Operational Risk Management
Operational risk means risk related to processes and systems that can interrupt business operations. Managing operational risk is one of the key roles of an information security manager. Some of the key aspects of operational risk that an information security manager must understand are as follows:
- Recovery time objective (RTO)
- Recovery point objective (RPO)
- Service delivery objective (SDO)
- Maximum tolerable outage (MTO)
- Allowable interruption window (AIW)
Recovery Time Objective
The Recovery Time Objective (RTO) is a measure of the user's tolerance to system downtime. In other words, the RTO is the extent of acceptable system downtime. For example, an RTO of 2 hours indicates that an organization will not be overly impacted if its system is down for up to 2 hours.
Recovery Point Objective
The Recovery Point Objective (RPO) is a measure of the user's tolerance to data loss. In other words, the RPO is the...