Assign topic to the user
Answer: MAO and RTO are similar things, but not the same. MAO is maximum outage for a particular activity, whereas RTO is targeted time for recovery, and is usually shorter then MAO.
It works like this: first you define MAOs for all your activities, then see if there are any interdependencies, and once you realize that e.g. activity A depends on activity B, you will need to decrease the activity B's RTO to the time that will fit the MAO of the activity A.
This principle is explained further in this article: How to implement business impact analysis (BIA) according to ISO 22301 https://advisera.com/27001academy/knowledgebase/how-to-implement-business-impact-analysis-bia-according-to-iso-22301/
Comment as guest or Sign in
Sep 13, 2018