Expert Advice Community

Guest

RTO and MAO

  Quote
Guest
Guest user Created:   Feb 13, 2020 Last commented:   Feb 13, 2020

RTO and MAO

Can the RTO be more than the MAO?

1 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Feb 13, 2020

 Considering ISO 22300 vocabulary (which can be found here: https://www.iso.org/obp/ui/#iso:std:iso:22300:ed-2:v1:en)

  • MAO: maximum acceptable outage, the time it would take for adverse impact to become unacceptable
  • RTO: recovery time objective, the period of time following a disruptive event within which operation is resumed, or resources are recovered.

Considering these definitions, the RTO value only makes sense if it is smaller than MAO, so RTO cannot be greater than MAO.

In fact, there is a note for RTO in the standard defining this relation: the recovery time objective is less than the time it would take for the adverse impacts to become unacceptable.

For further information about RTO, see:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Feb 13, 2020

Feb 13, 2020

Suggested Topics

Guest user Created:   Nov 04, 2020 ISO 27001 & 22301
Replies: 1
0 0

Queries on ISO22301, BCM

Guest user Created:   Jan 12, 2016 ISO 27001 & 22301
Replies: 1
0 0

MBCO, RTO, MPTD/MAO