Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » Generic » Business Impact Analysis

Business Impact Analysis

A Business Impact Analysis (BIA) is a critical process that predicts the potential consequences of a disruption to your business. It collects information necessary for creating proper recovery strategies.

The extent and complexity of your BIA should align with your organization’s size and intricacy. Larger and more complex institutions may have a more detailed list of business processes to review during their BIA. 

For example, while smaller institutions might address “Administrative” functions as one process, larger ones may break it down further into processes like “Accounts Payable,” “Human Resources,” and “Payroll.” 

Examples of standard business processes that might be assessed include:

  • Administrative
  • Investment
  • Trust
  • Back-office
  • Customer service
  • Information technology
  • Accounting
  • Lending
  • Marketing
  • Compliance
  • Retail

Disruptions and their impacts

The BIA helps you anticipate various disruptions and their potential impacts on your business, such as:

  • Data breaches or cyberattacks could harm your security 
  • Scheduling delays could mess up your plans 
  • Natural disasters or power outages could stop your operations 
  • Equipment failures could slow things down 
  • Losing key employees or suppliers could be a big setback

Additional reading

ISO 27001 Internal Audit: Everything You Need to Know

Getting an ISO 27001 certification largely depends on how effective your internal audits are. An ISO 27001 internal audit tells you if your ISMS is actually working as intended, whether your controls are in place, and if there are any gaps you need to fix before you meet the external auditor. And here’s the part…

Cyber Hygiene: Maintaining Secure and Healthy Systems

TL,DR: Cyber hygiene means routine security practices that protect networks, devices, and sensitive data. Core controls include passwords, security software, backups, firewalls, MFA, and employee awareness. The article covers cyber hygiene benefits, rollout steps, routine-check fatigue, device sprawl, and executive buy-in. Vint Cerf, one of the internet’s pioneers, is said to have coined the term…

How To Define Your SOC 2 Scope

TL;DR SOC 2 scope defines the parameters for evaluating internal controls, covering services, systems, policies, processes, and people assessed against 5 trust principles: security, availability, processing integrity, confidentiality, and privacy Preparing scope follows key steps: choose relevant Trust Service Criteria based on customer expectations, identify in-scope systems and infrastructure, define organizational boundaries, document subservice organizations,…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.