← All Cheat Sheets
Recovery Metrics (RTO, RPO, MTD)
Recovery time, point, and tolerable downtime explained.
Recovery Metrics (RTO, RPO, MTD)
Business continuity and disaster recovery metrics that define how quickly and completely an organization must recover. These are heavily tested on the CISA exam.
Core Recovery Metrics
| Metric | Full Name | Definition | Determines |
|---|---|---|---|
| RPO | Recovery Point Objective | Maximum acceptable data loss measured in time | Backup frequency |
| RTO | Recovery Time Objective | Maximum acceptable downtime before recovery | Recovery strategy (hot, warm, cold site) |
| MTD | Maximum Tolerable Downtime | Total time the business can survive without the function | Overall recovery priority |
| WRT | Work Recovery Time | Time to verify and restore data integrity after systems are back | Post-recovery testing effort |
Critical Relationship
MTD = RTO + WRT
RTO must always be less than MTD. If RTO exceeds MTD, the business suffers unacceptable harm.
Recovery Site Types
| Site Type | Equipment | Data | Recovery Time | Cost |
|---|---|---|---|---|
| Hot Site | Fully equipped | Near real-time replication | Minutes to hours | Highest |
| Warm Site | Partial equipment | Recent backups | Hours to days | Moderate |
| Cold Site | Space and power only | Offsite backups | Days to weeks | Lowest |
| Mobile Site | Transportable unit | Brought in | Hours to days | Variable |
| Reciprocal | Shared with partner | Varies | Variable | Low (mutual agreement) |
BIA and Recovery Planning
- The Business Impact Analysis (BIA) determines RPO, RTO, and MTD
- BIA identifies critical business functions and their dependencies
- Recovery strategies must be tested regularly (tabletop, walkthrough, full interruption)
- The full interruption test is the most thorough but carries the most risk
- Plans should be updated after every test, organizational change, or actual incident
CISA Exam Tip
The BIA is performed before selecting recovery strategies. RPO drives backup decisions. RTO drives site selection. MTD is set by business leadership, not IT.
Ready to test your knowledge?
Put this cheat sheet to work with scenario-based CISA practice questions.
Start Free