EzRisk
As risk
analysis is such a central part of Business Continuity Management, the BS25999
Toolkit includes a copy of the EzRisk desktop risk analysis
system.
This
comprises a set of MS-Word documents to help you conduct a high level risk
assessment exercise.
EzRisk
adopts a 3 phase approach: Business Impact Analysis; Risk Assessment; Final
Analysis. It provides four documents to guide this. The first is a BIA
questionnaire to help identify potential impacts, and also determine which
of the other questionnaires should be completed. The others reflect the CIA
approach, with a questionnaire covering each of Confidentiality, Integrity
and Availability. Each examines a range of threats at a high level.
It
is intended that the completed questionnaires will be used to drive an
assessment workshop, which will determine further actions (usually a full
assessment of identified potentially exposed areas, or a dedicated workshop
to examine certain issues in more depth).
Sample
Pages:
Extract
from the Introduction

Extracts
from the BIA Questionnaire
Extract
from the Availability Questionnaire
Extract
from the Integrity Questionnaire
Return
to Index Page