BCM-008 Business Impact Analysis
Description
A business impact analysis records each business process, the services, systems and data it depends on, the internal and third-party dependencies beneath them, the operational, financial, regulatory and reputational impact of losing the process measured over increasing periods of outage, the maximum tolerable period of disruption and the recovery priority that follows. Each entry is agreed with the business owner accountable for the process. The analysis is reviewed at defined intervals and after any change that alters the criticality of a process or its dependencies.
Rationale
Recovery objectives that were never derived from anything are guesses. A recovery plan that restores the wrong service first is worse than a slow one. Measuring impact over increasing outage periods separates a process that can wait a day from one that cannot wait an hour. Naming dependencies stops a priority-one service from quietly depending on a priority-three one. BCM-003 takes its objectives from this analysis, BCM-001 and BCM-002 take their sequencing from it and BCM-010 takes the third-party entries from it. Issued in S4 from G-BCM-1 in docs/review-canonical-quality.md section 7.3.
Applicability (9 profiles)
164.308(a)(7)(ii)(E) is the business impact analysis in the rule's own vocabulary, and it exists to order the recovery sequence the three required contingency specifications execute.
Framework Mappings (9)
| BCR-02 | Risk Assessment and Impact Analysis | full |
| BCR-02 | Risk Assessment and Impact Analysis | full |
| HIPAA-164.308.a.7.ii.E | Applications and Data Criticality Analysis | full |
| NIS2-CIR-13.2 | Protection Against Physical and Environmental Threats | informative |
| NIS2-CIR-4.1 | Business Continuity and Disaster Recovery Plan | informative |
| CP-2 | Contingency Plan | informative |
| CP-2(8) | Contingency Plan | Identify Critical Assets | full |
| RA-9 | Criticality Analysis | partial |
| MP-2.2-001 | AI System Knowledge Limits Documentation | MP-2.2-001 | informative |
Evidence (2)
Business impact analysis giving, per process, the dependencies, the impact of an outage at increasing durations, the maximum tolerable period of disruption, the recovery priority and the business owner who agreed it.
Example: Business impact analysis 2026 edition, dated 2026-05-12, covering 23 processes with impact assessed at 1 hour, 4 hours, 24 hours and 72 hours, each signed off by the accountable business owner
Test: Read the business impact analysis. Verify: (1) every process in the service catalogue appears or is recorded as out of scope with a reason, (2) impact is assessed at more than one outage duration and covers operational, financial, regulatory and reputational effect, (3) each process carries a maximum tolerable period of disruption and a recovery priority, (4) each entry names the business owner who agreed it and the date, (5) the analysis was reviewed within the defined interval or after the last change in criticality.
Service and dependency inventory export from the service catalogue or configuration management system, used to test the dependency picture the analysis asserts.
Example: Service catalogue export of 2026-08-11 listing 64 services with their upstream dependencies, owning team and the third-party services each calls
Test: Export the service and dependency inventory. Verify: (1) every service the analysis names as a dependency exists in the inventory, (2) every service in the inventory that supports a listed process appears in the analysis, (3) no process with a short tolerable disruption period depends on a service ranked at a lower recovery priority, (4) third-party dependencies in the inventory appear against the processes that use them.
Questions (3)
Does a business impact analysis exist that ranks business processes by recovery priority?
The analysis ranks business processes, not servers. A list of systems by criticality is an asset inventory and answers a different question.
Which of the following does the business impact analysis record for each process?
Impact at more than one duration is what produces a defensible tolerable disruption period. A single worst-case figure ranks everything as critical and tells the recovery team nothing.
When is the business impact analysis reviewed?
Options run from strongest to weakest. The change trigger matters more than the interval: a new product line or a new third party can move a process two priority bands between annual reviews.