RES / RES-03
Business impact analysis, continuity and disaster recovery planning
Determine which activities must recover first and prepare continuity or restoration. Business continuity planning covers business operations; disaster recovery planning describes restoration of the supporting information systems.

WHEN IT HELPS
A focused response
to a defined need.
Leadership uncertain about recovery priorities, customer requirements, new critical services or dependence on a few applications without documented alternatives.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Business workshops
- interruption impacts
- dependencies
- RTO/RPO objectives
- degraded operations
- resources
- recovery sequence
- procedures
- responsibilities
- testing strategy
Deliverables
- BIA
- dependency map
- approved objectives
- continuity/DR plans
- recovery guides
- capability-gap analysis
- exercise and investment plan
Acceptance evidence
Business priorities are approved; RTO/RPO are defined as targets; dependencies are identified; procedures have owners; gaps between targets and tested capability are explicit.
DELIVERY
How the work is structured.
Approach
Define objectives and ownership; prepare scenarios and resources; perform authorised response or exercise; document evidence; improve and revise.
Prerequisites & responsibilities
Customer: decision-makers, operations, business owners, legal/insurer where required, permissions and recovery resources. Provider: contracted expertise with evidence preservation.
Scope factors
Criticality, scope, investigation depth, data volume, dependencies, scenarios and mobilisation terms. Preparation, response, rebuilding and licensing are separate.
Questions to clarify
How long can each activity be interrupted? What data loss is acceptable? Can current resources actually meet those objectives?
IMPORTANT BOUNDARIES
An untested document does not prove recovery capability. Objectives require resources, available dependencies and business validation during exercises.
Recovery and investigation have limits; no total recovery or absolute resolution-time promise. Exercise results remain specific to the tested scenario.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
A company wants everything restored first. Project: link applications, sales and production to establish priorities. Target outcome: leadership-approved recovery order and degraded operations for lower-priority activities.
Scenario 02
An organisation demands a very short RPO without suitable backups. Project: measure the gap and propose architecture options. Target outcome: a documented investment-versus-risk decision rather than presenting the target as already achieved.
Technology and reference context
References: NIST risk and recovery practices; backup and continuity architectures tailored to selected applications.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
