• Menu
  • Skip to right header navigation
  • Skip to main content
  • Skip to secondary navigation
  • Skip to primary sidebar
  • Skip to footer

Before Header

Bryghtpath

Business Continuity and Crisis Management Consultants

  • About
        • About Bryghtpath

        • Our Core Values

        • Meet our Team

        • About Bryghtpath
          • Case Studies & Results
          • Certifications and Awards
          • Contact Bryghtpath
          • Contract Vehicles
          • Media & Professional Appearances
          • Our Clients
          • Our Proven Process
          • Security & Compliance
          • Strategic Partners
          • Work with Us
  • Capabilities
        • Our Capabilities
        • We help your organization strategically navigate uncertainty and disruption.

        • Case Studies & Results

        • Business Continuity as a Service

        • Business Continuity
          • Business Continuity - Overview
          • Business Continuity as a Service (BCaaS)
          • Business Continuity Software
          • Coaching
          • IT Disaster Recovery
          • Resiliency Diagnosis®️
        • Crisis Management
          • Crisis Management - Overview
          • Crisis Communications
          • Crisis Exercises
          • Cyber Crisis Exercises
          • Cyber Incident Response Planning
          • Crisis Playbook®️
          • Global Security Operations Center (GSOC)
          • Resiliency Diagnosis®️
        • Other Capabilities
          • Coaching
          • Intelligence & Global Security Consulting
          • Speaking
          • Training
        • Case Studies & Results
        • Industries
  • Insights
  • Products
        • Our Products

          College Classroom - Mature Teacher
        • Crisis Playbook™️

        • Exercise in a Box™️

        • Exercise in a Day™️

        • Books
          • From Panic to Poise: Crisis Management in the Modern World
          • The Continuity Code: Mastering Business Resilience
        • Crisis Playbook™️
          • Overview
          • Active Shooter Plan
          • Emergency Response Guide
          • Fatality
          • Food/Product Recall
          • Protest
          • Violent Attack
        • Maturity Models
          • Overview
          • ASIS Workplace Violence and Active Assailant
          • FFEIC Maturity Model – Business Continuity
          • ISO 22301 – Business Continuity
          • ISO 22361 – Crisis Management
          • ISO 27031 - IT Disaster Recovery
          • NIST 800-53 Contingency Planning Maturity Model
        • Templates & More
          • After-Action Process & Templates
          • Awareness Collateral
          • Business Continuity Plan Templates
          • Crisis Management Plan Templates
          • Disaster Recovery Plan Templates
          • Job Descriptions
  •  

Mobile Menu

  • About
    • About Bryghtpath
      • Case Studies & Results
      • Certifications and Awards
      • Contact Bryghtpath
      • Contract Vehicles
      • Media & Professional Appearances
      • Our Clients
      • Our Proven Process
      • Security & Compliance
      • Strategic Partners
      • Work with Us
  • Capabilities
    • Our Capabilities
    • Business Continuity
      • Business Continuity – Overview
      • Business Continuity as a Service (BCaaS)
      • Business Continuity Software
      • Coaching
      • IT Disaster Recovery
      • Resiliency Diagnosis®️
    • Crisis Management
      • Crisis Management – Overview
      • Crisis Communications
      • Crisis Exercises
      • Cyber Crisis Exercises
      • Cyber Incident Response Planning
      • Crisis Playbook®️
      • Global Security Operations Center (GSOC)
      • Resiliency Diagnosis®️
    • Other Capabilities
      • Coaching
      • Intelligence & Global Security Consulting
      • Speaking
      • Training
    • Case Studies & Results
    • Industries
  • Insights
  • Products
    • Books
      • From Panic to Poise: Crisis Management in the Modern World
      • The Continuity Code: Mastering Business Resilience
    • Crisis Playbook™️
      • Overview
      • Active Shooter Plan
      • Emergency Response Guide
      • Fatality
      • Food/Product Recall
      • Protest
      • Violent Attack
    • Maturity Models
      • Overview
      • ASIS Workplace Violence and Active Assailant
      • FFEIC Maturity Model – Business Continuity
      • ISO 22301 – Business Continuity
      • ISO 22361 – Crisis Management
      • ISO 27031 – IT Disaster Recovery
      • NIST 800-53 Contingency Planning Maturity Model
    • Templates & More
      • After-Action Process & Templates
      • Awareness Collateral
      • Business Continuity Plan Templates
      • Crisis Management Plan Templates
      • Disaster Recovery Plan Templates
      • Job Descriptions
  •  

A look at the new ISO 22317 Standard for Business Impact Analysis (BIA)

You are here: Home / Business Continuity / A look at the new ISO 22317 Standard for Business Impact Analysis (BIA)
business continuity images

March 14, 2016 By //  by Bryan Strawser

In September 2015, ISO finalized and published their second standard for business continuity: ISO 22317:2015 – Guidelines for Business Impact Analysis (BIA).

In the life cycle of your business, leveraging a systematic business continuity process can mean the difference between a safety net and disaster.

ISO 22317 analyzes from within

Getting to the heart of business continuity analysis, planning and execution involve working from within — developing a deep understanding of your organization, its products, and its processes.

How to document all of that information, achieve management buy-in, and come up with the best Business Impact Analysis (BIA), is what ISO 22317 is all about.

How ISO 22317 relates to ISO 22301

Somewhat of a stepchild as well as a stand-alone nephew of ISO 22301, ISO 22317 is the “how-to” part of ISO 22301 guidance for the Business Impact Analysis process, which says an organization needs to do the following:

  • identify activities supporting how a business provides products and services
  • assess how not performing those products and services over time will impact the organization
  • set priorities and timeframes for resuming business at a minimum acceptable level
  • identify the connection and dependencies between supporting resources for the impacted business activities

Purpose and scope of ISO 22317

So ISO 22317 is a new technical specification designed to complement ISO 22301. It can, however, be a “stand-alone” standard. The BIA processes analyzes the actual consequences of a “disruptive incident” on the organization.

Its specific purposes are to:

  • be the basis for continually improving the organization’s BIA–It specifies ongoing review and event-triggered activities.
  • guide the organization in planning, conducting, and reporting on BIA–This is where the “how-to” part of ISO 22301 comes in.
  • assist the organization in its BIA in a consistent manner reflecting good practices–ISOs are all about agreed and “good” practices.
  • open the door to proper coordination between BIA and the overarching business continuity (BC) program–BC planning, as we pointed out in our previous blog is an integrated process; BIA is at its center.

5 impact areas of your business that ISO 22317 analyzes

The following are 5 areas of any business that ISO 2317 addresses:

1. Financial–losses due to lost profits, diminished market share, fines, penalties, etc.

2. Reputational–Damage to the brand or negative public opinion

3. Legal and Regulatory–loss of license or litigation liability with a need of DVLA feedback.

4.  Contractual–breach of contract or service obligation with other organizations

5. Business Objectives–going “dead in the water” by failure to deliver on objectives and take advantage of opportunities.

Outcomes of ISO 22317

The goal of ISO 22317 is to address the foregoing and other consequences of business disruption. Its goals are to both promote and ensure the following:

  • imprinting (endorsing) or modifying the overall scope of the organization’s business continuity program
  • focusing and identifying governing obligations–legal, contractual, etc.–that justify going to the trouble of doing all this in the first place (The requirement for business continuity planning is the law of the land for many types of business.)
  • setting a timeframe and priority for restoring the business after a disruptive incident
  • identifying and articulating the relationships between everything the business does: products/services, processes, activities, and resources
  • determining the people, facilities, equipment, etc., needed to do what is necessary to get the business up and running after the disaster
  • taking into account the dependencies on other factors–activities, supply chains, partners, etc.
  • knowing how recent and up to date all that information must be

The value of BIA

Stated another way, the value of BIA is that it ensures the most cost-effective strategies by focusing on the correct business continuity requirements. Moreover, BIA provides evidence to company managers that business continuity aligns with organizational objectives and strategies.

Finally, BIA identifies the connection between products and services and the process, activities, and resources that the company needs to employ to keep going.

Monitoring and Reviewing the BIA

ISO 22317 specifies BIA monitoring on a periodic basis, or when triggered by events such as product or service change, regulatory change, change in company structure, or following a business continuity exercise or disruptive event.

Conclusions

  • ISO 22317 has flexible guidelines for any type of business in the performance of a BIA process.
  • ISO 22317 is consistent with ISO 22301, and it can stand alone as the basis for BIA.
  • ISO 22317 gives your business the ability to identify business continuity requirements, which matter to your organization and its stakeholders

3hzKqKBM_2OH79EsrklydIaKkL961qCj7Z3pxvH5UdmxaZibFN4SQh1X6HkJ7XU5nbQLq67Uib8Pr5ti-BCpHw=s0 A look at the new ISO 22317 Standard for Business Impact Analysis (BIA)

We can help

Do you need advice or guidance in your business continuity planning or implementing ISO 22317 as a part of your business continuity program?

We can help. Learn more about our approach to Business Continuity in our Ultimate Guide to Business Continuity and then contact us today.

Category: Business ContinuityTag: bcm, bcms, bia, Bryan Strawser, Business Continuity, business continuity management, business impact analysis, iso 22301, iso 22317, iso22301, iso22317

About Bryan Strawser

Bryan Strawser is Founder, Principal, and Chief Executive at Bryghtpath LLC, a strategic advisory firm he founded in 2014. He has more than twenty-five years of experience in the areas of, business continuity, disaster recovery, crisis management, enterprise risk, intelligence, and crisis communications.

At Bryghtpath, Bryan leads a team of experts that offer strategic counsel and support to the world’s leading brands, public sector agencies, and nonprofit organizations to strategically navigate uncertainty and disruption.

Learn more about Bryan at this link.

Previous Post: «Zika Virus Mosquito The Zika Virus: 8 Steps a Business Should Take Today
Next Post: Why Your Company Needs Strong Workplace Violence Policies Workplace-Violence-Prevention-Web»

Primary Sidebar

Article Categories

  • Active Shooter Programs
  • Bryghtpath Live
  • Business Continuity
  • Crisis Communications
  • Crisis Management
  • Crisis Playbook
  • Cybersecurity
  • Disaster Recovery
  • Emergency Planning & Exercises
  • Information Security
  • Inside Bryghtpath
  • Intelligence & Global Security
  • Journal Articles
  • Managing Uncertainty Podcast
  • Media Mentions
  • Opinion
  • Organizational Resilience
  • Presentations
  • Press Releases
  • Public Health
  • Public/Private Partnerships
  • Publications
  • Speaking
  • Training
  • Uncategorized
  • Webinars
  • Whitepapers
  • Workplace Violence

Footer

Contact

BRYGHTPATH LLC
+1.612.235.6435

PO Box 131416
Saint Paul, MN 55113
USA


contact@bryghtpath.com

  • Facebook
  • LinkedIn
  • RSS
  • Twitter
  • YouTube

Our Capabilities

  • Business Continuity
    • Business Continuity as a Service (BCaaS)
    • Business Continuity Software
    • Coaching
    • IT Disaster Recovery Consulting Services
    • Resiliency Diagnosis®️
  • Crisis Communications
  • Crisis Management
    • Crisis Exercises
    • Cyber Crisis Exercises
    • Cyber Incident Response Planning
    • Global Security Operations Center (GSOC)
  • Speaking
  • Training

Our Free Courses

Business Continuity 101

Crisis Communications 101

Crisis Management 101

Our Products

After-Action Templates

Books

Business Continuity Plan Templates

Communications & Awareness Collateral Packages

Crisis Plan Templates

Crisis Playbook®

Disaster Recovery Templates

Exercise in a Box®

Exercise in a Day®

Maturity Models

Ready-Made Crisis Plans

Resilience Job Descriptions

Pre-made Processes & Templates

Site Footer

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.


Bryghtpath®, Crisis Management Academy®, Crisis Playbook®, Exercise in a Box®, Exercise in a Day®, Resiliency Diagnosis®, Resilience Operating Model®
and their respective logos are registered trademarks of Bryghtpath LLC in the United States and other countries.


About Bryghtpath LLC | Disclaimer | Privacy | Status Page | Terms of Use

Proudly powered by Mai Theme, the Genesis Framework, and Wordpress.