Identify the business impact
A business impact analysis examines what happens when an activity is disrupted and what it depends on. Discuss the consequences with the business owner, rather than allowing a technical inventory alone to determine the recovery order.
The result should connect an activity to its required information, applications, people and other services. A system that looks secondary on its own may be a dependency for another activity. The priorities need to reflect that relationship. Contingency Planning Guide for Federal Information Systems
Keep recovery objectives distinct
A recovery time objective (RTO) sets the target limit for how long a defined system resource or service may remain unavailable. A recovery point objective (RPO) identifies the point in time to which data must be recoverable. Maximum tolerable downtime (MTD) describes how long the business process can be disrupted before the impact becomes unacceptable. Set recovery targets to leave enough time for the remaining work needed to resume the business process. Contingency Planning Guide for Federal Information Systems, §3.2.1.
Record targets separately from demonstrated results. Owning backups does not show that a target can be met. A service commitment in a contract is another distinct matter; an internal objective does not automatically become a supplier promise.
Decide what ready to resume means
A restored component is not necessarily a useful business service. Recovery needs checks on the integrity of restored assets and the status of the operation before normal work is declared resumed. The CSF Recover outcomes and NIST’s incident-response recommendations address these decisions. The NIST Cybersecurity Framework (CSF) 2.0 Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile
For a business workflow, ask who checks that the required tasks can be performed and who resolves work accumulated during the interruption. After a cyber incident, involve the response specialists in decisions about trusted recovery. This article is not a technical procedure for declaring an environment clean.
An invented order-processing exercise
A business discusses an outage affecting order processing. It identifies the minimum activity it wants to sustain, what staff could do temporarily and which dependencies must return first. The exercise also considers how manually recorded orders would later be checked against the restored system.
The group leaves target recovery times and data-loss tolerances for accountable business decisions. No restore has been performed and no recovery target has been demonstrated. A discussion can expose missing arrangements without proving that those arrangements work.
A continuity-planning checklist
- Identify the activity, owner and consequences of interruption.
- Map information, systems, staff and supplier dependencies.
- Decide the minimum useful operation and recovery priorities.
- Set objectives with accountable business owners.
- Plan how recovery and business usability will be checked.
- Assign reconciliation, communications and return-to-service decisions.
- Record exercise findings and who will address them.
Optional depth: test the relationships
A useful exercise examines how decisions and dependencies interact, not only whether a file can be retrieved. The scope should fit the business impact and resources. Specialist continuity, application and infrastructure input can help turn the plan into an appropriate exercise. Contingency Planning Guide for Federal Information Systems
The older NIST federal guide is used here for planning concepts, not its federal time requirements or dated technology examples. Relevant contractual or legal obligations need separate assessment for the organisation.
Related reading
- Backups and restore tests — Plan a bounded restore exercise.
- Preparing a cyber incident-response plan — Connect incident response to recovery.
- What an integration involves: data, permissions and failure recovery — Consider reconciliation across systems.