ISO 22301:2019
Operation, ISO 22301:2019

ISO 22301:2019 8.2.2: Business impact analysis

Use the impact analysis to set continuity priorities and requirements: settle which types of impact matter in the organization's context and the criteria for judging them; identify the activities that support delivery of products and services; assess how the impact of disrupting those activities grows over time; fix the point beyond which failing to resume would be unacceptable; within that point, set prioritized time frames for resuming the activities at a stated minimum capacity that is still acceptable; identify the prioritized activities; and establish the resources, dependencies and interdependencies they need, partners and suppliers included.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 74 controls across 31 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-DE.AE-04 The estimated impact and scope of adverse events are understood
  • NIST-CSF-GV.OC-04 Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
  • NIST-CSF-GV.OC-05 Outcomes, capabilities, and services that the organization depends on are understood and communicated
  • NIST-CSF-ID.AM-05 Assets are prioritized based on classification, criticality, resources, and impact on the mission
  • NIST-CSF-ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
  • NIST-CSF-RC.RP-02 Recovery actions are selected, scoped, prioritized, and performed
  • NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared

NIST SP 800-53 Rev 5 · 7 controls

ISO 27001:2022 · 6 controls

  • 5.24 Information security incident management planning and preparation 
  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity
  • 5.34 Privacy and protection of personal identifiable information (PII)
  • 5.9 Inventory of information and other associated assets
  • 8.13 Information backup

SOC 2 · 5 controls

  • SOC2-A1.1 A1.1 Managing processing capacity
  • SOC2-A1.3 A1.3 Testing recovery plan procedures
  • SOC2-CC3.1 CC3.1 Objectives specified clearly enough to assess risk (COSO principle 6)
  • SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7)
  • SOC2-CC9.1 CC9.1 Mitigating risks of business disruption
  • CPS230-19 Tolerance Levels for Each Critical Operation
  • CPS230-26 Critical Operations Register, Continuity Plan and Activation
  • CPS230-P27 Comprehensive Assessment of the Operational Risk Profile
  • 37 Para 37 Tolerance levels for each critical operation

FedRAMP High · 4 controls

  • CP-2 Contingency Plan
  • CP-2(8) Contingency Plan | Identify Critical Assets (CP-2(8))
  • RA-2 Security Categorization
  • RA-9 Criticality Analysis (RA-9)

FedRAMP Moderate · 4 controls

  • CP-2 Contingency Plan
  • CP-2(8) Contingency Plan | Identify Critical Assets (CP-2(8))
  • RA-2 Security Categorization
  • RA-9 Criticality Analysis (RA-9)

PCI DSS 4.0 · 4 controls

  • 1.2.3 1.2.3 Accurate network diagram of CDE connections
  • 1.2.4 1.2.4 Accurate data-flow diagram for account data
  • 12.5.3 12.5.3 Scope review after significant organisational change
  • 12.8.1 12.8.1 List of third-party service providers

CIS Controls v8 · 3 controls

  • CIS-11.1 Establish and Maintain a Data Recovery Process
  • CIS-12.4 Establish and Maintain Architecture Diagram(s)
  • CIS-15.1 Establish and Maintain an Inventory of Service Providers

HIPAA Security Rule · 3 controls

NIST SP 800-66 Rev 2 · 3 controls

ISO 27002:2022 · 2 controls

  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity

ISO 28002:2011 · 2 controls

  • 4.2.2 4.2.2 Specific factors showing commitment to risk and resilience management
  • A.4.1 A.4.1 Risk assessment and monitoring
  • NFPA1600-05 Business Impact Analysis
  • NFPA1600-5.2 Business Impact Analysis
  • E8-BACKUP-ML1 Regular Backups (ML1)
  • 5.2.9 5.2.9 Business continuity personnel

APRA CPS 234 · 1 control

  • CPS234-20 Information Asset Classification

C5 (Germany) · 1 control

  • C5-BCM-02 Business impact analysis policies and instructions
  • CFTC-SS-23 Resources Sufficient to Fulfil Obligations

COBIT 2019 · 1 control

  • BAI04.02 BAI04.02 Assess business impact
  • EBA-GL-3.7.1 Business impact analysis
  • ISO-22313-8.2 Business impact analysis and risk assessment

ISO 22316 · 1 control

  • ISO22316-06 Business impact analysis methodology

ISO 27701:2019 · 1 control

  • 8.2.2 Organization’s purposes

ISO 9001:2015 · 1 control

  • 8.2.2 Determining the requirements for products and services

ISO/IEC 27031:2011 · 1 control

  • 27031-6.2 Business Impact Analysis for ICT

ISO/TS 22317:2021 · 1 control

  • ISO22317-06 Business impact analysis methodology

ISO/TS 22318:2021 · 1 control

  • ISO22318-06 Business impact analysis methodology

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Operation, ISO 22301:2019

You are reading one control. How much of ISO 22301:2019 have you already done?

ISO 22301:2019 8.2.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 22301:2019 your existing evidence covers. Hold APRA CPS 230 Operational Risk Management and 28 of 57 ISO 22301:2019 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the APRA CPS 230 Operational Risk Management pair alone.

Query this from an agent

The graph holds this control, the 74 it maps to, and the evidence behind each claim, over MCP and REST.