Skip to content

Business Impact Assessment

Ryan Wold edited this page Nov 22, 2019 · 21 revisions

U.S. General Services Administration

Technology Transformation Services

Touchpoints

Business Impact Analysis

November 22, 2018


Document Prepared by

| Organization Name | GSA/TTS | | Address Line 1 | 1800 F St | | Address Line 2 | Suite 4100 | | City, State Zip | Washington, DC 20405 |


Document Revision History

Date Description
2019-11-22 Initial Version 0.1 Ryan Wold, Lynnette Jackson

Table of Contents

  1. Overview 1.1 Purpose

1. Overview

This BIA (Business Impact Analysis) is developed as part of the contingency planning process for Touchpoints.

1.1 Purpose

The purpose of the BIA is to identify and prioritize system components by correlating them to the mission/business process(es) the system supports, and using this information to characterize the impact on the process(es) if the system were unavailable.

The BIA is composed of the following three steps:

  1. Determine mission/business processes and recovery criticality. Mission/business processes supported by the system are identified and the impact of a system disruption to those processes is determined along with outage impacts and estimated downtime. The downtime should reflect the maximum that an organization can tolerate while still maintaining the mission.
  2. Identify resource requirements. Realistic recovery efforts require a thorough evaluation of the resources required to resume mission/business processes and related interdependencies as quickly as possible. Examples of resources that should be identified include facilities, personnel, equipment, software, data files, system components, and vital records.
  3. Identify recovery priorities for system resources. Based upon the results from the previous activities, system resources can more clearly be linked to critical mission/business processes. Priority levels can be established for sequencing recovery activities and resources.

This document is used to build the Data.gov Information Security Contingency Plan (ISCP) and is included as a key component of the ISCP. It also may be used to support the development of other contingency plans associated with the system, including, but not limited to, a Disaster Recovery Plan or Incident Response Plan.

Clone this wiki locally