intranet, or Internet) or network-based applications or


data sources the business areas depends on:
Network Application/data source

Identify any service bureaus or external vendors the business areas depends on:
SB/vendor Purpose
Part II: Functional Impact
This questionnaire must be filled out for each major function within ABC Co.

Function:
Business area:
Department:
Senior manager:
Functional manager:
Overall functional priority (to be added
by CPMT):
Date of BIA questionnaire:
Questionnaire completed by:
Function Description: Describe the processes necessary to support the function:
Function Deliverables: Describe the output of this function as it supports the
organization:

Dependencies:

Input:
From what process does this function receive input to initiate its process? Include
source name, location, and method of receipt.

What effect is there on this function if the input were not available?

What work-around is required to continue this function?

Output:
What process receives the deliverable from this function? Include client name,
location, and method of receipt.

What effect is there on the client if this function were not available?

Resources:
What personnel resources are required to support this function?

What internal information is needed to support this function?

What external information is needed to support this function?

What application(s) is/are used by this function, and who provides support?

What application(s) is/are used by this function, and who provides support?

What network resource(s) is/are used by this function, and who provides support?
Impact:
For each of the following items, rate the functions impact on the corresponding
criteria:

1 (no 2 (low) 3 4 (high) 5 (very


impact) (moderate) high)
Activity:
Additional
expense:
Assets:
Revenue loss per
day:
Productivity loss
per day:
Customer service:
Goodwill:
Regulatory/legal:

For each of the following activities, identify the extent to which the corresponding procedure
or plan is implemented for this function:
Activity None exist Present but Implemente Rehearsed Fully
not d but not but not implemente
implemente rehearsed tested d,
d rehearsed,
and tested
Manual Procedures
Briefly describe the manual procedures for this function:
Risk Mitigation Plans
Briefly describe the risk mitigation plans for this function:
Incident Response
Plans
Briefly describe the incident response plans for this function:
Disaster Recovery
Plans
Briefly describe the disaster recovery plans for this function:
Business Continuity
Plan
Briefly describe the business continuity plans for this function:
What is the estimated recovery time objective (RTO) for this function (time after interruption
before operations are critically impacted)?
[ ] Tier 1 (024 hours) [ ] Tier 2 (2448 hours)
[ ] Tier 3 (4872 hours) [ ] Tier 4 (7296 hours)
What is the estimated recovery point objective (RPO) for this function (point in time by
which function must be recovered to support operations)?
[ ] Point 1 (less than 6 hours) [ ] Point 2 (less than 1 business day)
[ ] Point 3 (less than 2 business days) [ ] Point 4 (less than 3 business days)
[ ] Point 5 (3 or more business days)
Interdependencies
What is the relative importance of the following support functions to maintain this function
in the event of a
Support Function Not Somewhat Important Very Extremely
important important important important
Telephones
Cell phones
Fax
Radio
Data network
Other network
Wireless data
Internet
Intranet
Other: ____________
Other: ____________

What interdependencies exist between this function and each of the following
functions?
Supply chain
Environmental health & safety
Human resources
Major vendors & suppliers
Major vendors & suppliers
Do your current IR/DR/BC plans have recovery strategies that meet your RTO for
this function?

Does this function include an


emergency response plan?
Date of last BIA assessment:
Have there been any changes to the business function since your last BIA
assessment? If so describe:

You might also like