One of the first tasks to be undertaken is to prepare a comprehensive list of the potentially serious incidents that could affect the normal operations of the business. This list should include all possible incidents no matter how remote the likelihood of their occurrence.
Against each item listed the project team or manager should note a probability rating. Each incident should also be rated for potential impact severity level. From this information, it will become much easier to frame the plan in the context of the real needs of the organization.
SUPPORTING TOOLS & PRODUCTS
Almost synonymous with the term 'security risk analysis', COBRA is used by countless enterprises and many governments across the world. Quite simply, it is a tool used to make what can be a complex methodology, as simple as possible.
It's link with disaster recovery and business continuity is that it is built to perform the above tasks... which are formally called business impact analysis and risk analysis.