Business impact analysis
A BCP starts with a business impact analysis (BIA), which identifies the critical processes, the systems and suppliers they depend on, and how long the company can operate without each one.
RTO and RPO
Two figures shape the recovery strategy. The RTO (Recovery Time Objective) is the maximum acceptable time to restore a process or system. The RPO (Recovery Point Objective) is the maximum amount of data, measured in time, that the company can afford to lose, and it determines how often backups are made. An RPO of four hours means backups at least every four hours.
BCP vs disaster recovery
The BCP covers the whole business: people, offices, suppliers and communication. The disaster recovery plan (DRP) is its technical part, focused on restoring IT systems and data. Both should account for ransomware, which can disable systems and backups at the same time.
Where it shows up in compliance
ISO 27001 requires information security during disruption and ICT readiness for business continuity (Annex A 5.29 and 5.30). ISO 22301 is the standard for a full business continuity management system. The ENS, NIS2 and DORA all require continuity measures, and DORA requires them to be tested. A plan that has never been tested should not be relied on.




