Business Impact Analysis (BIA)
A Business Impact Analysis (BIA) answers a blunt question: how much would it hurt if one part of your organisation leaked its data, started producing the wrong numbers, or stopped working altogether? 3rdRisk ships a ready-made BIA assessment template built on the three classic information security domains — Confidentiality, Integrity and Availability — so you can score your processes, key services and assets without designing a questionnaire first.
This article covers what the template contains, how an answer becomes a score and a colour, and how to adjust it to your own wording. To assign it to an organisation element and plan its review, see the organisation model article linked at the end.
Overview
The BIA template is not one questionnaire. It is three separate risk assessment templates, one per domain, which you assign to an organisation element on its Assessments tab:
Domain | Questions | What it measures |
|---|---|---|
C - Confidentiality | 4 | The damage if this element's data were seen by the wrong people. |
I - Integrity | 4 | The damage if this element's data were wrong, and how quickly you would notice. |
A - Availability | 5 | The damage if this element were unavailable, and how fast it must come back. |
Every question offers five answer options scored 1 to 5, where 1 is the lowest impact and 5 the highest. The domain's score is the average of its answers, which the platform then shows as a coloured C, I and A indicator in the Risk Profile table.
The template is available to the organisation model, and it is not locked — you can rename the domains, rewrite the questions, change the answer options and change the scores.
Permissions needed: access to the risk management settings, which is granted per role via Configuration → Roles.
Where to find the BIA templates
Navigate to: Left menu: Configuration, then Risk management.
The three domains appear in the Risk Domains table alongside any domains your organisation has created itself.
- ID: the reference of the risk domain, for example RPD-13.
- Status: whether the domain is active and can be assigned.
- Risk domain: the name shown in the template picker. Rename it and the new name appears everywhere.
- Questions: how many questions the domain contains — 4, 4 and 5 for C, I and A.
- Actions: the ••• menu, described under Customise the template.
Note: the questionnaire columns show N/A for the BIA domains. Those columns link a domain to a third-party questionnaire, which a business impact analysis of your own organisation does not use.
The questions
C - Confidentiality
# | Question |
|---|---|
C1 | What is the sensitivity of the data processed by this element? |
C2 | What is the potential impact of unauthorised access to this element's data? |
C3 | How many individuals or organisations could be affected by a data breach? |
C4 | Is this element subject to regulatory data protection requirements? |
I - Integrity
# | Question |
|---|---|
I1 | What is the impact of corrupted or incorrect data produced by this element? |
I2 | How quickly would data integrity issues be detected? |
I3 | What is the effort required to restore data integrity after an incident? |
I4 | Are there manual override or fallback procedures if data integrity fails? |
A - Availability
# | Question |
|---|---|
A1 | What is the maximum tolerable downtime (RTO) for this element? |
A2 | What is the maximum tolerable data loss (RPO) for this element? |
A3 | What is the financial impact of this element being unavailable for 24 hours? |
A4 | How many internal or external stakeholders are directly affected by unavailability? |
A5 | Does a tested business continuity or disaster recovery plan exist for this element? |
Each question's five options run from least to most severe. A1 is a good example of the pattern:
Score | Answer |
|---|---|
1 | >72 hours (low criticality) |
2 | 24–72 hours |
3 | 4–24 hours |
4 | 1–4 hours |
5 | <1 hour (mission critical) |
How a score becomes a colour
A domain's score is the average of the scores of its answers, rounded to one decimal. Answer all four Confidentiality questions with a 5, a 5, a 4 and a 4, and Confidentiality scores 4.5.
That average sets the colour of the domain's dot in the Risk Profile table:
Average score | Indicator |
|---|---|
Not yet scored | Grey |
1.0 – 2.0 | Green |
2.1 – 3.0 | Orange |
3.1 – 4.0 | Red |
4.1 – 5.0 | Dark red |
Note: a domain only gets a score once every question in it has been answered. Answer three of the four Confidentiality questions and the C indicator stays grey — a partial answer set produces no partial score.
Customise the template
The template is a starting point. To change it, open the ••• menu on the domain's row in the Risk Domains table:
- Edit Risk Domain: rename the domain and change its settings. Renaming C - Confidentiality to your own wording is safe; scores already recorded stay attached.
- Configure internal organisation questions: add, edit and reorder the questions used on organisation elements, and set the answer options and scores for each one. This is where you adjust the BIA questionnaire itself.
- Recalculate risk profiles: re-run the scoring after you have changed questions, answers or scores, so existing elements reflect the new configuration.
Inside the questions overview you can use Add question to extend a domain, Edit question to reword one, and Configure answers to change the answer options and their scores.
Note: changing a score changes what previously recorded answers add up to. Use Recalculate risk profiles afterwards so the indicators in the Risk Profile table match the new scoring.
Known limitations
- The three BIA domains are scored 1 to 5 per answer. A different scale means editing every answer option in the domain.
- A domain has one score per element. There is no separate weighting per question within a BIA domain.
- The questionnaire columns in the Risk Domains table do not apply to the BIA domains and show N/A.
- Deleting a domain is not the same as deactivating it. Set Status to inactive to take a domain out of use while keeping the answers already recorded.
Assign a BIA to an organisation element
The templates on their own do not score anything. Assign them to an organisation element, answer the questions, and the C, I and A indicators appear in the Risk Profile table.
Learn how to assign the templates, read the scores, and plan the review: Organisation model