Expert Advice Community

Guest

Determine RTO for a business process

  Quote
Guest
Guest user Created:   Jan 13, 2016 Last commented:   Jan 13, 2016

Determine RTO for a business process

0 0

Assign topic to the user

ISO 22301 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 22301 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Guest
AntonioS Jan 13, 2016

When we determine the RTO for a business process, should we do it with the assumption of the critical periods or no? For example. payroll processing is not critical during the month, but only on the first day of the month when we do impact assessment, should we suppose the disaster will happen 1st of month? 
When customizing BIA questionnaire for a bank.. what time frames (I mean 0-4 hrs / 8 - 12, etc) should I use? 
 

Answer:

From my point of view, the best is to establish the RTO according the critical day (1st of month), on this way you will have a “demanding” RTO the rest of the month, but it not should be a problem for the organization. Another option from my point of view, is to have 2 RTO, one for the 1st and other for the rest of the month.
Regarding the customization of the BIA questionnaire, the time frames depend on each business, so in some cases it can be also in minutes: 1-15m, 15-30m, etc.
This article about the BIA can be interesting for you “How to implement business impact analysis (BIA) according to ISO 22301” : ht tp://advisera.com/27001academy/knowledgebase/how-to-implement-business-impact-analysis-bia-according-to-iso-22301/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 13, 2016

Jan 13, 2016

Suggested Topics

Guest user Created:   Nov 02, 2018 ISO 27001 & 22301
Replies: 1
0 0

Business strategies

Guest post Created:   Jan 12, 2016 ISO 27001 & 22301
Replies: 2
0 0

BCP and DR

Guest user Created:   Jan 12, 2016 ISO 27001 & 22301
Replies: 1
0 0

Control 17.2 Redundancies