RiskPilot Website FR GitHub

Incidents and continuity #

Incidents #

The Resilience menu manages title, description, severity, status, responsible, detection, unavailability, affected people, evidence, regulatory notification and feedback. The timeline adds timestamped events.

Combine assets, third parties, risks and actions of the same tenant. A closing with required notification is refused as long as the mailing date is missing.

BIA, PCA and PRA #

A business impact analysis (BIA) describes processes, criticality, scope, responsible, impacts, dependencies and objectives:

  • MTPD: maximum tolerable interruption duration;
  • RTO: target recovery time, which must remain less than or equal to the MTPD;
  • RPO: maximum admissible data loss.

Document PCA/PRA procedures and next exercise date.

Exercises #

Record date, scenario, participants, result, deviations and improvements. Do not mark an exercise as successful without proof or addressing discrepancies.

Roles and prerequisites #

Create scopes, assets, third parties, risks, actions and responsible parties before linking them. The incident owner coordinates the operational cycle; the process owner maintains the BIA and continuity procedures.

Create an incident #

FieldUse
Title / descriptionknown facts, scope and context
Severitylow, medium, high or critical
Statusprocessing stage
Responsibleinternal coordinator
Detected onbeginning of known chronology
Unavailabilityimpact duration in hours
Affected peoplehuman impact measurement
Evidenceprotected references
Notification required / dateregulatory monitoring
Feedbacklessons after stabilization

The statuses follow Detected, Qualified, Contented, Eradicated, Recovered and Closed. Don’t skip a step without documenting the decision.

Treatment procedure #

  1. Record the incident upon detection with confirmed facts.
  2. Qualify severity, impacts and owner.
  3. Add each event to the timeline with date and actor.
  4. Link assets, third parties, risks and tenant actions.
  5. Document containment, eradication and recovery.
  6. Determine reporting obligations.
  7. Add evidence and feedback.
  8. Close only after mandatory checks.

If regulatory notification is required, the dispatch date becomes mandatory before closing.

Timeline and evidence #

The chronology must distinguish fact, hypothesis and decision. Use a consistent time frame and avoid retrospectively changing an event without explanation. Evidence may include ticket references, logs, reports or protected documents.

Build a BIA #

Create the business process, choose criticality, scope and owner, then describe impacts and dependencies. Quantify:

ObjectiveQuestion
MTPDafter how long does the interruption become intolerable?
RTOHow soon should the service resume?
RPOwhat maximum data loss is admissible?

RiskPilot checks that the RTO does not exceed the MTPD. Justify values ​​by business impacts rather than current technical capabilities.

PCA and PRAThe PCA procedure maintains priority activities during the disruption. The PRA procedure restores technical means and data. Document triggering, roles, communications, fallback solutions, recovery order, dependencies and return to normal criteria. #

Organize an exercise #

  1. Choose a risk-related scenario.
  2. Set date, objectives and participants.
  3. Execute without putting production at risk.
  4. Record results, deviations and improvements.
  5. Assign improvements and plan the next exercise.

Controls and indicators #

Track incidents by severity/status, qualification and recovery time, process without recent exercise, RTO/MTPD inconsistencies and unaddressed improvements.

Common errors #

An absent asset or third party may be non-tenant. A denied close may report the missing notification date. An RTO greater than MTPD is inconsistent. Do not confuse backup, PRA and PCA: they serve complementary objectives.

Example #

Unavailability of the identity provider blocks the portal. The incident is linked to the third party, the assets concerned and the risk of dependency. The PCA provides for controlled emergency access; the PRA describes the restoration of the IdP; the exercise reveals an outdated contact list that becomes an improvement.