Certified Information Security Manager (CISM)Incident ManagementMedium
A company's CISO is reviewing the Business Continuity Plan (BCP) and discovers that several critical business functions lack a defined Recovery Point Objective (RPO). What is the MOST significant risk associated with an undefined RPO for a critical business function?
- AIncreased cost of recovery infrastructure and services.
- BInability to determine the maximum tolerable downtime (MTD).
- CPotential for excessive data loss during a recovery event.
- DFailure to identify the necessary recovery time objective (RTO).
Show answer & explanationAnswer & explanation
Correct answer: C. Potential for excessive data loss during a recovery event.
The RPO defines the maximum acceptable amount of data loss measured in time (e.g., 1 hour of data loss). If an RPO is undefined, there is no clear target for how much data can be lost, leading to a high risk of recovering an outdated state and thus excessive data loss that impacts business operations significantly.
Why the other options are wrong
- A. While an undefined RPO might lead to suboptimal recovery strategies, the direct and most significant risk is data loss, not necessarily increased cost.
- B. MTD (how long systems can be down) is distinct from RPO (how much data can be lost); one doesn't directly prevent the other's definition.
- D. RPO and RTO (how fast systems must be recovered) are related but distinct metrics; an undefined RPO doesn't prevent defining an RTO, though it complicates the overall recovery strategy.
Recovery Point Objective (RPO)
The maximum amount of data (measured in time) that an organization can afford to lose during a disaster or incident.
- Determined by business impact analysis.
- Dictates backup frequency and replication strategies.
- Expressed as a time interval (e.g., 1 hour, 24 hours).
Memory trick: RPO is about Point in time (data), RTO is about Time to operate (system).