CISSP GLOSSARY · BUSINESS CONTINUITY
Business Impact Analysis (BIA)
The process that identifies critical business functions and the impact of their disruption over time, producing the recovery metrics (RTO, RPO, MTD) that drive continuity planning.
The Business Impact Analysis is the foundational step of business continuity planning. It catalogues the organisation’s business functions, identifies which are critical, and quantifies how the impact of losing each one grows over time, in lost revenue, regulatory exposure, and reputational harm. From that analysis come the numbers everything else depends on: the MTD for each function and the RTO and RPO targets that recovery strategies must meet.
The order matters and the exam enforces it. The BIA comes before you choose recovery strategies, because you cannot sensibly pick a hot site over nightly backups until the BIA has told you what downtime and data loss each function can survive. It also identifies dependencies between functions, so recovery sequencing reflects reality. The metrics it produces are worked in the recovery metrics guide.
Exam relevance: two things get tested. First, the BIA sets the recovery objectives; those numbers are business decisions surfaced by the BIA, not IT preferences. Second, sequence: BIA first, then strategy selection, then plan development. A question that jumps to buying a recovery site before analysing impact is describing the wrong order.