ORGANIZATIONAL RESILIENCE
104
resilience objectives. Planning should clearly identify the strategy
for ORM and managing risk.
• Risk assessment and impact analysis: Involves understanding the
risks in order to prioritize and manage them. This includes assess-
ments of the business processes, functions, necessary resources to
achieve successful business functionality, and ongoing analyses
of the threats and impact to the business if these processes and
resources are interrupted—keeping in mind that prevention is
often less costly than the cure.
• Legal and other requirements: The organization must understand
the legal and other requirements under which it operates and it is
expected to make every effort to achieve compliance in order to
avoid ...