RESILIVANCE · Educational guide · 1 min read
A target is not proof
A recovery time objective describes how quickly an activity needs to resume. It does not establish that people, systems, facilities, suppliers, and decision makers can deliver that recovery. Treat the target as a requirement to test.
Start with the operation
Name the service, its minimum acceptable output, and the impact of its loss over time. Identify the owner who can explain those impacts and approve priorities. Connect technology dependencies to that business outcome.
Trace dependencies
Record the people, data, applications, equipment, facilities, utilities, external providers, and decision authority needed for minimum service. For each, name an owner, expected availability, evidence, and workaround. An unverified supplier promise remains an assumption.
Separate requirement from capability
Required recovery comes from business impact. Feasible recovery comes from resources and arrangements available. Demonstrated recovery comes from exercises or incidents under stated conditions. A test with extra staff or preloaded data does not prove the same result during an unplanned disruption.
Make the decision visible
Document each gap, its impact, options, accountable owner, and next validation date. Management can strengthen a dependency, test a workaround, revise a commitment, or accept a residual risk explicitly. Revisit decisions when operations change.
General educational guidance. Recommendations depend on your organization’s circumstances.

