SSCP Systems Security Certified PractitionerIncident Response and RecoveryHard
During a significant data breach, the incident response team determines that sensitive customer data has been exfiltrated. The organization has an RTO of 4 hours and an RPO of 1 hour for this data. Which of the following actions, if not already performed, is most critical to address the RPO requirement?
- AImplementing long-term forensic data retention for all affected systems.
- BNotifying affected customers within 72 hours as per regulatory requirements.
- CEnsuring the incident response team can restore services within 4 hours.
- DRestoring systems from a backup taken 30 minutes prior to the breach.
Show answer & explanationAnswer & explanation
Correct answer: D. Restoring systems from a backup taken 30 minutes prior to the breach.
The RPO (Recovery Point Objective) of 1 hour means that the maximum acceptable data loss is 1 hour. Restoring from a backup taken 30 minutes prior to the breach directly addresses this by minimizing data loss to within the RPO.
Why the other options are wrong
- A. Long-term forensic data retention is important for post-incident analysis and legal purposes, but it does not directly address the RPO of minimizing data loss.
- B. Customer notification is a regulatory and public relations step, not a technical action to meet an RPO.
- C. This addresses the RTO (Recovery Time Objective) of 4 hours, which is about system availability, not the RPO which is about data loss.
Recovery Point Objective (RPO)
The maximum acceptable amount of data loss, measured in time, that an organization can tolerate after a disruption.
- Determines how frequently data must be backed up.
- A key metric for disaster recovery planning.
- Expressed as a duration (e.g., 1 hour, 24 hours).
Memory trick: RPO is data 'P'oint, RTO is 'T'ime to restart.