Business Continuity Management: BIA Dependency Assessment

Ash42
Tera Expert

When performing a BIA dependency assessment, for a given dependency, how should one determine what value to specify for the Recovery Time Objective (RTO) and/or Recovery Point Objective(RPO)? The documentation (https://docs.servicenow.com/bundle/utah-governance-risk-compliance/page/product/grc-business-continu...) is quite vague about this.

Do these values represent the currently achievable or best guess values for the dependency? Or are these more like targets the BIA owner sets for the dependency based on the overall BIA RTO/RPO calculated from the BIA impact assessment?

Any insights about this would be very much appreciated.

 

 

 

1 ACCEPTED SOLUTION

Per ServiceNow's product team the BIA dependency RTO/RPO values come from Subject-matter Experts (SMEs), i.e., they're currently achievable values. Currently there are no business rules around this, but will be in future.

 

The way I'm interpreting this is that it can help with prioritization of plans. You'd want to focus on creating plans for dependencies that have have RTO/RPO higher than the BIA RTO/RPO and put in place alternate recovery strategies that would bring the dependency RTP/RPO values down.

 

View solution in original post

4 REPLIES 4

Community Alums
Not applicable

Hi @Ash42 ,

While recovery time objective and recovery point objective are both core components of DR and business continuity planning, each serves a different and distinct purpose, however.

  • Recovery time objective is about having policies and technologies in place that enable an organization to recover within a certain duration of time.
  • Recovery point objective, by contrast, is about making sure, ahead of time, that the data recovery and backup capabilities are in place to minimize the amount of data that could be lost during an incident.

SandeepDutta_0-1692590341000.png

Also, in terms of BIA Dependency Assessment, please refer to the link :Recovery time objective, Recovery point objective, and Recovery tiers 

 

Thanks for the info Sandeep. But I'm looking for best practices/guidance on determining the RTO/RPO values for a dependency on a BIA. In particular, the documentation: Assess the impact categories and dependencies Step 8 says that for a dependency (Depends on), you can add the RTO, RPO, Description of use, etc. It offers no guidance on how to determine the RTO, RPO values to put here. If I was completing this portion of the BIA, what RTO, RPO values would I put for a given dependency? The currently achievable/known RTO, RPO for the dependency? Or would the values I put be the RTO, RPO goals for the dependency scoped to this BIA (perhaps taking in account the overall calculated BIA RTO, RPO)? If these are goal based values, I'm thinking I could just put the overall BIA RTO/RPO value for every dependency on the BIA. Unless there's some inter-dependency between the dependencies (one must be recovered before the other can be).

 

cvik
Tera Contributor

I am struggling with this one too. Not even sure where those numbers for each dependency will be used afterwards, if any place at all. When you perform RTO assessment of impacts for Business Process you will already have RTO for the process. Logically it would make sense that all dependencies was adjusted to fit that RTO. That is to say it makes no sense having av dependency toward an application but allow it to have a longer RTO than the process it is part of. If on the other hand, those values are achievable RTOs (what the application is capable of today), than it would make a lot more sense to set that in the CMDB itself, since one application can be used within multiple business processes.

Per ServiceNow's product team the BIA dependency RTO/RPO values come from Subject-matter Experts (SMEs), i.e., they're currently achievable values. Currently there are no business rules around this, but will be in future.

 

The way I'm interpreting this is that it can help with prioritization of plans. You'd want to focus on creating plans for dependencies that have have RTO/RPO higher than the BIA RTO/RPO and put in place alternate recovery strategies that would bring the dependency RTP/RPO values down.