GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

BCM-008 Business Impact Analysis

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

A business impact analysis records each business process, the services, systems and data it depends on, the internal and third-party dependencies beneath them, the operational, financial, regulatory and reputational impact of losing the process measured over increasing periods of outage, the maximum tolerable period of disruption and the recovery priority that follows. Each entry is agreed with the business owner accountable for the process. The analysis is reviewed at defined intervals and after any change that alters the criticality of a process or its dependencies.

Rationale

Recovery objectives that were never derived from anything are guesses. A recovery plan that restores the wrong service first is worse than a slow one. Measuring impact over increasing outage periods separates a process that can wait a day from one that cannot wait an hour. Naming dependencies stops a priority-one service from quietly depending on a priority-three one. BCM-003 takes its objectives from this analysis, BCM-001 and BCM-002 take their sequencing from it and BCM-010 takes the third-party entries from it. Issued in S4 from G-BCM-1 in docs/review-canonical-quality.md section 7.3.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
HIPAA Business Associate (US)stablerequiredrole duty

164.308(a)(7)(ii)(E) is the business impact analysis in the rule's own vocabulary, and it exists to order the recovery sequence the three required contingency specifications execute.

NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (9)

BCR-02Risk Assessment and Impact Analysisfull
BCR-02Risk Assessment and Impact Analysisfull
HIPAA-164.308.a.7.ii.EApplications and Data Criticality Analysisfull
NIS2-CIR-13.2Protection Against Physical and Environmental Threatsinformative
NIS2-CIR-4.1Business Continuity and Disaster Recovery Planinformative
CP-2Contingency Planinformative
CP-2(8)Contingency Plan | Identify Critical Assetsfull
RA-9Criticality Analysispartial
MP-2.2-001AI System Knowledge Limits Documentation | MP-2.2-001informative

Evidence (2)

recorddocumentmanual

Business impact analysis giving, per process, the dependencies, the impact of an outage at increasing durations, the maximum tolerable period of disruption, the recovery priority and the business owner who agreed it.

Example: Business impact analysis 2026 edition, dated 2026-05-12, covering 23 processes with impact assessed at 1 hour, 4 hours, 24 hours and 72 hours, each signed off by the accountable business owner

Test: Read the business impact analysis. Verify: (1) every process in the service catalogue appears or is recorded as out of scope with a reason, (2) impact is assessed at more than one outage duration and covers operational, financial, regulatory and reputational effect, (3) each process carries a maximum tolerable period of disruption and a recovery priority, (4) each entry names the business owner who agreed it and the date, (5) the analysis was reviewed within the defined interval or after the last change in criticality.

system_exporttechnicalautomated

Service and dependency inventory export from the service catalogue or configuration management system, used to test the dependency picture the analysis asserts.

Example: Service catalogue export of 2026-08-11 listing 64 services with their upstream dependencies, owning team and the third-party services each calls

Test: Export the service and dependency inventory. Verify: (1) every service the analysis names as a dependency exists in the inventory, (2) every service in the inventory that supports a listed process appears in the analysis, (3) no process with a short tolerable disruption period depends on a service ranked at a lower recovery priority, (4) third-party dependencies in the inventory appear against the processes that use them.

Questions (3)

boolean

Does a business impact analysis exist that ranks business processes by recovery priority?

The analysis ranks business processes, not servers. A list of systems by criticality is an asset inventory and answers a different question.

multi

Which of the following does the business impact analysis record for each process?

The services, systems and data the process depends onThird-party dependenciesImpact measured at more than one outage durationOperational, financial, regulatory and reputational impactThe maximum tolerable period of disruptionThe recovery priority and the business owner who agreed itNone of the above

Impact at more than one duration is what produces a defensible tolerable disruption period. A single worst-case figure ranks everything as critical and tells the recovery team nothing.

select

When is the business impact analysis reviewed?

At defined intervals and after any change that alters the criticality of a process or its dependenciesAt defined intervalsWhen a continuity plan is rewrittenIt has not been reviewed since it was produced

Options run from strongest to weakest. The change trigger matters more than the interval: a new product line or a new third party can move a process two priority bands between annual reviews.