What does RTO mean in ISO 22301?
RTO means recovery time objective: the target timeframe for resuming a disrupted activity at a specified minimum acceptable capacity. ISO 22301 places it inside the business impact analysis, after the organization has assessed impacts over time and identified the maximum tolerable period of disruption.
The RTO should normally sit inside the MTPD, not equal it by default. MTPD is the point where the impact of not resuming becomes unacceptable; the RTO is the operational target that gives the organization time to recover before that outer limit is reached.
- Define the product or service that depends on the activity.
- Identify the prioritized activity and the minimum acceptable capacity after disruption.
- Set the RTO within the MTPD and document the assumptions behind it.
- Assign an accountable owner who can fund and maintain the recovery capability.
Primary ISO listing for the current ISO 22301 business continuity management system requirements standard.
Supports the distinction between ICT continuity requirements, BIA-derived RTOs, and RPOs for information needed during disruption.