THREAT AND RISK ASSESSMENT
Impact assessment
Essentially, the method of assessment is the same as that used for evaluating scenarios in Chapter 9, with the proviso that, with business recovery, or indeed survival, time is the critical measure of impact. Yes, you may lose revenue, possibly erosion of the customer base and loss of reputation – but how long will an interruption have to last to be intolerable, if not catastrophic? What is your risk appetite or tolerance for an outage, such as: customers affected, data recovery, server recovery, voice equipment recovery – most important, the time for recovery? And indeed, at which point does a disruption cause financial harm, both to the firm and to customers?
In assessing impact, you are trying ...
Get Mastering Risk Management now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.