SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

When does RTO begin?

  Quote
Guest
Guest user Created:   Jan 12, 2016 Last commented:   Jan 12, 2022

When does RTO begin?

Does RTO begin at time of incident or after assessment of the impact of an incident? To be ISO 22301 certified, will the organization’s definition of the starting point for RTO have to match the ISO’s definition of RTO. The published ISO definition merely states “following an incident” and it is not clear of the specific start time of RTO.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Guest
DejanK Jan 12, 2016

Answer: As you mentioned, ISO 22301 does not give a very precise definition, but the logic of Recovery Time Objective is the following: it should define a time within which an organization must recover a particular activity/process/resource, so that the damage doesn't get too big. Since the damage does not depend on the timing of your assessment and it primarily depends on the total duration of a disruption, this means that the RTO time begins at the moment of an incident occurrence (i.e. at the time the disruption begins).

Quote
1 0
Guest
colin murray Jan 09, 2022

The start time cannot be time of incident. I large enterprises the teams will always try and resolve the issue. Failover is a lot resort in most incidents

 

Quote
0 0
Expert
Rhand Leal Jan 12, 2022

I’m assuming that by failover you mean Disaster Recovery Plan because the failover concept is related to protective controls that automatically takes over when the main system fails, i.e., it is the first resort in most incidents, while the Disaster Recovery Plan refers to the actions to be performed when main facilities/systems cannot be recovered within an acceptable timeframe (i.e., within the Recovery Time Objective – RTO).

Considering that, the RTO needs to be considered from the time the disruption is perceived by the customer (the RTO is defined from the customer point of view), so it needs to start when the disruption is reported or detected.

What happens is that, for example, if you have an RTO of 10 hours and your DRP needs 3 hours to be implemented, the DRP only needs to be started after 7 hours of the start of the incident, and by this time the teams may solve the situation.

For further information, see:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 12, 2016

Jan 12, 2022