Page 232 - (ISC)² CISSP Certified Information Systems Security Professional Official Study Guide
P. 232
time to merge the two prioritized lists, which is more of an art than a
science. You must sit down with the BCP team and representatives
from the senior management team and combine the two lists into a
single prioritized list.
Qualitative concerns may justify elevating or lowering the priority of
risks that already exist on the ALE-sorted quantitative list. For
example, if you run a fire suppression company, your number-one
priority might be the prevention of a fire in your principal place of
business despite the fact that an earthquake might cause more
physical damage. The potential loss of reputation within the business
community resulting from the destruction of a fire suppression
company by fire might be too difficult to overcome and result in the
eventual collapse of the business, justifying the increased priority.

