ISC2 CISSP (Certified Information Systems Security Professional)Security OperationsEasy

An organization is implementing a new business continuity plan (BCP). As part of this, they are identifying critical business functions and the resources required to support them. A key activity is to determine the maximum period of time that a business function can be inoperative without causing unacceptable damage to the organization. What is this specific metric called?

  1. ARecovery Time Objective (RTO)
  2. BRecovery Point Objective (RPO)
  3. CMaximum Tolerable Downtime (MTD)
  4. DMean Time Between Failures (MTBF)
Show answer & explanation

Correct answer: C. Maximum Tolerable Downtime (MTD)

Maximum Tolerable Downtime (MTD), also known as Maximum Tolerable Period of Disruption (MTPD), is the total amount of time a business process can be inoperative before the organization suffers unacceptable consequences. It's a key input for setting RTOs.

Why the other options are wrong

  • A. RTO is the target time for system recovery, derived from MTD, but not the maximum acceptable business function outage itself.
  • B. RPO is about data loss, not the total time a business function can be down.
  • D. MTBF measures the reliability of a component, representing the average time between failures, not a measure of acceptable downtime.

Maximum Tolerable Downtime (MTD)

MTD, also known as Maximum Tolerable Period of Disruption (MTPD), is the maximum amount of time an organization can tolerate a business function or process to be inoperative before suffering unacceptable consequences.

  • Defines the absolute limit of downtime for a business function.
  • Determined by business impact analysis.
  • RTOs must be less than or equal to MTDs.

Memory trick: MTD is the absolute limit.

More Security Operations questions