BCP & DRP for the CISSP exam β RTO, RPO, MTD formulas, the BIA process, plan testing hierarchy, and 10 scenario questions modeled on real exam items.
π§ͺ Take the 10-Question Quiz βCISSP tests your ability to select the right recovery site, calculate RTO/RPO/MTD relationships, and sequence the BIA process correctly.
Select a topic to explore the BIA process, site activation steps, and plan testing hierarchy.
The BIA is always the first step in BCP development β before selecting strategies, before choosing recovery sites, before writing the plan. It identifies what the business actually needs to survive and in what order.
When a disaster is declared, each site type requires a very different activation process. This is why RTO varies so dramatically across site types.
CISSP requires knowing the five testing types in order of rigor, cost, and disruption risk. Each level includes everything from the levels below it.
| Term | Full Name | What It Measures | Who Sets It | Exam Signal |
|---|---|---|---|---|
| RTO | Recovery Time Objective | Max time to restore a system or function | IT / BCP team (constrained by MTD) | "How fast must we restore?" |
| RPO | Recovery Point Objective | Max acceptable data loss (age of backup) | Business owners + BIA | "How much data can we afford to lose?" |
| MTD | Maximum Tolerable Downtime | Longest downtime before business failure | Senior management + BIA | "Absolute maximum before irreversible harm" |
| MTPD | Max Tolerable Period of Disruption | ISO 22301 equivalent of MTD | Senior management + BIA | Same as MTD in ISCΒ² context |
| WRT | Work Recovery Time | Time to restore data after systems are up | IT / Data management team | "Time to clean/restore data after RTO met" |
| MTO | Maximum Tolerable Outage | Alternate term for MTD | Senior management | Treat same as MTD |
| RTO Range | π΄ Hot Site | π‘ Warm Site | π΅ Cold Site | π£ Cloud DR |
|---|---|---|---|---|
| < 1 hour | β Yes | β Unlikely | β No | β Possible |
| 1β8 hours | β Yes | πΆ Possible | β No | β Yes |
| 8β48 hours | β Overkill | β Ideal | πΆ Tight | β Yes |
| > 48 hours | β Overkill | β Yes | β Ideal | β Yes |
All four site types across every CISSP-relevant dimension.
| Criteria | π΄ Hot Site | π‘ Warm Site | π΅ Cold Site | π£ Cloud/Mobile |
|---|---|---|---|---|
| Hardware Pre-installed Basics |
β Yes β fully configured | β Yes β not configured | β No β must procure | β Virtual (cloud) / Mobile trailer |
| Data Currency Basics |
Real-time replication (seconds delay) | Recent backup (hours to days old) | Offsite backup (may be days old) | Configurable β can match hot or warm |
| Staffing Basics |
May be pre-staffed or require relocation | Requires IT staff to configure systems | Requires full IT team on-site for setup | Remote access; minimal on-site staff |
| Geographic Flexibility Basics |
Fixed location, typically near primary | Fixed location | Fixed location | π£ Highest β cloud is global; mobile can deploy anywhere |
| Typical RTO Metrics |
Minutes to hours | Hours to days | Days to weeks | Minutes to days (configurable) |
| Relative Cost Metrics |
π°π°π°π° Highest | π°π°π° Moderate | π° Lowest (fixed sites) | π°π° Pay-as-you-go (low idle cost) |
| Ongoing Maintenance Metrics |
Very high β must mirror production continuously | Moderate β periodic sync and testing | Low β facility maintenance only | Low idle; automated via IaC templates |
| Best for MTD of⦠Metrics |
Hours (life-safety, financial systems) | 1β3 days (important but not critical-minute) | 1+ weeks (tolerant business functions) | Any β depends on configuration |
| CISSP Exam Signals Exam Signals |
"fully operational," "real-time replication," "immediate failover," "highest cost," "most expensive," "minutes to recover" | "partially configured," "balanced cost and speed," "hours to days," "backup restoration required," "hardware in place" | "lowest cost," "facility only," "no hardware," "days to weeks," "procure equipment," "least expensive" | "elastic," "pay-as-you-go," "geographic flexibility," "spin up on demand," "IaC," "no fixed infrastructure" |
| Common Exam Trap Exam Signals |
Assuming hot site is "best" β it's most expensive; often overkill when MTD is 48+ hours | Forgetting that warm site still requires data restoration β RPO gap exists | Choosing cold site when RTO is tight β it cannot meet short RTOs | Treating cloud as always equivalent to hot site β depends entirely on replication configuration |
Six scenarios modeled directly on CISSP exam question formats.
Scenario-based items modeled on real exam format. Read each scenario carefully before selecting.
Answer 3 questions to identify the right recovery tier for any CISSP scenario.
Click each card to flip and reveal the mnemonic.
| If the question says⦠| Think⦠| Answer |
|---|---|---|
| "real-time replication," "immediate failover," "most expensive," "fully operational duplicate," "RTO of minutes," "zero data loss" | π΄ Already running everywhere | Hot Site |
| "hardware in place but needs configuration," "restore from backup," "hours to days RTO," "balanced cost and speed" | π‘ Equipment waiting, data gaps | Warm Site |
| "lowest cost," "facility only," "procure hardware after disaster," "days to weeks RTO," "budget constrained" | π΅ Empty room β bring everything | Cold Site |
| "elastic," "pay-as-you-go," "geographic flexibility," "spin up on demand," "no fixed infrastructure," "Infrastructure as Code" | π£ No fixed location, no idle cost | Cloud / Mobile |
| "maximum acceptable data loss," "backup frequency," "how old can the data be" | Data loss window | RPO |
| "how fast must we restore," "maximum downtime," "time to restore the system" | System recovery clock | RTO |
| "absolute maximum before irreversible harm," "upper bound for RTO," "business failure point" | Business survival limit | MTD (= MTPD) |
| "time to restore data AFTER systems are up," "data validation time" | Post-recovery data work | WRT |
| "BCP development β what comes FIRST" | Must know what to recover before how | BIA |
| "runs recovery site while primary stays online," "parallel operation" | Safe β both running | Parallel Test |
| "shuts down primary to test failover," "most rigorous test," "highest confidence" | Risky β primary actually down | Full Interruption Test |
| "staff verbally walk through the plan," "tabletop exercise," "no systems moved" | Paper exercise β identify gaps | Structured Walkthrough |