Expert Advice Community

Guest

Working out the RTO and RPO

  Quote
Guest
Guest user Created:   Feb 02, 2019 Last commented:   Feb 02, 2019

Working out the RTO and RPO

I’ve completed the Business Impact Analysis questionnaires and I need to work out the RTO and RPO. Do I need to work out the RTO and RPO per application and database for each activity (department)?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Feb 02, 2019

Answer:

In your scenario, the RTO refers to the time required to resume an application operation, while the RPO refers to the acceptable data loss on a database.
Considering that, you can establish a single pair of RTO and RPO for the most critical applications and databases in your BIA, and from those you can derive other RTO's and RPO's for specific application and database when needed. For example you can set a RTO of 4h for an application and a RPO of 1 day for a database from your most critical activities, but you can identify that for other activities you can define a RTO of 1 day for applications and a RPO of 5 days for databases. This way you can optimize your resources, allocating them where they are more needed to recover from a disruptive event.

This article will provide you further explanation about RPO and RTO:
- What is the dif ference between Recovery Time Objective (RTO) and Recovery Point Objective (RPO)? https://advisera.com/27001academy/knowledgebase/what-is-the-difference-between-recovery-time-objective-rto-and-recovery-point-objective-rpo/

This material will also help you regarding RPO and RTO:
- Book Becoming Resilient: The Definitive Guide to ISO 22301 Implementation https://advisera.com/books/becoming-resilient-the-definitive-guide-to-iso-22301-implementation/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Feb 02, 2019

Feb 02, 2019

Suggested Topics

Guest user Created:   Mar 01, 2023 ISO 27001 & 22301
Replies: 1
0 0

ISO 27001 query

Guest user Created:   Jun 14, 2021 ISO 27001 & 22301
Replies: 1
0 0

ISO 27001 query

Guest user Created:   Nov 04, 2020 ISO 27001 & 22301
Replies: 1
0 0

Queries on ISO22301, BCM