Benchmark - Business Impact Analysis and Resource Profile

profileLoic@1313
ReportPDFSimilarityScore-60.pdf

Submission Ide: 7306c67e-a20f-4e88-b33a-2753ae0c5dc7

60% SIMILARITY SCORE 8   CITATION ITEMS 31   GRAMMAR ISSUES 0   FEEDBACK COMMENT Internet Source   0% Institution   60%

Felicitas Amana

Benchmark - Business Impact Analysis and Resource Profile

Summary

 1499 Words  

© 2021. Grand Canyon University. All Rights Reserved.

Business Impact Analysis 1. Overview This business impact analysis (BIA) was developed as part of the contingency planning process for the Apple Inc. It was prepared by Felicitas Amana.

1.1 Purpose The purpose of the BIA is to identify and prioritize system components by correlating them to the mission/business process(es) the system supports and using this information to characterize the impact on the process(es) if the system were unavailable. The BIA is composed of the following three steps:

1. Determine mission/business processes and recovery criticality. Mission/Business processes supported by the system are identified, and the impact of a system disruption to those processes is determined along with outage impacts and estimated downtime. The downtime should reflect the maximum that an organization can tolerate while still maintaining the mission.

2. Identify resource requirements. Realistic recovery efforts require a thorough evaluation of the resources required to resume mission/business processes and related interdependencies as quickly as possible. Examples of resources that should be identified include facilities, personnel, equipment, software, data files, system components, and vital records.

3. Identify recovery priorities for system resources. Based upon the results from the previous activities, system resources can more clearly be linked to critical mission/business processes. Priority levels can be established for sequencing recovery activities and resources.

This document is used to build the information system contingency plan (ISCP) and is included as a key component of the ISCP. It also may be used to support the development of other contingency plans associated with the system, including, but not limited to, the disaster recovery plan (DRP) or cyber incident response plan.

2. System Description Considering this firm operates as the second-largest Information technology firm, its system allows it to determine how its business operations, from research to production to supply, and distribution are conducted. The firm's information system is categorized into five different types: iCloud services system, transaction process system, supplier information database system, management information system, decision support system. These systems perform collectively to ensure that the firm's everyday operations are conducted smoothly and safely recorded for future use (Luo. et al., 2018). The organization's information system ensures that the firm can benefit

from offering the best customer service by using a reliable and efficient system. As a result, the firm increases its competitive advantage and its profitability.

3. BIA Data Collection

 Student: Submitted to Grand Canyon University

 Student: Submitted to Grand Canyon University

 Spelling mist...: interdependen...  inter depende...

 Possibly demeaning adverb: clearly

 Spelling mistake: iCloud  cloud

 Checks that a sentence starts with ...: et  Et

 Student: Submitted to Grand Canyon University

2

3.1 Determine Process and System Criticality Working with input from users, managers, mission/business process owners, and other internal or external points of contact (POC), identify the specific mission/business processes that depend on or support the information system.

Mission/Business Process Description

Pay vendor invoice Process of obligating funds, issuing a check or electronic payment, and acknowledging receipt

Managing information system Process of searching for data, recording, and keeping the data in a safe cloud

Making corporate decisions Process of making decisions by collecting data and analyzing it to fit the firm in the best way

Office automation Process of connecting with the branches of the firm, transferring company data through the geographically separate location

3.1.1 Identify Outage Impacts and Estimated Downtime If Apple Inc experienced an outage in managing the information system, the company workers would be unable to collect clients' data. It would be a horrific experience where the firm would risk losing clients' data. Such an occurrence can result in loss of income since transactions would not be conducted. In addition, the consumers would not be able to trust the firm, and thus their loyalty would be eroded.

If the system of making company decisions had an outage, the managers of the firm’s branches and the executives would have a hard time determining the best ways of conducting their operations. It would hinder the production process causing low supply. The outcome would be higher costs of production and reduced profitability.

If the office automation system had a problem, all the firm branches would be required to work independently. Therefore, there would be inconsistencies in the production processes causing the firm to have additional production costs in some of its branches. The leaders' decisions would not be applied in the branches which are located in different areas. Outage Impacts The following impact categories represent important areas for consideration in the event of a disruption or impact. Impact category: Additional Cost (expenses)

Customer Loyalty (trust) Loss of Revenue (income) Regulatory or Legal Ramifications (penalties) Impact values for assessing category impact: Severe Moderate Minimal

The table below summarizes the impact on each mission/business process, if unavailable, based on the following criteria:

Impact Category Mission/Business Process

Expenses Trust Income Penalty ∑ Impact Pay vendor invoice Minimal Moderate Minimal Minimal Moderate

Managing information system Moderate Severe Severe Severe Severe

Making corporate decisions Moderate Minimal Moderate Moderate Moderate

Office automation Moderate Minimal Minimal Moderate Moderate

Estimated Downtime Working directly with mission/business process owners, departmental staff, managers, and other stakeholders, estimate the downtime factors for consideration because of a disruptive event.

• Maximum Tolerable Downtime (MTD): The MTD represents the total amount of time leaders/managers are willing to accept for a mission/business process outage or disruption and includes all impact considerations. Determining MTD is important because it could leave continuity planners with imprecise direction on (1) selection of an appropriate recovery method, and (2) the depth of detail that will be required when developing recovery procedures, including their scope and content.

• Recovery Time Objective (RTO): RTO defines the maximum amount of time that a

 Student: Submitted to Grand Canyon University

 in the event of, in th...: in the event of  if

 Word repetition: Minimal Minimal  Minimal

 Duplicated ph...: Severe Sever...  Severe Severe

 Word repetition: Moderate Modera...  Moderate

 Word repetition: Minimal Minimal  Minimal

 Word repetition: Moderate Modera...  Moderate

 Student: Submitted to Grand Canyon University

 Use an m-dash.: -  —

 Use an m-dash.: –  —

Example Impact Category = Cost

▪ Severe - temporary staffing, overtime, fees are greater than $1 million

▪ Moderate – fines, penalties, liabilities potential $550,000

▪ Minimal – new contracts, supplies $75,000

3

system resource can remain unavailable before there is an unacceptable impact on other system resources, supported mission/business processes, and the MTD. Determining the information system resource RTO is important for selecting appropriate technologies that are best suited for meeting the MTD.

• Recovery Point Objective (RPO ): The RPO represents the point in time, prior to a disruption or system outage, to which mission/business process data must be recovered (given the most recent backup copy of the data) after an outage.

4

The table below identifies the MTD, RTO, and RPO (as applicable) for the organizational mission/business processes.

Values for MTDs and RPOs are expected to be specific timeframes, identified in hourly increments (e.g., 8 hours, 36 hours, 97 hours).

Mission/Business Process MTD RTO RPO

Pay vendor invoice 72 hours 48 hours 12 hours (last backup)

Managing information system 6 hours 3 hours 24 hours (last backup)

Making corporate decisions 72 hours 12 hours 24 hours (last backup)

Office automation 48 hours 12 hours 24 hours (last backup)

The managing information system is essential in the day-to-day operations of the firm. A lot of workloads would accumulate, and the performance of the firm would have been affected immensely. For this reason, the outage would take a few hours before reaching the maximum time for the situation to be tolerated. The vast workload would require a lot of time to recover to ensure optimal performance is restored. The firm officials make decisions very often, but they would stay about three days without hindering the firm's operations. Moreover, recovering from this outage would take about 12 hours to record all those data since the workload would not be huge (Aleksandrova. et al.,2018). Office automation operations can last to 48 hours since most of the workload of each branch office can be stored locally for a longer time before being uploaded to the headquarter of the company. It would take around 12 hours to recover and start normal operations since all the office-related workload will be uploaded into the mainstream system. 3.2 Identify Resource Requirements The following table identifies the resource requirements including hardware, software, and other resources, such as data files.

System Resource/Component Platform/OS/Version (as applicable) Description

Web Server 1 OptiPlex GX280 Website Host

Webserver 1 Mac OS server Website host

Operating system 1 Sourcebook Website Host

Operating system 2 Linux Operating system

 Use an m-dash.: –  —

 Student: Submitted to Grand Canyon University

 Spelling mistake: MTDs  Mods

 Spelling mistake: RPOs  Rios

 Passive voice: are expected to be

 Spelling mistake: timeframes  time frames

 Passive voice: have been affected

 Spelling mistake: Aleksandrova

 Checks that a sentence starts with ...: et  Et

 a/the + infinitive: the headquarter

 Student: Submitted to Grand Canyon University

 Spelling mistake: Webserver  Web server

 Spelling mistake: Sourcebook  Coursebook

 Spelling mistake: Webserver  Web server

 Word repetition: database Databas...  database

Webserver 2 CentOS Website host

Database 1 OLAP database

Database 2 Data Marts Database

Wireless connection LTE networks Network device

End-user network CDN apple Network device

5

 Spelling mistake: Webserver  Web server

 Word repetition: database datab...  database

 Spelling mistake: iCloud  cloud

 Passive voice: It is assumed that

 Student: Submitted to Grand Canyon University

 Spelling mistake: Webserver  Web server

 Spelling mistake: Sourcebook  Coursebook

Webserver 3 SMB apple Website host

Webpage 1 Tumblr Web page

Database Supplier information

database database

Data keeping iCloud Cloud system

It is assumed that all identified resources support the mission/business processes identified in Section 3.1 unless otherwise stated.

3.3 Identify Recovery Priorities for System Resources The table below lists the order of recovery for OptiPlex GX280 resources. The table also identifies the expected time for recovering the resource following a “worst case” (complete rebuild/repair or replacement) disruption. Recovery Time Objective (RTO ): RTO defines the maximum amount of time that a system resource can remain unavailable before there is an unacceptable impact on other system resources, supported mission/business processes, and the MTD. Determining the information system resource RTO is important for selecting appropriate technologies that are best suited for meeting the MTD.

Priority System Resource/Component Recovery Time Objective

Web Server 1 OptiPlex GX280 24 hours to rebuild or replace

Database 1 OLAP 24 hours to rebuild

Wireless

connection LTE networks 12 hours to rebuild

Webserver 1 Mac OS server 12 hours to rebuild

End-user network CDN apple 12 hours to rebuild

Operating system

1 Sourcebook 12 hours to rebuild

A system resource can be software, data files, servers, or other hardware and should be identified individually or as a logical group.

6