During a business continuity strategy assessment, a hospital's IT security officer reviews the Business Impact Analysis (BIA) for the Electronic Health Record (EHR) system. The business impact analysis defines a Maximum Tolerable Downtime (MTD) of . Technical server restoration and database mounting are calculated to have a Recovery Time Objective (RTO) of . However, post-restoration operational steps—including data integrity validation, paper chart reconciliation, and system synchronization—require a Work Recovery Time (WRT) of . Which of the following operational conclusions should the security officer draw regarding the current disaster recovery plan?
- The disaster recovery plan is non-compliant because the combined outage and recovery timeframe () exceeds the Maximum Tolerable Downtime ().Cevap
- BThe disaster recovery plan is fully compliant because the Recovery Time Objective () is less than the Maximum Tolerable Downtime ().
- CThe plan is compliant if the Recovery Point Objective (RPO) is adjusted to to absorb the Work Recovery Time.
- DThe post-restoration verification process acts as a corrective control that automatically reduces the effective Recovery Time Objective to .
Cevap
The disaster recovery plan is non-compliant because the combined outage and recovery timeframe () exceeds the Maximum Tolerable Downtime ().
In Business Impact Analysis (BIA) and Business Continuity Management (BCM), Maximum Tolerable Downtime (MTD) defines the total permissible disruption period. Total operational recovery includes both technical system restoration (RTO) and operational business verification/reconciliation (WRT). Because , the total recovery period exceeds the MTD, rendering the continuity plan non-compliant.
Adım Adım Çözüm
Anahtar Kavram
Work Recovery Time (WRT) and Recovery Time Objective (RTO) relationship to Maximum Tolerable Downtime (MTD)