ISC2 Certified in Cybersecurity (CC)Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) ConceptsEasy

A small business is developing its cybersecurity strategy. They need to determine the maximum amount of time a critical business function can be offline before suffering unacceptable consequences. Which of the following metrics is MOST appropriate for this determination?

  1. AMaximum Tolerable Downtime (MTD)
  2. BRecovery Point Objective (RPO)
  3. CMean Time To Recover (MTTR)
  4. DRecovery Time Objective (RTO)
Show answer & explanation

Correct answer: A. Maximum Tolerable Downtime (MTD)

Maximum Tolerable Downtime (MTD) defines the longest period a business function can be unavailable without causing irreparable harm. It sets the upper limit for recovery efforts.

Why the other options are wrong

  • B. RPO defines the maximum acceptable data loss, not downtime duration.
  • C. MTTR is an average metric for how long it takes to repair a failed system, not a planning objective for business tolerance.
  • D. RTO defines the target time for system recovery, which should be less than or equal to MTD.

Maximum Tolerable Downtime (MTD)

The maximum period of time a business process or function can be unavailable without causing significant, unacceptable damage or disruption to the organization.

  • Sets the upper limit for recovery time.
  • Determined by business impact analysis.
  • Guides the setting of Recovery Time Objectives (RTOs).

Memory trick: Don't Tolerate Disaster More Than Determined.

More Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts questions