Prioritize the business services and activities that matter most first; then identify the systems and other resources they depend on and set recovery requirements from the consequences of disruption over time. A system’s technical importance alone does not establish its business priority. Set recovery time objectives (RTOs) for activities, record recovery point objectives (RPOs) separately, and check both against what your continuity and recovery arrangements can actually deliver.
Start with business services, not a system ranking
A business impact analysis (BIA) examines how disruption affects an organization over time so it can set priorities and continuity requirements. Begin by listing the services, products, and mission-essential activities that must continue or be restored. Confirm the scope and disruption scenarios with the accountable business owners.
NIST’s February 2025 edition of IR 8286D describes using BIA to understand potential impacts to enterprise mission and identify the assets that support objectives. That makes the business activity the starting point: a technology component matters to the extent that it enables an important service or outcome.
Map the dependencies behind each activity
For every in-scope activity, trace the resources needed to operate it. Include more than applications: a service may also depend on information, infrastructure, facilities, staff, suppliers, and supporting processes. CISA’s CRR Supplemental Resource Guide, Volume 6: Service Continuity addresses essential services and priorities alongside technology, facilities, information, people, and infrastructure.
#1 Best Overall
Record upstream dependencies—the services an activity needs—and downstream dependencies—the services or customers that rely on it. This prevents a visible customer-facing application from appearing recoverable when a shared identity, network, data, facility, or supplier service is still unavailable.
Assess consequences as disruption continues
Ask each activity owner what would happen at meaningful elapsed-time intervals after a disruption. Capture the consequences and the point at which continued interruption becomes unacceptable. Relevant impacts may include harm to health or safety, interruption of essential services, revenue effects, external obligations that apply to the organization, and impacts on other activities.
Rank #2
Use impact categories and thresholds that fit your organization and sector, and have accountable owners agree to them. ISO’s ISO/TS 22317:2021 is detailed guidance for conducting and maintaining BIA consistent with ISO 22301; it notes the importance of information from people with different perspectives on time-criticality and impacts. Do not assume that another organization’s categories or a federal framework automatically suit your business or jurisdiction.
Distinguish RTO, RPO, and disruption tolerance
Set recovery requirements for the business activity first, then translate them into requirements for the systems, information, people, and other resources that enable it.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Rank #3
- Recovery time objective (RTO): the desired speed or time for recovery. It is a business-derived target, not automatically a vendor commitment or evidence that recovery is achievable.
- Recovery point objective (RPO): the desired currency of recovered information. Record it separately from the elapsed time allowed for recovery.
- Maximum tolerable period of disruption (MTPD): a disruption-tolerance concept used alongside RTO in ISO BIA guidance. Follow the definitions and method applicable to your organization.
RTO should reflect the disruption tolerance and service level agreed for the activity. RPO should reflect how much loss of data currency the business can accept. NIST’s SP 800-34 Rev. 1 provides federal information-systems contingency-planning guidance, including BIA material; it is guidance that organizations may adapt, not a universal RTO mandate.
Compare competing priorities using explicit criteria
When several activities or systems compete for limited recovery resources, compare them against a consistent set of organization-approved dimensions. These are decision factors, not a universal scoring formula or prescribed weighting scheme.
Rank #4
- Impact as time passes and the point at which disruption becomes unacceptable.
- Contribution to mission objectives and essential services.
- Health and safety, revenue, and other material consequences.
- External obligations that apply to the organization.
- Number and criticality of dependent activities.
- Required RTO and RPO, and any workable manual alternative.
- Feasibility, resource demands, and cost of available recovery options.
Document assumptions and have business owners approve the criteria and resulting priorities. NIST’s IR 8179, Criticality Analysis Process Model, provides a structured approach to analyzing the criticality of programs, systems, and components; use it to connect system importance to the objectives and activities it supports.
Turn the priorities into a feasible restoration sequence
Combine business priority with dependency relationships to produce a sequence that can work in practice. A shared service may need restoration before a higher-priority activity that relies on it, even if that service is not itself customer-facing. CISA’s #StopRansomware Guide advises including critical assets—such as those supporting health and safety, revenue, or critical services—and the systems on which those assets depend in a predefined restoration list.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteBest Value
Do not treat the sequence as a list of isolated applications. Make clear which enabling resources must be restored, in what order, for each priority activity to resume at the required level.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Validate targets against recovery capability
Compare each required RTO and RPO with the recovery strategies, resources, workarounds, and demonstrated capability available for the activity and its dependencies. Record gaps rather than quietly changing the target to match current capability. Identify the residual risk, who owns it, and who has authority to accept it.
CISA’s service-continuity resource includes BIA material and a template, and emphasizes weighing continuity investment against risk. Use that comparison to decide whether to improve capability, change the strategy, document a workaround, or formally accept the exposure.
Use a worksheet that keeps decisions traceable
A practical BIA record should make it possible to see why an activity has its priority, what it needs to recover, and whether the organization can meet that need. Adapt the fields to your continuity method and sector.
Recommended Free Tools
- Business activity or service and accountable owner.
- Disruption scenario and impact by elapsed time.
- Impact threshold or maximum tolerable disruption, where used.
- Required RTO and RPO, recorded separately.
- Workaround and the service level it can sustain.
- Supporting people, information, facilities, systems, and suppliers.
- Upstream and downstream dependencies.
- Recovery strategy and demonstrated recovery capability.
- Gap, residual-risk owner, and approval date.
Review the entries with the relevant owners and update them when services, dependencies, assumptions, or recovery arrangements change. For more detailed reference material, consult NIST IR 8286D, NIST SP 800-34 Rev. 1, and CISA’s service continuity guide.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

