Benchmark - Business Impact Analysis and Resource Profile
Submission Ide: 7306c67e-a20f-4e88-b33a-2753ae0c5dc7
60% SIMILARITY SCORE 8 CITATION ITEMS 31 GRAMMAR ISSUES 0 FEEDBACK COMMENT Internet Source 0% Institution 60%
Felicitas Amana
Benchmark - Business Impact Analysis and Resource Profile
Summary
1499 Words
© 2021. Grand Canyon University. All Rights Reserved.
Business Impact Analysis 1. Overview This business impact analysis (BIA) was developed as part of the contingency planning process for the Apple Inc. It was prepared by Felicitas Amana.
1.1 Purpose The purpose of the BIA is to identify and prioritize system components by correlating them to the mission/business process(es) the system supports and using this information to characterize the impact on the process(es) if the system were unavailable. The BIA is composed of the following three steps:
1. Determine mission/business processes and recovery criticality. Mission/Business processes supported by the system are identified, and the impact of a system disruption to those processes is determined along with outage impacts and estimated downtime. The downtime should reflect the maximum that an organization can tolerate while still maintaining the mission.
2. Identify resource requirements. Realistic recovery efforts require a thorough evaluation of the resources required to resume mission/business processes and related interdependencies as quickly as possible. Examples of resources that should be identified include facilities, personnel, equipment, software, data files, system components, and vital records.
3. Identify recovery priorities for system resources. Based upon the results from the previous activities, system resources can more clearly be linked to critical mission/business processes. Priority levels can be established for sequencing recovery activities and resources.
This document is used to build the information system contingency plan (ISCP) and is included as a key component of the ISCP. It also may be used to support the development of other contingency plans associated with the system, including, but not limited to, the disaster recovery plan (DRP) or cyber incident response plan.
2. System Description Considering this firm operates as the second-largest Information technology firm, its system allows it to determine how its business operations, from research to production to supply, and distribution are conducted. The firm's information system is categorized into five different types: iCloud services system, transaction process system, supplier information database system, management information system, decision support system. These systems perform collectively to ensure that the firm's everyday operations are conducted smoothly and safely recorded for future use (Luo. et al., 2018). The organization's information system ensures that the firm can benefit
from offering the best customer service by using a reliable and efficient system. As a result, the firm increases its competitive advantage and its profitability.
3. BIA Data Collection
Student: Submitted to Grand Canyon University
Student: Submitted to Grand Canyon University
Spelling mist...: interdependen... inter depende...
Possibly demeaning adverb: clearly
Spelling mistake: iCloud cloud
Checks that a sentence starts with ...: et Et
Student: Submitted to Grand Canyon University
2
3.1 Determine Process and System Criticality Working with input from users, managers, mission/business process owners, and other internal or external points of contact (POC), identify the specific mission/business processes that depend on or support the information system.
Mission/Business Process Description
Pay vendor invoice Process of obligating funds, issuing a check or electronic payment, and acknowledging receipt
Managing information system Process of searching for data, recording, and keeping the data in a safe cloud
Making corporate decisions Process of making decisions by collecting data and analyzing it to fit the firm in the best way
Office automation Process of connecting with the branches of the firm, transferring company data through the geographically separate location
3.1.1 Identify Outage Impacts and Estimated Downtime If Apple Inc experienced an outage in managing the information system, the company workers would be unable to collect clients' data. It would be a horrific experience where the firm would risk losing clients' data. Such an occurrence can result in loss of income since transactions would not be conducted. In addition, the consumers would not be able to trust the firm, and thus their loyalty would be eroded.
If the system of making company decisions had an outage, the managers of the firm’s branches and the executives would have a hard time determining the best ways of conducting their operations. It would hinder the production process causing low supply. The outcome would be higher costs of production and reduced profitability.
If the office automation system had a problem, all the firm branches would be required to work independently. Therefore, there would be inconsistencies in the production processes causing the firm to have additional production costs in some of its branches. The leaders' decisions would not be applied in the branches which are located in different areas. Outage Impacts The following impact categories represent important areas for consideration in the event of a disruption or impact. Impact category: Additional Cost (expenses)
Customer Loyalty (trust) Loss of Revenue (income) Regulatory or Legal Ramifications (penalties) Impact values for assessing category impact: Severe Moderate Minimal
The table below summarizes the impact on each mission/business process, if unavailable, based on the following criteria:
Impact Category Mission/Business Process
Expenses Trust Income Penalty ∑ Impact Pay vendor invoice Minimal Moderate Minimal Minimal Moderate
Managing information system Moderate Severe Severe Severe Severe
Making corporate decisions Moderate Minimal Moderate Moderate Moderate
Office automation Moderate Minimal Minimal Moderate Moderate
Estimated Downtime Working directly with mission/business process owners, departmental staff, managers, and other stakeholders, estimate the downtime factors for consideration because of a disruptive event.
• Maximum Tolerable Downtime (MTD): The MTD represents the total amount of time leaders/managers are willing to accept for a mission/business process outage or disruption and includes all impact considerations. Determining MTD is important because it could leave continuity planners with imprecise direction on (1) selection of an appropriate recovery method, and (2) the depth of detail that will be required when developing recovery procedures, including their scope and content.
• Recovery Time Objective (RTO): RTO defines the maximum amount of time that a
Student: Submitted to Grand Canyon University
in the event of, in th...: in the event of if
Word repetition: Minimal Minimal Minimal
Duplicated ph...: Severe Sever... Severe Severe
Word repetition: Moderate Modera... Moderate
Word repetition: Minimal Minimal Minimal
Word repetition: Moderate Modera... Moderate
Student: Submitted to Grand Canyon University
Use an m-dash.: - —
Use an m-dash.: – —
Example Impact Category = Cost
▪ Severe - temporary staffing, overtime, fees are greater than $1 million
▪ Moderate – fines, penalties, liabilities potential $550,000
▪ Minimal – new contracts, supplies $75,000
3
system resource can remain unavailable before there is an unacceptable impact on other system resources, supported mission/business processes, and the MTD. Determining the information system resource RTO is important for selecting appropriate technologies that are best suited for meeting the MTD.
• Recovery Point Objective (RPO ): The RPO represents the point in time, prior to a disruption or system outage, to which mission/business process data must be recovered (given the most recent backup copy of the data) after an outage.
4
The table below identifies the MTD, RTO, and RPO (as applicable) for the organizational mission/business processes.
Values for MTDs and RPOs are expected to be specific timeframes, identified in hourly increments (e.g., 8 hours, 36 hours, 97 hours).
Mission/Business Process MTD RTO RPO
Pay vendor invoice 72 hours 48 hours 12 hours (last backup)
Managing information system 6 hours 3 hours 24 hours (last backup)
Making corporate decisions 72 hours 12 hours 24 hours (last backup)
Office automation 48 hours 12 hours 24 hours (last backup)
The managing information system is essential in the day-to-day operations of the firm. A lot of workloads would accumulate, and the performance of the firm would have been affected immensely. For this reason, the outage would take a few hours before reaching the maximum time for the situation to be tolerated. The vast workload would require a lot of time to recover to ensure optimal performance is restored. The firm officials make decisions very often, but they would stay about three days without hindering the firm's operations. Moreover, recovering from this outage would take about 12 hours to record all those data since the workload would not be huge (Aleksandrova. et al.,2018). Office automation operations can last to 48 hours since most of the workload of each branch office can be stored locally for a longer time before being uploaded to the headquarter of the company. It would take around 12 hours to recover and start normal operations since all the office-related workload will be uploaded into the mainstream system. 3.2 Identify Resource Requirements The following table identifies the resource requirements including hardware, software, and other resources, such as data files.
System Resource/Component Platform/OS/Version (as applicable) Description
Web Server 1 OptiPlex GX280 Website Host
Webserver 1 Mac OS server Website host
Operating system 1 Sourcebook Website Host
Operating system 2 Linux Operating system
Use an m-dash.: – —
Student: Submitted to Grand Canyon University
Spelling mistake: MTDs Mods
Spelling mistake: RPOs Rios
Passive voice: are expected to be
Spelling mistake: timeframes time frames
Passive voice: have been affected
Spelling mistake: Aleksandrova
Checks that a sentence starts with ...: et Et
a/the + infinitive: the headquarter
Student: Submitted to Grand Canyon University
Spelling mistake: Webserver Web server
Spelling mistake: Sourcebook Coursebook
Spelling mistake: Webserver Web server
Word repetition: database Databas... database
Webserver 2 CentOS Website host
Database 1 OLAP database
Database 2 Data Marts Database
Wireless connection LTE networks Network device
End-user network CDN apple Network device
5
Spelling mistake: Webserver Web server
Word repetition: database datab... database
Spelling mistake: iCloud cloud
Passive voice: It is assumed that
Student: Submitted to Grand Canyon University
Spelling mistake: Webserver Web server
Spelling mistake: Sourcebook Coursebook
Webserver 3 SMB apple Website host
Webpage 1 Tumblr Web page
Database Supplier information
database database
Data keeping iCloud Cloud system
It is assumed that all identified resources support the mission/business processes identified in Section 3.1 unless otherwise stated.
3.3 Identify Recovery Priorities for System Resources The table below lists the order of recovery for OptiPlex GX280 resources. The table also identifies the expected time for recovering the resource following a “worst case” (complete rebuild/repair or replacement) disruption. Recovery Time Objective (RTO ): RTO defines the maximum amount of time that a system resource can remain unavailable before there is an unacceptable impact on other system resources, supported mission/business processes, and the MTD. Determining the information system resource RTO is important for selecting appropriate technologies that are best suited for meeting the MTD.
Priority System Resource/Component Recovery Time Objective
Web Server 1 OptiPlex GX280 24 hours to rebuild or replace
Database 1 OLAP 24 hours to rebuild
Wireless
connection LTE networks 12 hours to rebuild
Webserver 1 Mac OS server 12 hours to rebuild
End-user network CDN apple 12 hours to rebuild
Operating system
1 Sourcebook 12 hours to rebuild
A system resource can be software, data files, servers, or other hardware and should be identified individually or as a logical group.
6