An information security manager is kicking off a business impact analysis for a logistics firm. The board has agreed to fund the exercise but wants to know what the BIA is fundamentally intended to produce before resources are committed. Which outcome best describes the primary purpose of the BIA?
- AA catalogue of credible threats and their likelihood of occurring, used to decide which security controls the organisation should invest in first.
- BA technical inventory of servers, applications and network dependencies, used by operations staff to rebuild the environment after a major outage.
- CA ranked understanding of which business processes are most time-sensitive and the impact of their disruption over time, used to set recovery priorities. Correct
- DA statement of residual risk accepted by process owners after controls are applied, used to obtain formal sign-off from senior management.
Why A is wrong: Tempting because threat likelihood feels central to planning, but that is the output of a risk assessment; the BIA focuses on impact of disruption over time, not threat probability.
Why B is wrong: Tempting because dependency mapping does feed recovery, but an asset inventory is a supporting artefact; the BIA's purpose is to quantify business impact and set priorities, not to be a build sheet.
Why C is correct: Correct: the BIA characterises the consequences of disruption to each process over time and ranks them, which is exactly the input needed to drive recovery priorities and resourcing.
Why D is wrong: Tempting because both involve management sign-off, but residual risk acceptance belongs to the risk management process; the BIA produces impact-over-time analysis and recovery priorities, not a risk acceptance record.