ISC2 Certified in Cybersecurity (CC)Security PrinciplesMedium
A financial institution is implementing a new system for processing high-value transactions. They want to ensure that if a system failure or data corruption occurs, the system can be restored to a known good state from a recent backup with minimal data loss. The goal is to limit the maximum acceptable period of data loss measured in time. Which metric is the institution primarily concerned with when addressing this requirement?
- ARecovery Time Objective (RTO)
- BMean Time To Recover (MTTR)
- CAnnualized Loss Expectancy (ALE)
- DRecovery Point Objective (RPO)
Show answer & explanationAnswer & explanation
Correct answer: D. Recovery Point Objective (RPO)
The Recovery Point Objective (RPO) defines the maximum acceptable amount of data loss measured in time. It determines how far back in time data must be recovered to after an outage or data corruption event.
Why the other options are wrong
- A. RTO measures the maximum acceptable downtime, not data loss.
- B. MTTR measures the average time it takes to repair a failed system, not the amount of data loss.
- C. ALE is a financial calculation of expected loss per year, unrelated to recovery time or data loss objectives.
Recovery Point Objective (RPO)
The maximum acceptable amount of data (measured in time) that an application can afford to lose during a disaster.
- Determines backup frequency.
- Measured in units of time (e.g., 1 hour, 1 day).
- Lower RPO means less data loss but higher cost/complexity.
Memory trick: RPO is about the 'Point' in time for data recovery, how much data you can 'lose'.