Identify Necessary Policies for Business Continuity—BIA and

Assessment Worksheet
59
LAB #7 – ASSESSMENT WORKSHEET
Identify Necessary Policies for Business Continuity—BIA and
Recovery Time Objectives
Course Name and Number:
Student Name:
Instructor Name:
Lab Due Date:
Overview
The purpose of a business impact analysis (BIA) is to assess and align affected IT systems, applications, and
resources to their required recovery time objectives (RTOs). The prioritization of the identified mission-critical
business functions defines what IT systems, applications, and resources are impacted. The RTO drives the
type of business continuity and recovery steps needed to maintain IT operations in specified time frames. The
business continuity plan (BCP) outlines these steps so that operations may continue when mission-critical
functions are at risk or jeopardized. In this lab, you identified the elements of a BCP, you reviewed the results
of a BIA and RTOs, and you created a BCP.
1. Why must an organization define policies for its business continuity and disaster recovery plans?
Identify Necessary Policies for
Business Continuity—BIA and
Recovery Time Objectives
Lab Assessment Questions & Answers
7
2. When should you define a policy and when should you not define one?
38375_LMxx_Lab07.indd 59
9/20/12 6:00 PM
60
LAB #7 | Identify Necessary Policies for Business Continuity—BIA and Recovery Time Objectives
3. What is the purpose of having a BCP policy definition that defines the organization’s BIA?
4. Why is it critical to align the RTO and RPO standards within the policy definition itself?
5. What is the purpose of a BIA?
6. Why is a BIA an important first step in defining a BCP?
7. How do risk management and risk assessment relate to a business impact analysis for an IT
infrastructure?
8. True or false: If the recovery point objective (RPO) metric is not the same as the recovery time objective
(RTO), you may potentially lose data or not have data backed up to recover. This represents a gap in
potential lost or unrecoverable data.
38375_LMxx_Lab07.indd 60
9/20/12 6:00 PM
Assessment Worksheet
61
9. Why should organizations update their BCP, BIA, RTOs, and RPOs?
10. For the sample BIA, which systems, applications, and functions were mission-critical to this organization?
7
Identify Necessary Policies for
Business Continuity—BIA and
Recovery Time Objectives
38375_LMxx_Lab07.indd 61
9/20/12 6:00 PM
38375_LMxx_Lab07.indd 62
9/20/12 6:00 PM