Is in ISO 22301 mentioned any specific kilometer distance between the fail-over data centers ? I Know that the selection of DC location/provider is a complex thing and many things are to be considered, but the people (mangers) are kind of discussing all over again a Number X or Y. If there would be some concrete number in ISO 22301 (or PCI-DSS or another ISO/??? market/industry relevant/authoritative document, the discussion could be over). Please advice.
Answer: ISO 22301 and most regulations and industry practices do not define any specific distance to recovery sites because, as you mention, many factors can affect what would be considered a "safe" distance. From our experience I suggest you to start the discussion suggesting a distance between 30 miles (50 kilometers) and 100 miles (160 kilometers) away from your primary location and from that analyse your organization's context (geographic situation, available resources, required investment, etc.).