Page 232 - (ISC)² CISSP Certified Information Systems Security Professional Official Study Guide
P. 232

time to merge the two prioritized lists, which is more of an art than a
               science. You must sit down with the BCP team and representatives

               from the senior management team and combine the two lists into a
               single prioritized list.

               Qualitative concerns may justify elevating or lowering the priority of
               risks that already exist on the ALE-sorted quantitative list. For
               example, if you run a fire suppression company, your number-one
               priority might be the prevention of a fire in your principal place of

               business despite the fact that an earthquake might cause more
               physical damage. The potential loss of reputation within the business
               community resulting from the destruction of a fire suppression
               company by fire might be too difficult to overcome and result in the
               eventual collapse of the business, justifying the increased priority.
   227   228   229   230   231   232   233   234   235   236   237