ISO 27001 does NOT require a business impact analysis.
I DO conduct a BIA with every client I work with.
Let me explain why: In lot’s of risk registers I saw, "impact" is a gut feeling. Someone says "ransomware on the ERP system, that's a 4", and it goes into the register.
But a “4” for how long? An ERP outage of two hours is an annoyance. After two days, orders stop shipping. After two weeks, you’re losing customers and paying contractual penalties. Impact isn’t a fixed number. It grows the longer the disruption lasts, and a single score on a scale hides that completely.
A BIA makes the time dimension visible. For each business activity, you ask how the impact develops over hours, days and weeks, and how much data the business can afford to lose. The point where the impact becomes unacceptable is your maximum tolerable period of disruption (MTPD). From there, you set your RTOs and RPOs and map them to the systems behind each activity.
Now your impact scores are derived, not negotiated. And every availability control in your Statement of Applicability has a reason an auditor can trace straight back to the business.
In this masterclass, I walk you through the entire method, using a beer brewery as an example.
Be the GRC Practitioner AI can’t replace.
– Aron






