RPO, RTO, WRT and MTD on One Recovery Timeline
How RPO, RTO, WRT and MTD sit on a single outage timeline, and why MTD is the ceiling the other three have to fit inside.
Running security day to day and recovering when it fails: logging and monitoring, incident handling, evidence and chain of custody, change management, and the disaster recovery metrics, sites and plans that decide how fast a business gets back on its feet.
The ISC2 CISSP exam outline lists these areas for Domain 7 and gives the domain a weighting of 13%. The wording below is a plain-English paraphrase; the outline itself is the source.
How RPO, RTO, WRT and MTD sit on a single outage timeline, and why MTD is the ceiling the other three have to fit inside.
Hot, warm, cold and cloud recovery sites compared. The BIA sets the RTO, and the RTO picks the site. A CISSP insight with a manager mindset.
The five phases of the BCP lifecycle, how BCP differs from DRP, who is accountable for the programme, and the six testing methods in order of disruption.
What End of Life and End of Support mean, why only the second date is a security cliff, and how CISSP scenarios may test the difference between them.
The maximum time a business process can be down before recovery must complete. A CISSP Domain 7 metric: RTO plus WRT must fit inside the Maximum Tolerable Downtime (MTD).
The maximum data loss a business can tolerate, measured as a time window backwards from a disruption. RPO drives backup frequency: a one-hour RPO needs backups at least hourly.
The time after a system is technically restored spent verifying data, reconciling records, and resuming normal processing. RTO plus WRT must fit inside the MTD.
The longest a business process can be unavailable before the damage becomes unacceptable. The outer boundary every other recovery metric must fit inside: RTO plus WRT.
Fully equipped alternate facility with hardware, software, and near-real-time data replication in place, able to take over within hours; the fastest and most expensive option.
Alternate facility with hardware and connectivity in place but no current data; backups must be restored on activation, giving recovery in days at a fraction of hot-site cost.
Alternate facility providing only space, power, and environmental support; hardware and data arrive after the disaster, so activation takes weeks, at the lowest standing cost.
The IT-focused plan for restoring systems, infrastructure and data after a failure. One component beneath the business continuity plan, not a synonym for it.
Discussion-based walkthrough in which the response team talks through a disaster scenario against the plan, validating roles and decisions without touching any production system.
Documented, unbroken record of who collected, handled, transferred, and stored evidence, with times and locations, proving it was not altered between collection and court.
Formal process taking every change through request, approval, testing, and rollback planning before implementation, so changes are deliberate, documented, and reversible.
Managed lifecycle for handling security incidents: detection, response, mitigation, reporting, recovery, remediation, and lessons learned, limiting damage and preventing recurrence.
Centralised platform that aggregates logs from across the estate, normalises them, correlates events from multiple sources in near real time, and raises alerts for investigation.
Monitoring control that inspects network traffic or host activity for signs of attack and raises alerts without blocking; detection is signature-based or anomaly-based.
Decoy system with no production value, deployed to attract attackers so their tools and methods can be observed; any interaction with it is suspicious by definition.
Watching traffic that leaves the network for signs of data exfiltration, command-and-control beacons, and policy violations; the outbound counterpart to inbound-facing defences.
Running untrusted code in an isolated environment so its behaviour can be observed and contained without risk to production; the basis of malware detonation and browser isolation.
Reading is half of it. Scenario questions in this domain tend to turn on the distinctions above, and the quickest way to find out which ones you hold is to answer some. The CISSP practice tests cover all eight domains with an explanation for every answer, and the free assessment gives you a baseline first.