RTO and RPO: The Two Numbers That Define Your Recovery
Every backup and recovery strategy must start with two defined numbers. Recovery Time Objective (RTO) is the maximum acceptable time to restore a system after failure — e.g., "critical financial systems must be online within 4 hours." Recovery Point Objective (RPO) is the maximum acceptable data loss — e.g., "we can lose no more than 1 hour of transaction data." These are business decisions, not IT decisions, and they must be formally approved by management, documented in your Business Continuity Plan (BCP), and tested to verify they are achievable. CERT-In Directions 2022 requires organisations to maintain a tested BCP with documented RTO and RPO values. The RBI Master Direction on IT requires BFSI organisations to test DR annually with RTO evidence.
Recommended RTO/RPO by System Criticality — Indian Regulated Enterprises
| System Tier | Examples | RTO Target | RPO Target |
|---|---|---|---|
| Tier 1 — Critical | Core banking, payment systems, ERP | < 2 hours | 15 minutes |
| Tier 2 — High | Email, CRM, collaboration tools | < 8 hours | 1 hour |
| Tier 3 — Medium | Dev/test systems, reporting tools | < 24 hours | 4 hours |
| Tier 4 — Low | Archives, static files, legacy systems | 72 hours | 24 hours |
The 3-2-1 Backup Rule
The 3-2-1 rule is the industry-standard backup architecture recommended by CISA and ISO: maintain 3 copies of data (1 primary, 2 backups), on 2 different media types (e.g., disk and tape, or local NAS and cloud), with 1 copy offsite (geographically separated from the primary site). For ransomware protection, extend this to 3-2-1-1: one copy must be immutable (air-gapped or WORM storage) so attackers cannot encrypt or delete it.
Testing Backups: The Control Most Enterprises Skip
Backup testing is the single most commonly skipped control in Indian enterprise assessments. Organisations assume backups work because the nightly job completed successfully. But a completed backup job does not prove a restorable backup. Audit requirements demand: quarterly restore tests for critical systems with documented results (time to restore, data integrity verification, test environment used), and annual full DR failover test with measured RTO vs. target.
Audit Evidence for Backup Compliance
ISO 27001:2022 A.8.13 requires information backup procedures. CERT-In requires documented BCP with tested recovery procedures. Evidence auditors expect: backup job completion logs (90-day history minimum), restore test records (date, system, result, time taken), RTO/RPO targets documented in BCP, and exception records for backup failures with root cause and remediation.
Is Your Backup Strategy Audit-Ready?
InfraVeritas 360 assesses your backup architecture, RTO/RPO documentation, restore test records, and offsite copy strategy — delivering a compliance gap report mapped to CERT-In and ISO 27001.
Assess Your Backup Readiness →