Recovery objectives
As we saw in Figure 15.1, BC planning typically begins with a BIA. The goal of a BIA is to identify the critical systems and services and ensure that sufficient controls are put in place so they operate within their recovery point objective (RPO) and recovery time objective (RTO), which are two key metrics to determine the criticality of an application.
The RPO is the maximum amount of data that an organization can afford to lose without a material impact, whereas the RTO is the maximum amount of time an application can remain unavailable before having a material impact on the business.
A similar metric to the RPO is the maximum tolerable downtime (MTD), that is, the maximum amount of time stakeholders are willing to accept for a business process outage that includes all impact considerations.
These metrics are illustrated in the following figure:
Figure 15.2 – The relationship between the RPO, RTO, and MTD
A risk practitioner...