> ## Content Index
> Fetch the complete content index at: https://paulobrien.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# PP3: Analysis
- URL: https://paulobrien.com/pp3-analysis/
- Published: 2026-08-25T14:37:56.000Z
- Updated: 2026-08-25T17:48:02.000Z
- Description: Part 3 of 6 in my CBCI study series. A practical breakdown of BCI GPG 7.0 PP3: Analysis—moving from subjective opinions to objective, data-driven requirements, mastering critical metrics like RTO and RPO, and tackling risk assessments.
- Author: Paul O'Brien
- Tags: CBCI Study Series, PP3: Analysis

## CBCI Study Series · Professional Practice 3 of 6

**BCI Good Practice Guidelines (GPG 7.0)**

### Demystifying the BIA: A Study Guide to BCI PP3 (Analysis)

**Introduction: My Journey from "Opinions" to "Data"**

In my previous post, [PP2: Embracing Business Continuity](https://paulobrien.com/pp2-embracing-business-continuity/), we explored the critical shift from rational policy compliance to a vibrant, culture-driven resilience model. We discussed how a technically flawless plan means nothing if your people aren't personally bought into the "why" behind continuity. But once you have that supportive organisational culture, how do you actually determine what to protect, and in what order? This is where BCI **Professional Practice 3 (PP3): Analysis** comes into play.

When I first started studying this module, I'll admit I found it incredibly daunting. Words like RTO, RPO, MTPD, and MBCO flew around, and they felt like an alphabet soup of technical jargon. But as I dove into the Good Practice Guidelines (GPG 7.0) and aligned ISO standards, I hit my major "aha!" moment: PP3 is about moving the entire business continuity conversation from subjective, emotional *"opinions"* to objective, empirical *"data."* It strips away departmental hyperbole (where every single manager claims their team is the most urgent in the building) and replaces it with a rigorous, standard-aligned framework for measuring impacts over time.

Here are my core, exam-focused study notes to help you demystify the BIA, master the critical recovery metrics, and easily avoid the classic exam traps in PP3!

#### 1\. The Two Pillars of PP3: BIA and Risk Assessment

PP3 is strictly built upon two distinct yet highly complementary analytical techniques: the Business Impact Analysis (BIA) and the Risk Assessment (RA). Together, they form the complete foundation for designing strategies and solutions in PP4.

- **The Business Impact Analysis (BIA):** Analyses the impact over time of a disruption on the organisation. Its primary purpose is to identify prioritised activities, determine their recovery timeframes, and map out their resource requirements.
- **The Risk Assessment (RA):** Identifies and analyzes the disruption risks to the organisation's prioritised activities and required resources. Its focus is on uncovering concentrations of risk and single points of failure (SPOFs) that could trigger a disruption.

🚨

****EXAM TRAP ALERT: The Sequence of Analysis:** A very common exam question focuses on the sequence of these two techniques. Why does the GPG recommend conducting the BIA before the Risk Assessment?

#### 2\. The Three Types of BIA (and When to Use Them)

A common point of confusion for CBCI candidates is assuming that every organisation must perform three separate, complex analyses. In reality, GPG Edition 7.0 emphasises scalability. The guidelines outline three types of BIA that can be used individually or combined to suit the size, complexity, and type of organisation:

| BIA Type                    | Core Objective                                                                                                                                      | GPG 7.0 Suitability & Scalability Tip 🧠                                                                                                                                                                             |
| --------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Product and Service BIA** | Identifies and prioritises the organization's high-level outputs provided to interested parties.                                                    | Mandatory first step. It validates and confirms the high-level scope of the BCMS. Top management holds the ultimate responsibility for assigning these priorities.                                                   |
| **Process BIA (Optional)**  | Determines the chronological, end-to-end processes required to deliver prioritised products and services.                                           | Optional! Recommended specifically for highly process-driven organizations (e.g., manufacturing). Service-oriented or less process-focused businesses can omit this entirely and move straight to activity analysis. |
| **Activity BIA**            | Identifies the specific tasks with defined outputs that support prioritized processes, and breaks down the resources and dependencies they rely on. | The heart of operational planning. Determines RTOs, MTPDs, and resource needs (people, data, IT, facilities, suppliers) for each prioritised activity.                                                               |

#### 3\. Core Metrics: Master MTPD, RTO, RPO, and MBCO

To score 100% on the PP3 portion of the CBCI exam, you must memorize the ISO-aligned definitions of the four core business continuity metrics word-for-word, and deeply understand how they relate to each other.

**• Maximum Tolerable Period of Disruption (MTPD):** Time frame within which the impacts of not resuming activities would become unacceptable to the organisation.

**• Recovery Time Objective (RTO):** The time frame within the MTPD for resuming disrupted activities at a specified minimum acceptable capacity.

**• Recovery Point Objective (RPO):** The point to which information used by an activity is restored to enable the activity to operate on resumption to pre-defined levels." Note: The GPG highlights that RPO can also be referred to as *"maximum data loss.*

**• Minimum Business Continuity Objective (MBCO):** The minimum capacity or level of services or products that is acceptable to an organisation to achieve its business objectives during a disruption.

🚨

****EXAM TRAP ALERT: The Metric Interconnections:** First, RTO must ALWAYS be less than the MTPD. This difference creates a critical 'safety margin' or buffer for the recovery teams to act before the organization hits the point of existential failure or unacceptable regulatory damage.

#### 4\. Conducting a Risk Assessment & Identifying SPOFs

While the BIA looks at the \*impacts\* of disruption over time, the Risk Assessment (RA) looks at the \*likelihood and consequence\* of specific disruptive risks materialising. Aligned with the ISO 31000:2018 risk management standard, the RA involves identifying, analysing, and evaluating risks to prioritise them systematically.

As a BC Professional, your primary focus during the RA is to identify **single points of failure (SPOFs)**—any critical dependency (such as a single specialised supplier, a lone technical expert, or a single power feed) that has no backup and would cause immediate cessation of your prioritised activities if lost. Once risks are calculated using a standard Likelihood × Consequence scoring system (High, Medium, Low), those identified as "unacceptable" or classified as SPOFs are passed as direct inputs to PP4 (Solutions Design) to develop robust risk treatments.

#### 5\. Practical Collection Methods: Workshops vs. Surveys vs. Interviews

How do you collect BIA data without pulling your hair out? The GPG outlines three primary data collection methods, each with distinct advantages and resource considerations. To build a strong BCM culture (PP2), a mix is often ideal:

- **Workshops:** The highest-quality method. Gathering teams together (physically or virtually) allows for lively discussion, uncovers complex interdependencies, and actively builds culture. They require more preparation time but deliver robust, validated results.
- **Surveys/Questionnaires:** Excellent for large-scale data collection. They allow you to gather information from a large number of people very quickly. However, the questions must be exceptionally well-written to prevent respondents from misinterpreting definitions.
- **Interviews:** One-on-one conversations. Ideal for deep dives into specific complex departments, allowing you to ask follow-up questions and tease out hidden risks. The main drawback is that they require a significant amount of your time to execute.

🚨

****EXAM TRAP ALERT: The Terminology Shift:** In previous editions of the GPG, practitioners often used terms like 'key', 'critical', 'urgent', or 'important' activities. In GPG Edition 7.0, these have been officially unified under the standard term 'prioritised activities'.

#### Test Your Knowledge: BCI Exam Prep PP3 Quiz

**Question 1**

Why does the BCI Good Practice Guidelines recommend conducting the Business Impact Analysis (BIA) before the Risk Assessment (RA)?

- A) Because the BIA is a legal requirement under ISO 22301, while the RA is completely optional.
- B) To identify prioritised activities first, so that the subsequent Risk Assessment can focus its resources strictly on identifying risks to those critical areas.
- C) Because the Risk Assessment is conducted exclusively by third-party external auditors.
- D) To allow the IT disaster recovery team to purchase hardware before the business continuity policy is signed.

#### Answer

****Correct Answer: B** 

****Explanation**: Conducting the BIA first establishes which activities are prioritised and essential to organisational survival. This prevents the organisation from wasting time and money conducting detailed risk assessments on low-priority or non-critical business processes.

**Question 2**

An organisation operates in a service-oriented sector with very few linear, step-by-step assembly workflows. According to GPG 7.0, how should they approach the optional Process BIA?

- A) They must still complete it, as all three types of BIA are mandatory for all organisations.
- B) They must hire external consultants to map all processes before conducting the Product and Service BIA.
- C) They can omit the Process BIA entirely and move directly from the Product and Service BIA to the Activity BIA.
- D) They must postpone the entire BCMS project until processes are formalised.

#### Answer

****Correct Answer: C**

****Explanation**: Under GPG GPG 7.0, the Process BIA is strictly optional. It is highly recommended for highly process-driven businesses (such as manufacturing), but less process-focused businesses can omit it completely and transition straight into the Activity BIA.

**Question 3**

Which of the following is the correct ISO-aligned definition of the Recovery Point Objective (RPO)?

- A) The timeframe within the MTPD for resuming disrupted activities at a specified minimum acceptable capacity.
- B) The target timeframe set by management to relocate staff to an alternate work location.
- C) The point to which information used by an activity is restored to enable the activity to operate on resumption to pre-defined levels.
- D) The maximum financial loss an organisation can tolerate before declaring bankruptcy.

#### Answer

****Correct Answer: C**

****Explanation**: RPO represents data integrity and acceptable data loss. It is strictly defined as the point to which information must be restored (e.g., 'transactions up to 1 hour before the crash') to enable the activity to operate upon resumption.

**Question 4**

What is the required relationship between the Recovery Time Objective (RTO) and the Maximum Tolerable Period of Disruption (MTPD)?

- A) The RTO must always be greater than the MTPD to allow backup systems to cool down.
- B) The RTO must always be less than the MTPD to provide a necessary safety margin for recovery.
- C) The RTO and MTPD must be mathematically equal to satisfy ISO 22301 audits.
- D) There is no relationship between RTO and MTPD, as they apply to completely different organisational scopes.

#### Answer

****Correct Answer: B**

****Explanation**: The RTO must always be shorter than the MTPD. This safety margin ensures that the activity is recovered and operating before the disruption's impact becomes unacceptable or places the organisation at risk of failure.

**Question 5**

Why has the BCI GPG Edition 7.0 officially replaced informal descriptors like 'key', 'critical', or 'urgent' with the standardised term 'prioritised activities'?

- A) Because 'prioritised activities' is the only term legally recognised by the United Nations.
- B) To reduce the file size of business continuity plans stored in cloud databases.
- C) To prevent internal data inflation and exaggeration, ensuring a consistent globally understood meaning focused on urgency to avoid unacceptable impacts.
- D) Because the word 'critical' was copyrighted by alternate risk management bodies.

#### Answer

****Correct Answer: C**

****Explanation**: Informal words like 'critical' or 'important' are highly subjective and lead to departments exaggerating their recovery needs. Using the formal ISO 22301-aligned term 'prioritised activities' ensures a rigorous, consistent, and objective threshold for what actually requires urgent recovery.

  
## 📬 Never Miss a Deep Dive

I’m breaking down the entire BCI Good Practice Guidelines (GPG 7.0) step-by-step as I prepare for the CBCI exam. If you want practical resilience breakdowns and study notes delivered straight to your inbox as they publish, subscribe below—100% free, zero spam.

Subscribe 

Email sent! Check your inbox to complete your signup. 

No spam. Unsubscribe anytime.

**What's Next? Moving into Technical Solutions**

Now that we've used PP3 (Analysis) to gather empirical data, define clear RTOs and RPOs, and uncover our Single Points of Failure, we have a solid, objective roadmap of our business continuity requirements. But how do we bridge the gap between where our capabilities stand today and where they need to be? For that, we enter the next technical practice: [Professional Practice 4 (PP4): Solutions Design](https://paulobrien.com/pp4-solutions-design/). In my next post, we will dissect the three-step solutions determination process—gap analysis, strategy selection, and solutions specification—and explore how to design cost-effective recovery options across all primary resources (people, IT, facilities, and suppliers) without breaking the bank. Stay tuned, and keep analysing with rigor!

**Next in the series:**[PP4: Solutions Design](https://paulobrien.com/pp4-solutions-design/)

📚

New to the series?  
Start from the beginning or jump to any chapter by visiting the [CBCI Study Series Index](https://paulobrien.com/journey-to-cbci-business-continuity-gpg-7-0/) and don’t forget to grab your copy of the companion [GPG 7.0 Glossary Study Guide](https://paulobrien.com/bci-gpg-edition-7-0-complete-glossary/)!

---

*Disclaimer: These are independent study notes compiled to assist candidates preparing for the Certificate of the Business Continuity Institute (CBCI) examination. This content is not officially endorsed, sponsored, or affiliated with the Business Continuity Institute (BCI). The official body of knowledge is the BCI Good Practice Guidelines (GPG) Edition 7.0, which can be sourced directly from the BCI.*