NIST Special Publication 800-34 Revision 1, Contingency Planning Guide for Federal Information Systems
Business Impact Analysis

NIST Special Publication 800-34 Revision 1, Contingency Planning Guide for Federal Information Systems NISTSP34-2: Business Impact Analysis (BIA): Critical Resources, Recovery Priorities

Conduct Business Impact Analysis per NIST SP 800-34 Rev 1 Section 3.2 + Appendix B (Sample BIA Template). BIA identifies and prioritises information systems and components critical to supporting the organisations mission/business processes. BIA must (a) determine mission/business processes and recovery criticality per Section 3.2.1: identify the systems supporting each mission/business process + the impact of disruption + recovery time objective (RTO) + recovery point objective (RPO) + maximum tolerable downtime (MTD) per process, (b) identify resource requirements per Section 3.2.2: hardware + software + data + facilities + personnel + supplier dependencies + external service providers + critical records + telecommunications, (c) identify system resource recovery priorities per Section 3.2.3: order systems by criticality with documented rationale + alignment with FIPS 199 security categorisation + organisational risk tolerance. BIA output feeds Contingency Strategy Development (NISTSP34-3) + IT Contingency Plan Development (NISTSP34-4). Review BIA annually + after significant change.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.