graphgrc

SCF - RSK-08 - Business Impact Analysis (BIA)

Mechanisms exist to conduct a Business Impact Analysis (BIA) to identify and assess cybersecurity and data protection risks.

Mapped framework controls

GDPR

ISO 27002

SOC 2

Control questions

Does the organization conduct a Business Impact Analysis (BIA) to identify and assess cybersecurity and data protection risks?