An organization is developing a Business Continuity Plan (BCP). Which analysis is performed first to identify critical business functions and their dependencies?
A Business Impact Analysis identifies critical business functions, quantifies the impact of their disruption, and maps dependencies on systems, people and suppliers, producing the foundation from which recovery priorities and continuity strategies are later derived.
Why this answer
The Business Impact Analysis (BIA) is performed first in BCP development because it identifies critical business functions, their dependencies, and the impact of disruption over time. This data drives recovery time objectives (RTO) and recovery point objectives (RPO), which then inform the rest of the BCP. Risk assessment and other analyses come after the BIA because you must know what to protect before assessing threats to it.
Exam trap
The trap is assuming risk assessment comes first because it sounds foundational — but BCP best practice (and ISO 22301) places the BIA first to define what matters before assessing threats.
How to eliminate wrong answers
Option A is wrong because risk assessment identifies threats and vulnerabilities to assets, but it is performed after the BIA has determined which business functions and assets are critical. Option C is wrong because vulnerability assessment focuses on technical weaknesses in systems, not on identifying critical business functions and their dependencies. Option D is wrong because gap analysis compares current capabilities against desired state and is typically done after the BIA and risk assessment to plan improvements.