1
00:00:06,540 --> 00:00:08,850
- In this lesson 24.4,

2
00:00:08,850 --> 00:00:09,683
we're gonna take a look

3
00:00:09,683 --> 00:00:12,000
at doing a business impact analysis.

4
00:00:12,000 --> 00:00:13,200
Which is always gonna be part

5
00:00:13,200 --> 00:00:15,240
of our risk management program.

6
00:00:15,240 --> 00:00:16,860
Now, the purpose of a BIA,

7
00:00:16,860 --> 00:00:18,990
or a Business Impact Analysis,

8
00:00:18,990 --> 00:00:21,690
is to characterize system components,

9
00:00:21,690 --> 00:00:23,790
supported business processes,

10
00:00:23,790 --> 00:00:25,740
and interdependencies.

11
00:00:25,740 --> 00:00:27,270
In terms of how important

12
00:00:27,270 --> 00:00:28,923
they are to the organization.

13
00:00:30,060 --> 00:00:32,160
Now, the outcome of a BIA

14
00:00:32,160 --> 00:00:34,800
is gonna be a prioritized
matrix of services,

15
00:00:34,800 --> 00:00:36,840
systems, and infrastructure

16
00:00:36,840 --> 00:00:39,450
used to inform management decisions.

17
00:00:39,450 --> 00:00:41,730
In terms of resource prioritization

18
00:00:41,730 --> 00:00:43,500
and investment strategy.

19
00:00:43,500 --> 00:00:45,480
And to guide the development

20
00:00:45,480 --> 00:00:48,480
of our incident response,
disaster recovery,

21
00:00:48,480 --> 00:00:50,703
and business continuity plans.

22
00:00:51,630 --> 00:00:55,260
Now, the goal of doing
a BIA is to determine

23
00:00:55,260 --> 00:00:58,020
the criticality and impact of our systems.

24
00:00:58,020 --> 00:00:59,940
And if they weren't available

25
00:00:59,940 --> 00:01:02,460
what our recovery requirements are?

26
00:01:02,460 --> 00:01:04,800
And, when we look at
the aggregative systems

27
00:01:04,800 --> 00:01:06,873
what our recovery priority is?

28
00:01:08,310 --> 00:01:09,750
So the first thing we wanna do,

29
00:01:09,750 --> 00:01:12,660
is we wanna identify
our critical processes.

30
00:01:12,660 --> 00:01:15,873
And then the associated
impact of a disruption.

31
00:01:16,980 --> 00:01:19,320
Now our recovery
requirements is an evaluation

32
00:01:19,320 --> 00:01:21,150
of all of the resources needed

33
00:01:21,150 --> 00:01:23,280
to resume business processes

34
00:01:23,280 --> 00:01:25,620
and the related interdependencies.

35
00:01:25,620 --> 00:01:27,150
Now, those dependencies may include

36
00:01:27,150 --> 00:01:30,090
technology, infrastructure, facilities,

37
00:01:30,090 --> 00:01:32,430
personnel, even third parties.

38
00:01:32,430 --> 00:01:35,250
And then our recovery
priority is establishing

39
00:01:35,250 --> 00:01:37,888
the prioritization and sequencing

40
00:01:37,888 --> 00:01:41,100
of recovery and resumption activities.

41
00:01:41,100 --> 00:01:42,514
So those are our goals to determine

42
00:01:42,514 --> 00:01:44,520
criticality and impact,

43
00:01:44,520 --> 00:01:47,853
recovery requirements,
and recovery priority.

44
00:01:48,870 --> 00:01:51,150
Now here's one of the most basic metrics

45
00:01:51,150 --> 00:01:52,110
that we're gonna use.

46
00:01:52,110 --> 00:01:54,540
It's called a Maximum Tolerable Downtime.

47
00:01:54,540 --> 00:01:56,760
The Maximum Tolerable Downtime, MTD,

48
00:01:56,760 --> 00:01:58,080
sometimes you'll hear it is MTO,

49
00:01:58,080 --> 00:01:59,730
Maximum Tolerable Outage,

50
00:01:59,730 --> 00:02:01,770
represents the amount of time

51
00:02:01,770 --> 00:02:03,930
that a system owner is willing to accept

52
00:02:03,930 --> 00:02:07,500
for a service or process
outage or disruption.

53
00:02:07,500 --> 00:02:10,470
And includes all impact considerations.

54
00:02:10,470 --> 00:02:13,200
So I wanna stress this
is not an IT decision.

55
00:02:13,200 --> 00:02:15,390
This is not a security decision.

56
00:02:15,390 --> 00:02:17,790
This is a business unit decision.

57
00:02:17,790 --> 00:02:19,800
This will be made by the management

58
00:02:19,800 --> 00:02:21,210
of that business unit.

59
00:02:21,210 --> 00:02:22,980
Which basically says,

60
00:02:22,980 --> 00:02:25,320
what's the amount of time, that we can go

61
00:02:25,320 --> 00:02:27,720
by having a service or a process

62
00:02:27,720 --> 00:02:30,450
either out or disrupted right before

63
00:02:30,450 --> 00:02:33,543
it causes an unacceptable impact.

64
00:02:35,310 --> 00:02:37,110
Now, the MTD may also include

65
00:02:37,110 --> 00:02:38,520
the amount of time that a business

66
00:02:38,520 --> 00:02:41,220
can support alternate processing modes.

67
00:02:41,220 --> 00:02:43,650
So for example, in a bank, you know,

68
00:02:43,650 --> 00:02:45,540
at the teller stations,

69
00:02:45,540 --> 00:02:47,010
if they couldn't connect back

70
00:02:47,010 --> 00:02:48,630
to the the core system,

71
00:02:48,630 --> 00:02:49,680
well they may be able to work

72
00:02:49,680 --> 00:02:51,270
in offline mode for an hour.

73
00:02:51,270 --> 00:02:53,610
So that would be taken into consideration.

74
00:02:53,610 --> 00:02:55,680
But we get past that timeframe,

75
00:02:55,680 --> 00:02:57,300
now they can't operate at all.

76
00:02:57,300 --> 00:02:58,923
That would be unacceptable.

77
00:02:59,880 --> 00:03:01,796
And we also have what's known as an SDO.

78
00:03:01,796 --> 00:03:03,963
An SDO is a Service Delivery Objective.

79
00:03:03,963 --> 00:03:07,170
Now, that's the acceptable
level of operations

80
00:03:07,170 --> 00:03:09,330
in alternate processing mode.

81
00:03:09,330 --> 00:03:10,860
So if we had this outage,

82
00:03:10,860 --> 00:03:12,690
is there something we can accept

83
00:03:12,690 --> 00:03:15,270
that's not quite full resumption,

84
00:03:15,270 --> 00:03:17,220
but enough to keep us going.

85
00:03:17,220 --> 00:03:20,040
So operations might be less than normal,

86
00:03:20,040 --> 00:03:21,660
but sufficient to sustain

87
00:03:21,660 --> 00:03:24,360
business functions until full recovery.

88
00:03:24,360 --> 00:03:26,523
So MTD and STO.

89
00:03:28,320 --> 00:03:30,480
And here are some of our MTD,

90
00:03:30,480 --> 00:03:33,870
Maximum Tolerable Downtime
Impact Considerations.

91
00:03:33,870 --> 00:03:37,260
Our dependencies, our
fluctuations, financial,

92
00:03:37,260 --> 00:03:41,460
regulatory, reputational, and contractual.

93
00:03:41,460 --> 00:03:43,650
So Dependencies, Is there an impact

94
00:03:43,650 --> 00:03:46,413
on other functions,
processes, or services?

95
00:03:47,880 --> 00:03:50,640
Fluctuations, based on date and time.

96
00:03:50,640 --> 00:03:53,040
Is there a difference
between a system or process

97
00:03:53,040 --> 00:03:55,710
not being available on
a Monday than a Friday?

98
00:03:55,710 --> 00:03:57,573
A morning than an evening?

99
00:03:58,560 --> 00:04:01,440
Financial, what is the monetary loss?

100
00:04:01,440 --> 00:04:04,290
Regulatory, Will this
disruption or downtime

101
00:04:04,290 --> 00:04:06,450
cause any compliance issues?

102
00:04:06,450 --> 00:04:09,930
Reputational, Will this
outage or downtime,

103
00:04:09,930 --> 00:04:12,210
you know, result in a loss

104
00:04:12,210 --> 00:04:14,460
of customer trust and or business?

105
00:04:14,460 --> 00:04:17,580
And then, do we have any
contractual obligations

106
00:04:17,580 --> 00:04:20,250
and not being available?

107
00:04:20,250 --> 00:04:23,343
Would there that be a
contractual violation?

108
00:04:26,850 --> 00:04:28,500
So then we start looking at, okay,

109
00:04:28,500 --> 00:04:30,270
if there was a downtime,

110
00:04:30,270 --> 00:04:32,940
there was this problem, an outage.

111
00:04:32,940 --> 00:04:34,830
How do we restore our systems?

112
00:04:34,830 --> 00:04:35,670
How do we get back?

113
00:04:35,670 --> 00:04:37,590
And how quickly do we need to get back?

114
00:04:37,590 --> 00:04:40,860
And so we've got four
BIA recovery metrics.

115
00:04:40,860 --> 00:04:43,050
RTO, Recovery Time Objective.

116
00:04:43,050 --> 00:04:45,510
RPO, Recovery Point Objective.

117
00:04:45,510 --> 00:04:49,500
MTTR, Mean Time To Repair.

118
00:04:49,500 --> 00:04:52,533
And MTBF, Mean Time Between Failures.

119
00:04:53,730 --> 00:04:55,260
Now the Recovery Time Objective

120
00:04:55,260 --> 00:04:57,150
is the amount of time allocated

121
00:04:57,150 --> 00:04:59,130
for system recovery before

122
00:04:59,130 --> 00:05:01,500
negatively impacting other systems.

123
00:05:01,500 --> 00:05:03,570
So it's how much time
do we have to recover?

124
00:05:03,570 --> 00:05:06,030
But very often, there's
a number of components.

125
00:05:06,030 --> 00:05:08,430
Number of systems, that we have to recover

126
00:05:08,430 --> 00:05:10,320
for a particular process.

127
00:05:10,320 --> 00:05:13,620
And so the sum of all the RTOs

128
00:05:13,620 --> 00:05:16,023
should be less than the MTD.

129
00:05:17,820 --> 00:05:19,410
RPO is all about data.

130
00:05:19,410 --> 00:05:21,240
It's the Recovery Point Objective.

131
00:05:21,240 --> 00:05:22,980
It's the acceptable data loss.

132
00:05:22,980 --> 00:05:25,500
And this translates to the point in time

133
00:05:25,500 --> 00:05:27,120
prior to a disruption,

134
00:05:27,120 --> 00:05:29,220
that data can be recovered.

135
00:05:29,220 --> 00:05:30,450
And honestly, this is a place

136
00:05:30,450 --> 00:05:32,430
where I find the largest disconnect

137
00:05:32,430 --> 00:05:34,740
between expectations and reality.

138
00:05:34,740 --> 00:05:36,360
So I might be doing a BIA,

139
00:05:36,360 --> 00:05:38,040
and say to a business unit,

140
00:05:38,040 --> 00:05:40,350
okay, if there was a disruption

141
00:05:40,350 --> 00:05:41,940
how much data could you recreate?

142
00:05:41,940 --> 00:05:42,960
How many transactions?

143
00:05:42,960 --> 00:05:43,793
And they might say,

144
00:05:43,793 --> 00:05:45,360
oh, probably from the last half hour

145
00:05:45,360 --> 00:05:47,220
of transactions we could recreate.

146
00:05:47,220 --> 00:05:48,990
And then I say to IT,

147
00:05:48,990 --> 00:05:50,220
how often are you backing up

148
00:05:50,220 --> 00:05:51,570
or replicating their data?

149
00:05:51,570 --> 00:05:54,660
And maybe they say, oh, every 12 hours.

150
00:05:54,660 --> 00:05:56,490
Well, we could potentially
have a data loss

151
00:05:56,490 --> 00:05:57,990
of eleven and a half hours

152
00:05:57,990 --> 00:05:59,760
that no one's really acknowledging.

153
00:05:59,760 --> 00:06:03,120
And so once we establish that RPO, right,

154
00:06:03,120 --> 00:06:06,300
we either have to change expectations.

155
00:06:06,300 --> 00:06:08,370
Or make additional investments.

156
00:06:08,370 --> 00:06:10,170
Or change how we do things.

157
00:06:10,170 --> 00:06:13,050
And then these next two recovery metrics

158
00:06:13,050 --> 00:06:15,690
actually will come from
a manufacturer generally.

159
00:06:15,690 --> 00:06:17,910
MTTR, Mean Time to Repair,

160
00:06:17,910 --> 00:06:18,900
which is the average time

161
00:06:18,900 --> 00:06:22,530
it takes to repair a
failed component or device.

162
00:06:22,530 --> 00:06:26,160
And then MTBF, is the Mean
Time Between Failures.

163
00:06:26,160 --> 00:06:28,500
Which is just a measure of reliability

164
00:06:28,500 --> 00:06:30,993
with usage generally stated in hours.

165
00:06:32,580 --> 00:06:33,413
So let's take a look

166
00:06:33,413 --> 00:06:37,230
at the full business
impact analysis process.

167
00:06:37,230 --> 00:06:38,310
The first thing we're gonna do is,

168
00:06:38,310 --> 00:06:39,360
we're gonna prioritize

169
00:06:39,360 --> 00:06:41,640
our services and processes.

170
00:06:41,640 --> 00:06:42,810
And really what we're saying is,

171
00:06:42,810 --> 00:06:44,880
if there was a major disruption,

172
00:06:44,880 --> 00:06:47,700
what are our essential
services and processes?

173
00:06:47,700 --> 00:06:49,650
And essential is a tough word to use here,

174
00:06:49,650 --> 00:06:50,970
because everybody likes to think

175
00:06:50,970 --> 00:06:52,680
their job is essential.

176
00:06:52,680 --> 00:06:53,513
But let's think about

177
00:06:53,513 --> 00:06:55,140
a financial institution, right.

178
00:06:55,140 --> 00:06:58,110
If there was a major
outage, what is essential

179
00:06:58,110 --> 00:07:00,150
for a financial institution to do?

180
00:07:00,150 --> 00:07:02,070
Well, to be able to let their customers

181
00:07:02,070 --> 00:07:03,450
get their money out, is probably

182
00:07:03,450 --> 00:07:05,310
one of the most essential things, right.

183
00:07:05,310 --> 00:07:08,100
Are we gonna be worried
about making new loans?

184
00:07:08,100 --> 00:07:09,330
Probably not.

185
00:07:09,330 --> 00:07:11,550
Are we gonna be worried about,

186
00:07:11,550 --> 00:07:12,450
you know, marketing.

187
00:07:12,450 --> 00:07:13,770
Probably not, right.

188
00:07:13,770 --> 00:07:14,670
We have to look at what

189
00:07:14,670 --> 00:07:18,450
those essential services
are in a disruption.

190
00:07:18,450 --> 00:07:19,650
So we're gonna prioritize

191
00:07:19,650 --> 00:07:21,510
those services and processes.

192
00:07:21,510 --> 00:07:24,270
And then for each service and process,

193
00:07:24,270 --> 00:07:27,090
we're gonna identify the
impact of a disruption.

194
00:07:27,090 --> 00:07:28,890
We're gonna establish the MTD,

195
00:07:28,890 --> 00:07:31,050
The Maximum Tolerable Downtime.

196
00:07:31,050 --> 00:07:32,490
We'll establish the SDO,

197
00:07:32,490 --> 00:07:34,860
the Service Delivery Objective.

198
00:07:34,860 --> 00:07:38,550
We'll determine their required RPO, right.

199
00:07:38,550 --> 00:07:40,230
The Recovery Point Objective.

200
00:07:40,230 --> 00:07:42,000
That's all about data.

201
00:07:42,000 --> 00:07:44,700
We'll identify all of the infrastructure.

202
00:07:44,700 --> 00:07:46,650
Or all of the components.

203
00:07:46,650 --> 00:07:49,170
We're gonna determine the required RTO,

204
00:07:49,170 --> 00:07:50,920
that's our Recovery Time Objective.

205
00:07:52,080 --> 00:07:53,700
Then we'll compare the required

206
00:07:53,700 --> 00:07:57,090
and the actual RTO and RPO.

207
00:07:57,090 --> 00:07:59,070
Then we will analyze the gaps

208
00:07:59,070 --> 00:08:02,550
between the actual RTO and RPO.

209
00:08:02,550 --> 00:08:05,193
And then lastly, we'll
report up to management.

210
00:08:06,600 --> 00:08:08,370
So let me just give you an illustration

211
00:08:08,370 --> 00:08:10,110
of the outcome of a BIA.

212
00:08:10,110 --> 00:08:11,340
This is actually from NIST,

213
00:08:11,340 --> 00:08:16,340
Special Publication 800-34r1.

214
00:08:16,350 --> 00:08:18,240
You can see we've got
the business processes

215
00:08:18,240 --> 00:08:20,610
of process an invoice, prepare a report,

216
00:08:20,610 --> 00:08:22,980
create a budget, respond to inquiries.

217
00:08:22,980 --> 00:08:25,320
We have what the potential impact is.

218
00:08:25,320 --> 00:08:28,410
Operations more than 1,000 staff affected.

219
00:08:28,410 --> 00:08:29,730
Or reputation affected,

220
00:08:29,730 --> 00:08:31,710
or customer service affected.

221
00:08:31,710 --> 00:08:32,543
Then we have

222
00:08:32,543 --> 00:08:34,740
the Maximum Tolerable Downtime, right.

223
00:08:34,740 --> 00:08:38,130
The MTD, that's a business unit decision.

224
00:08:38,130 --> 00:08:40,380
Then we have, what are
all the system components?

225
00:08:40,380 --> 00:08:42,660
And it's very likely that you'll have

226
00:08:42,660 --> 00:08:45,000
multiple system components.

227
00:08:45,000 --> 00:08:47,070
It looks like the application server,

228
00:08:47,070 --> 00:08:48,360
well, is responsible for both

229
00:08:48,360 --> 00:08:51,690
processing the invoice
and creating a budget.

230
00:08:51,690 --> 00:08:52,560
So you can see that there's

231
00:08:52,560 --> 00:08:54,330
multiple dependencies here.

232
00:08:54,330 --> 00:08:55,710
So we're gonna identify

233
00:08:55,710 --> 00:08:58,500
those system components,
that's right here.

234
00:08:58,500 --> 00:09:00,270
So we started with our Business Process,

235
00:09:00,270 --> 00:09:01,530
our Potential Impact.

236
00:09:01,530 --> 00:09:03,690
Our Maximum Tolerable Downtime.

237
00:09:03,690 --> 00:09:05,070
And then we'll get to our

238
00:09:05,070 --> 00:09:06,873
Recovery Time Objective.

239
00:09:08,850 --> 00:09:10,380
Then what we don't have

240
00:09:10,380 --> 00:09:12,450
in this particular illustration,

241
00:09:12,450 --> 00:09:14,943
is our RPO, our Recovery Point Objective.

242
00:09:16,830 --> 00:09:18,000
You've seen this slide before.

243
00:09:18,000 --> 00:09:19,740
This is just a refresher.

244
00:09:19,740 --> 00:09:22,500
This is just a reminder
about cost balancing.

245
00:09:22,500 --> 00:09:23,460
That we always, you know,

246
00:09:23,460 --> 00:09:25,020
need to think about cost.

247
00:09:25,020 --> 00:09:28,440
And we want to balance
the the cost to recover

248
00:09:28,440 --> 00:09:30,510
and the cost of disruption.

249
00:09:30,510 --> 00:09:32,310
Taking into account

250
00:09:32,310 --> 00:09:34,233
the length of disruption as well.

251
00:09:35,100 --> 00:09:35,933
And that my friends,

252
00:09:35,933 --> 00:09:37,890
brings us to a 3-second challenge.

253
00:09:37,890 --> 00:09:40,263
Five challenge questions,
three seconds each.

254
00:09:41,760 --> 00:09:43,830
This is the maximum time
a process or service

255
00:09:43,830 --> 00:09:45,450
can be unavailable, without causing

256
00:09:45,450 --> 00:09:47,583
significant damage to the business.

257
00:09:48,420 --> 00:09:50,343
One, two, three.

258
00:09:51,450 --> 00:09:53,730
That's MTD, Maximum Tolerable Downtime.

259
00:09:53,730 --> 00:09:54,660
Again, sometimes you'll see it

260
00:09:54,660 --> 00:09:56,220
as Maximum Tolerable Outage.

261
00:09:56,220 --> 00:09:57,423
It means the same thing.

262
00:09:58,620 --> 00:10:00,600
Number two, the amount of time allocated

263
00:10:00,600 --> 00:10:02,550
for system recovery.

264
00:10:02,550 --> 00:10:03,540
That's gonna be inclusive

265
00:10:03,540 --> 00:10:05,280
of all of the dependencies.

266
00:10:05,280 --> 00:10:07,320
One, two, three.

267
00:10:07,320 --> 00:10:10,440
That's your RTO, your
Recovery Time Objective.

268
00:10:10,440 --> 00:10:13,080
Number three, the acceptable data loss

269
00:10:13,080 --> 00:10:15,210
expressed in time.

270
00:10:15,210 --> 00:10:17,163
One, two, three.

271
00:10:18,150 --> 00:10:20,913
And that's our RPO,
Recovery Point Objective.

272
00:10:21,960 --> 00:10:24,330
Number four, the intersection

273
00:10:24,330 --> 00:10:26,190
of the cost of the disruption,

274
00:10:26,190 --> 00:10:27,843
and the cost to recover.

275
00:10:29,460 --> 00:10:31,590
One, two, three.

276
00:10:31,590 --> 00:10:33,870
That's our Cost Balance Point.

277
00:10:33,870 --> 00:10:35,670
And lastly, number five,

278
00:10:35,670 --> 00:10:37,140
a measure of reliability.

279
00:10:37,140 --> 00:10:39,870
And that's generally stated in hours.

280
00:10:39,870 --> 00:10:41,223
One, two, three.

281
00:10:42,060 --> 00:10:43,680
That's gonna be an MTBF

282
00:10:43,680 --> 00:10:46,023
or Mean Time Between Failures.

283
00:10:46,890 --> 00:10:48,780
So let's do a security in action

284
00:10:48,780 --> 00:10:50,943
about a business impact analysis.

285
00:10:51,900 --> 00:10:54,450
Anytown's Bank's mission-critical priority

286
00:10:54,450 --> 00:10:56,400
is to be able to serve their customers

287
00:10:56,400 --> 00:10:58,530
24 hours a day, seven days a week,

288
00:10:58,530 --> 00:11:00,870
365 days a year.

289
00:11:00,870 --> 00:11:02,040
So to facilitate this,

290
00:11:02,040 --> 00:11:02,940
they have an online

291
00:11:02,940 --> 00:11:05,190
and a mobile banking platform.

292
00:11:05,190 --> 00:11:06,023
They have determined

293
00:11:06,023 --> 00:11:08,220
that their online banking application

294
00:11:08,220 --> 00:11:11,610
can operate in offline
customer transaction mode

295
00:11:11,610 --> 00:11:14,850
for 60 minutes with
minimal customer impact.

296
00:11:14,850 --> 00:11:16,200
So that would be offline mode,

297
00:11:16,200 --> 00:11:18,150
after there's a disruption.

298
00:11:18,150 --> 00:11:19,650
After that, service

299
00:11:19,650 --> 00:11:21,840
is no longer available to customers.

300
00:11:21,840 --> 00:11:23,760
Now they can manually recreate

301
00:11:23,760 --> 00:11:26,070
the last 30 minutes of transactions

302
00:11:26,070 --> 00:11:27,600
relatively easily.

303
00:11:27,600 --> 00:11:29,490
Generally within 10 minutes.

304
00:11:29,490 --> 00:11:31,230
So here's what I wanna know from you.

305
00:11:31,230 --> 00:11:34,080
What is the MTD, the RPO,

306
00:11:34,080 --> 00:11:36,663
and the RTO for this scenario?

307
00:11:37,680 --> 00:11:42,060
So they wanna be online, right, 24x7x365?

308
00:11:42,060 --> 00:11:42,893
They've determined

309
00:11:42,893 --> 00:11:44,790
that their online banking application,

310
00:11:44,790 --> 00:11:46,770
that's really our focus here.

311
00:11:46,770 --> 00:11:49,350
Can operate in offline transaction mode

312
00:11:49,350 --> 00:11:52,500
for 60 minutes with
minimal customer impact.

313
00:11:52,500 --> 00:11:55,050
But after that service
is no longer available.

314
00:11:55,050 --> 00:11:57,060
They can no longer
service their customers.

315
00:11:57,060 --> 00:11:58,830
After the 60 minutes.

316
00:11:58,830 --> 00:12:01,290
And they tell us they
could manually recreate

317
00:12:01,290 --> 00:12:04,110
the last 30 minutes of transactions

318
00:12:04,110 --> 00:12:05,340
relatively easily.

319
00:12:05,340 --> 00:12:06,420
Within 10 minutes or so,

320
00:12:06,420 --> 00:12:08,820
but probably not past that.

321
00:12:08,820 --> 00:12:13,820
So, what's the MTD, the RPO, and the RTO.

322
00:12:14,280 --> 00:12:15,330
Go ahead and put me on pause,

323
00:12:15,330 --> 00:12:17,193
and come up with this BIA metrics.

324
00:12:20,190 --> 00:12:22,020
Well, the Maximum Tolerable Downtime

325
00:12:22,020 --> 00:12:23,805
really is 60 minutes.

326
00:12:23,805 --> 00:12:25,560
That's the most we can be down.

327
00:12:25,560 --> 00:12:26,613
So we go down,

328
00:12:27,480 --> 00:12:30,330
and at that point the
offline mode kicks in.

329
00:12:30,330 --> 00:12:32,550
So we could still service our customers.

330
00:12:32,550 --> 00:12:34,440
But at the end of that 60 minutes,

331
00:12:34,440 --> 00:12:35,610
we're down, we're done.

332
00:12:35,610 --> 00:12:37,950
We can no longer service customers at all.

333
00:12:37,950 --> 00:12:40,080
So our Maximum Tolerable Downtime

334
00:12:40,080 --> 00:12:41,763
is going to be 60 minutes.

335
00:12:42,870 --> 00:12:45,540
Our Recovery Point Objective, or RPO,

336
00:12:45,540 --> 00:12:47,040
is going to be 30 minutes.

337
00:12:47,040 --> 00:12:47,873
Why?

338
00:12:47,873 --> 00:12:49,410
Because they tell us
that they could recover

339
00:12:49,410 --> 00:12:52,020
the last 30 minutes of transactions.

340
00:12:52,020 --> 00:12:54,150
But after that, absolutely not.

341
00:12:54,150 --> 00:12:55,620
So the Recovery Point Objective,

342
00:12:55,620 --> 00:12:56,460
that's looking back,

343
00:12:56,460 --> 00:12:58,170
how much data could they recover?

344
00:12:58,170 --> 00:12:59,490
They're saying we could only recover

345
00:12:59,490 --> 00:13:01,563
the last 30 minutes worth of data.

346
00:13:02,820 --> 00:13:05,370
Now, the Recovery Time Objective, the RTO,

347
00:13:05,370 --> 00:13:07,170
needs to be less than 60.

348
00:13:07,170 --> 00:13:09,210
And that 60 minutes combined

349
00:13:09,210 --> 00:13:11,490
for all applicable components

350
00:13:11,490 --> 00:13:13,173
and interdependencies.

351
00:13:14,550 --> 00:13:16,950
And then another question to ask would be,

352
00:13:16,950 --> 00:13:18,930
is there an acceptable SDO

353
00:13:18,930 --> 00:13:20,670
or Service Delivery Option?

354
00:13:20,670 --> 00:13:22,650
Is there something that's acceptable

355
00:13:22,650 --> 00:13:25,380
between being like dead in the water

356
00:13:25,380 --> 00:13:26,490
and full recovery?

357
00:13:26,490 --> 00:13:28,350
Is there something in between

358
00:13:28,350 --> 00:13:29,550
that would be acceptable?

359
00:13:29,550 --> 00:13:31,140
And that would be the SDO.

360
00:13:31,140 --> 00:13:33,420
The Service Delivery Option.

361
00:13:33,420 --> 00:13:35,610
Knowing these metrics for your exam

362
00:13:35,610 --> 00:13:37,170
and in real life,

363
00:13:37,170 --> 00:13:38,943
is for sure security in action.

364
00:13:40,170 --> 00:13:41,340
There's your word cloud,

365
00:13:41,340 --> 00:13:44,280
make sure that you know
all of these terms.

366
00:13:44,280 --> 00:13:45,600
And when you're ready,

367
00:13:45,600 --> 00:13:46,890
head on over to our quiz.

368
00:13:46,890 --> 00:13:47,840
I'll see you there.
