StudyToCert

All certifications / CISSP / Lessons

ISC2 CISSP 2024 outline · Domain 7: Security operations

Recovery strategies: backup types, recovery sites, resilience, high availability

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Recovery strategies determine how quickly and completely an organization can restore operations after a disruption. They are driven by the business impact analysis (BIA). The recovery time objective (RTO) sets how fast a function must be restored, the recovery point objective (RPO) sets how much data loss is tolerable, and the maximum tolerable downtime (MTD) sets the outer limit before the organization suffers unacceptable harm. The RTO must be shorter than the MTD. Every strategy choice is a trade-off between cost and how well it meets those objectives, and management decides the balance.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISSP for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISSP study plan