What methodology is commonly used in Business Continuity Program?

A.
Work Group Recovery
B.
Business Impact Analysis
C.
Qualitative Risk Analysis
D.
Quantitative Risk Analysis
Explanation:
A BIA is performed at the beginning of disaster recovery and continuity planning to
identify the areas that would suffer the greatest financial or operational loss in the event of a
disaster or disruption. It identifies the company’s critical systems needed for survival and
estimates the outage time that can be tolerated by the company as a result of disaster or
disruption. – Shon Harris All-in-one CISSP Certification Guide pg 597
The correct answer is Quantitative Risk Assessment/Analysis. The quote from Shon Harris book is out of context here. BIA is the first step in BCP but its results go into the Risk Analysis and the results of the RA formulate the BCP. So while BIA is the 1st step it is NOT the whole methodology..
0
0