What is Impact Tolerance?
Impact Tolerance is setting the maximum tolerable level of disruption to a critical business service.
What Are the Tasks Required to Set Impact Tolerance?
These are the tasks required to Set Impact Tolerance:
- Identify impact types
- Set impact tolerances for each type
- Link impact tolerances to risk appetite and risk assessment scales
- Set appropriate impact tolerances for critical business services
How to set appropriate impact tolerances for critical business services?
Setting impact tolerances helps organisations define acceptable levels of disruption for critical business services.
The following steps guide the process:
Define Impact Tolerance Levels
Collaboratively establish impact tolerance levels in consultation with key stakeholders. Consider each critical service's maximum acceptable downtime, data loss, financial losses, and customer impact.
Consider Regulatory and Compliance Requirements
Consider specific regulatory or compliance requirements that dictate impact tolerances for particular services or industries. Ensure alignment with legal obligations and industry standards.
Document Impact Tolerance Levels
Document each critical service's agreed-upon impact tolerance levels. This documentation will be a reference point for developing resilience strategies and response plans.
Review and Update
Review and update impact tolerance levels regularly to reflect evolving business needs, technological advancements, and changes in the operating environment.
In addition, Impact Tolerance:
- Represent the point beyond which the harm caused by an operational disruption to the critical business service becomes intolerable.
- Do not factor in the frequency at which operational disruptions are likely to occur.
- Focus on limiting the impact the organisation can tolerate from a single disruption.
- Is different from the recovery time objective (RTO) and the maximum acceptable outage as defined in business continuity planning, as these are time-based.
- Focus on outcome-based objectives: how much, when, and for how long.
"Implement" Phase of OR Planning Methodology
Identify Important Business Services | Map Processes and Resources |
Set Impact Tolerance |
Conduct Scenario Testing | Improve Lesson Learnt | |
More Information About Blended Learning OR-5000 [OR-5] or OR-300 [OR-3]
To learn more about the course and schedule, click the buttons below for the OR-3 Blended Learning OR-300 Operational Resilience Implementer course and the OR-5 Blended Learning OR-5000 Operational Resilience Expert Implementer course.