<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>A Risk Management Framework for Business Continuity in Agriculture</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Athanasios Podaras</string-name>
          <email>athanasios.podaras@tul.cz</email>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Dana Nejedlová</string-name>
          <email>dana.nejedlova@tul.cz</email>
        </contrib>
      </contrib-group>
      <fpage>408</fpage>
      <lpage>414</lpage>
      <abstract>
        <p>The article introduces a modern risk management framework, which can serve as a driver for an objective business continuity management, especially in agriculture where disaster recovery issues are of major importance due to the existence of multiple environmental hazards. The method is supported by a user-friendly interface developed by the authors in Visual Basic for Applications and the MS excel software. The impact-weight value of each factor is mathematically calculated while the probability of occurrence for each factor is determined based on a semi-quantitative one-to-five scale.</p>
      </abstract>
      <kwd-group>
        <kwd>business continuity</kwd>
        <kwd>risk management</kwd>
        <kwd>agriculture</kwd>
        <kwd>visual basic for applications (VBA)</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>
        Business continuity policy is nowadays a crucial issue for the enterprises of the
private sector as well as the public organizations and institutions. However, in the
agricultural sector “the preservation of processes is not dependent solely on information
systems, but on the continuity of all processes that lead to the fulfillment of the
global goal of agriculture”
        <xref ref-type="bibr" rid="ref5">(Hájek and Urbancová, 2013)</xref>
        . This goal involves the
amelioration of outdated technical and technological infrastructure for eliminating the
negative environmental impact
        <xref ref-type="bibr" rid="ref4">(Fedyszak-Radziejowska, 2011)</xref>
        .
      </p>
      <p>
        On the other hand, risk assessment (RA) and business impact analysis (BIA) are
crucial elements for understanding the organization
        <xref ref-type="bibr" rid="ref7">(ISO 22301, 2012)</xref>
        in order to
implement an integrated business continuity management strategy. “Risks are part of
every business operation and can never be avoided completely. To minimize the
danger of corporate crisis, a conscientious and responsible approach to the handling
of risks and the resulting impact on business is essential. Unforeseen events pose an
especially great challenge for companies and require quick decision-making and
immediate reactions”
        <xref ref-type="bibr" rid="ref2">(Breuer et al, 2015)</xref>
        .
      </p>
      <p>
        “Risk management in agriculture is now an essential tool for farmers to anticipate,
avoid and react to shocks. An efficient risk management system for agriculture will
preserve the standard of living of those who depend on farming, strengthen the
viability of farm businesses, and provide an environment which supports investment in
the farming sector
        <xref ref-type="bibr" rid="ref11">(OECD, 2011)</xref>
        .
      </p>
      <p>The goal of the current paper is to describe a modern risk management framework
for calculating possible time deviations from defined by business continuity or
domain experts recovery timeframes for bringing back to their normal state interrupted
critical business activities. The framework includes the application of the
mathematical risk magnitude formula in order to predict time deviations (in absolute value)
from the initially defined by experts recovery time. Moreover, the recovery process is
influenced by unexpected factors which, if emerging, they can significantly delay the
recovery procedure for a business function, information system or business process.
The weights of these factors are mathematically calculated, while the probability of
occurrence for each factor is semi-quantitatively determined. Finally the proposed
contribution estimates a new recovery time by considering the aforementioned
factors. The calculations are implemented via a VBA user friendly interface in MS
Excel. Methods and Tools</p>
    </sec>
    <sec id="sec-2">
      <title>1.1 Risk magnitude estimation</title>
      <p>
        The current approach is based on a semi-quantitative method for probability
determination regarding the occurrence of factors which can cause a prolonged information
system/business function interruption. The illustrated idea, is based on the
assumption when no past data is available of similar crisis situation in order to determine the
probability with pure quantitative mathematical tools. In such cases,
semiquantitative scales can be defined. According to
        <xref ref-type="bibr" rid="ref3">(FAO, 2009)</xref>
        , a semi-quantitative
risk assessment “does not require the same mathematical skills as quantitative risk
assessment, nor does it require the same amount of data, which means it can be
applied to risks and strategies where precise data are missing”. Our currently presented
model uses a one-to-five (1-5) scale for defining the probability of an unexpected
factor’s presence. The Risk Magnitude (RM) is estimated according to the following
formula:
      </p>
      <p>RM = Impact * Probability
(1)</p>
      <p>In the proposed framework, the Risk Magnitude for a number N of specific factors
is estimated according to the following equation (Eq. 2):</p>
      <p>N
RM = ∑W P</p>
      <p>i i
i=1
(2)</p>
      <p>The model’s representation is based on the following steps (Fig. 1). The RTE
value is initially determined based on business function recovery tests when unexpected
situations are not considered (ideal conditions).</p>
    </sec>
    <sec id="sec-3">
      <title>1.2 Weight Assignment of Factors with the Rank Order Centroid (ROC)</title>
    </sec>
    <sec id="sec-4">
      <title>Method</title>
      <p>
        Part of the proposed risk management framework is the decision making process
regarding the impact of the factor which can delay the business function recovery
process. Due to the fact that our model is based on the concept of a non-arbitrary
weight assignment, the selected technique for assigning weights is the Rank Order
Centroid method. In the proposed framework, the weights of the factors are
quantitatively estimated according to the Rank Order Centroid Method (ROC)
        <xref ref-type="bibr" rid="ref1">(Barron and
Barett, 1996)</xref>
        as follows:
      </p>
      <p>Wi =
1 m 1</p>
      <p>∑ , and
m i=1 n
m
∑Wi = 1
i=1
(3)</p>
    </sec>
    <sec id="sec-5">
      <title>1.3 Visual Basic for Applications (VBA Excel) – Applied Cases in Agriculture,</title>
    </sec>
    <sec id="sec-6">
      <title>Food and Environment</title>
      <p>
        The Visual Basic for Applications is utilized in Microsoft Office Tools, such as
Microsoft Excel in order to ameliorate and strengthen its future developing functions. It
was developed based on the very popular programming language Visual Basic and
took after its language structure
        <xref ref-type="bibr" rid="ref12">(Wang and Hu, 2012)</xref>
        . Multiple software based
activities in agriculture, food and environment have been developed in VBA and MS
Excel
        <xref ref-type="bibr" rid="ref8 ref9">(Li et al, 2007, Ma et al, 2003)</xref>
        .
      </p>
      <sec id="sec-6-1">
        <title>Results</title>
      </sec>
    </sec>
    <sec id="sec-7">
      <title>2.1 The proposed RM Framework</title>
      <p>The weight assignment formula (Eq. 3) prohibits the arbitrary weight assignment of
the presence for a given factor during the BF Recovery process. According to the
proposed method, if RTE is the time required to recover a business function in ideal
conditions, a non-ideal recovery case should estimate the recovery time as follows:
RTE1 = RTE + RTE
TimeDeviation = RTE</p>
      <p>RM</p>
      <p>,
100</p>
      <p>RM
100
and</p>
      <p>RM
RTE1 = 2 ± 2</p>
      <p>
        100
1.58Hours(RTO)
where RTE1 is the new Recovery Time. A practical example is illustrated for the
better interpretation of the approach. Example: If RTE= 2Hours, Number of Factors
(N) = 4, WF1= 0.521, WF2= 0.271, WF3= 0.146, WF4= 0.062 and we assume that
semiquantitatively defined probabilities of occurrence for each factor are PF1= 2, PF2= 5,
PF3= 2, PF4= 4 then:
= 2 ± 0.42 = 2.42Hours(MAO)
or
It should be noticed that the RM values are normalized by multiplying the weight
values of each factor with 10 for obtaining more rational results
(w1+w2+w3+w4=10). The business process aspect of the proposed framework is
demonstrated via an ORD Diagram which is part of the Business Object Relation
Model (BORM) (Fig.2), which is used for modeling agricultural and environmental
processes
        <xref ref-type="bibr" rid="ref10">(Nedvedova, 2015)</xref>
        .
      </p>
      <p>Moreover, the above delineated risk management framework, is also supported by
a VBA Excel tool which is developed by the authors and implements all the above
stated calculations (Fig. 3).</p>
      <p>The initial form is loaded by the user in order to estimate the time deviation from
the estimated in ideal recovery testing conditions by the business continuity experts.
The user is prompted to store the input parameters, which are:
-Proposed RTE Value or Proposed Recovery Time
-Number of Factors, which are unexpected factors which could trigger the
extended recovery time for a given business function,
-Probability of occurrence for each factor based on the semi-quantitative risk
assessment 1-5 scale. The output values are the risk magnitude RM, the ratio RM/100,
new RTE1 when hard recovery scenarios are considered, the Time Deviation from
the initially expected recovery time and the weights for all the potential factors based
on the Rank Order Centroid approach.
3</p>
      <sec id="sec-7-1">
        <title>Discussion</title>
        <p>Even if the proposed risk assessment framework is simple to use, specific issues
should be further discussed and clarified. The first issue is the so called
semiquantitative probability of occurrence of each unexpected situation (factor). Simple
risk management models avoid complex mathematical quantification methods of a
given probability. Moreover, quantification is not suggested when past data for
similar disasters is not available to experts who implement risk analysis for a more
detailed business continuity management.</p>
        <p>
          Another point, which requires further explanation, is the absolute value
determined by for the Time Deviation from the initially defined RTE value. The model
follows the principle that a reasonable recovery time (RTO) can be based on the
negative time deviation, and, respectively, a maximum accepted timeframe (MTD)
          <xref ref-type="bibr" rid="ref6">(Harris, 2010)</xref>
          that can justify the unavailability of a BF is determined via a positive Time
Deviation.
4
        </p>
      </sec>
      <sec id="sec-7-2">
        <title>Conclusion – Future work</title>
        <p>The current paper illustrated a risk management framework, which supports an
efficient business continuity strategy in organizations. The framework can be
successfully implemented within the agricultural domain where automation is highly demanded
for precision agriculture, irrigation techniques, gas emissions control and multiple
other critical business activities. The framework is supported by a developed by the
authors VBA excel standalone software environment. Its adjustment to other
agricultural IT systems is currently considered as a future step but has not yet been
achieved. Additional future implementation involves the proposed, by the developed
framework/VBA Tool, corrective recovery actions and risk mitigation policies for an
integrated business continuity strategy.</p>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Barron</surname>
            ,
            <given-names>F. H.</given-names>
          </string-name>
          <article-title>and</article-title>
          <string-name>
            <surname>Barrett</surname>
            ,
            <given-names>B. E.</given-names>
          </string-name>
          (
          <year>1996</year>
          )
          <article-title>Decision Quality Using Ranked Attribute Weights</article-title>
          .
          <source>Management Science</source>
          ,
          <volume>42</volume>
          (
          <issue>11</issue>
          ): pp.
          <fpage>1515</fpage>
          -
          <lpage>1523</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Breuer</surname>
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Haasis</surname>
            <given-names>HD.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Siestrup</surname>
            <given-names>G.</given-names>
          </string-name>
          (
          <year>2015</year>
          )
          <article-title>Operational Risk Response for Business Continuity in Logistics Agglomerations</article-title>
          . In: Dethloff J.,
          <string-name>
            <surname>Haasis</surname>
            <given-names>HD.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kopfer</surname>
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kotzab</surname>
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Schönberger</surname>
            <given-names>J</given-names>
          </string-name>
          . (eds) Logistics
          <source>Management. Lecture Notes in Logistics</source>
          . Springer.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3. FAO, (
          <year>2009</year>
          )
          <article-title>Semi-quantitative risk characterization. Risk characterization of microbiological hazards in food</article-title>
          , pp.
          <fpage>37</fpage>
          -
          <lpage>51</lpage>
          . [Online],
          <source>[Retrieved April 20</source>
          ,
          <year>2017</year>
          ], http://www.fao.org/docrep/012/i1134e/i1134e04.pdf.
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Fedyszak-Radziejowska</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          (
          <year>2011</year>
          )
          <article-title>Společná Zemědělská Politika EU: Co a Jak Měnit Po Roce</article-title>
          <year>2013</year>
          ? [Online]: http://www.revuepolitika.cz/clanky/1583/.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Hájek</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          , and
          <string-name>
            <surname>Urbancová</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          (
          <year>2013</year>
          )
          <article-title>Using of Business Continuity Standards in Agriculture, Industry and ICT</article-title>
          .
          <source>Agris Online Papers in Economics and Informatics</source>
          ,
          <volume>5</volume>
          (
          <issue>4</issue>
          ), p.
          <fpage>55</fpage>
          -
          <lpage>67</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Harris</surname>
            <given-names>S.</given-names>
          </string-name>
          ,
          <article-title>Business continuity and Disaster Recovery: CISSP All in One Exam Guide</article-title>
          , 5th ed.,
          <string-name>
            <surname>McGraw-Hill</surname>
          </string-name>
          , New York, pp.
          <fpage>777</fpage>
          -
          <lpage>840</lpage>
          (
          <year>2010</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7. ISO 22301 (
          <year>2012</year>
          )
          <article-title>Societal security - Business continuity management systems -Requirements</article-title>
          . Switzerland: International Organization for Standardization.
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Li</surname>
            ,
            <given-names>Z.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yi</surname>
            ,
            <given-names>Q.C.</given-names>
          </string-name>
          , ,
          <string-name>
            <surname>Li</surname>
            ,
            <given-names>Y.J.</given-names>
          </string-name>
          , and
          <string-name>
            <surname>Zhang</surname>
            ,
            <given-names>D. Q.</given-names>
          </string-name>
          (
          <year>2007</year>
          )
          <article-title>Application of Excel in Hydrologic Frequency Computation</article-title>
          ,
          <source>Journal of Water Resources and Architectura Engineering</source>
          , Feb.
          <year>2007</year>
          , p.
          <fpage>95</fpage>
          -
          <lpage>97</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <surname>Ma</surname>
            ,
            <given-names>X.X.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Wang</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          , and
          <string-name>
            <surname>Ma</surname>
            ,
            <given-names>Q.H.</given-names>
          </string-name>
          (
          <year>2003</year>
          )
          <article-title>Application of VBA in the Optimal Selection of Hydrologic Statistic Parameters</article-title>
          , Journal of Zhengzhou University of Technology, Feb.
          <year>2003</year>
          , p.
          <fpage>67</fpage>
          -
          <lpage>69</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>Nedvedova</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          (
          <year>2015</year>
          )
          <article-title>Flood protection in historical towns</article-title>
          .
          <source>Sustainable development</source>
          , Vol.
          <volume>168</volume>
          , Southampton: WIT Press.
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>OECD</surname>
          </string-name>
          (
          <year>2011</year>
          )
          <article-title>Risk Management in Agriculture: What Role for Governments?</article-title>
          [Online]: https://www.oecd.org/agriculture/agricultural-policies/49003833.pdf,
          <source>[Retrieved April 20</source>
          ,
          <year>2017</year>
          ].
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>Wang</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          , and
          <string-name>
            <surname>Hu</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          (
          <year>2012</year>
          )
          <article-title>Hydropower Computation Using Visual Basic for Application Programming</article-title>
          ,
          <source>Physics Procedia</source>
          ,
          <year>2012</year>
          (
          <volume>24</volume>
          ), p.
          <fpage>37</fpage>
          -
          <lpage>43</lpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>