⏱️ CISSP Study Note: Maximum Allowable Downtime (MAD) / Maximum Tolerable Downtime (MTD)
⏱️ CISSP Study Note: Maximum Allowable Downtime (MAD) / Maximum Tolerable Downtime (MTD)
๐ Definition
Maximum Allowable Downtime (MAD)—also known as Maximum Tolerable Downtime (MTD)—is the longest period of time an organization can withstand the interruption of a critical function or system before the impact becomes unacceptable, unrecoverable, or catastrophic.
It sets the outer limit for how long systems or processes can be unavailable during a disaster, incident, or failure.
๐ง Why It Matters in Cybersecurity
MTD is a critical metric in Business Continuity (BC) and Disaster Recovery (DR) planning. It helps organizations:
-
Prioritize recovery efforts
-
Define system criticality
-
Determine appropriate Recovery Time Objectives (RTOs)
-
Align recovery strategies with business risk tolerance
Failing to meet MTD can result in:
-
Loss of life or safety
-
Regulatory noncompliance
-
Irreversible financial losses
-
Permanent brand/reputation damage
๐ MTD vs. Related Metrics
| Metric | Purpose |
|---|---|
| MTD (MAD) | Maximum downtime the business can tolerate before unacceptable consequences occur. |
| RTO | The target time to recover a system after disruption. Must be less than or equal to MTD. |
| RPO | The maximum acceptable data loss, measured in time. Helps guide backup frequency. |
๐ง Think of MTD as the "ceiling" for downtime. RTO must fit under it.
๐ ️ How MTD Is Used
-
Set during the Business Impact Analysis (BIA) phase
-
Helps define BC/DR priorities and resource allocation
-
Drives selection of recovery strategies, such as hot sites, cloud failover, or manual processes
-
Influences insurance policies, vendor SLAs, and audit standards
✅ Example (CISSP-Style)
A hospital identifies its electronic health records (EHR) system as a critical asset. Through a BIA, it determines that the system’s MTD is 4 hours. This means any downtime beyond 4 hours would result in patient care disruption, regulatory violations, and legal risk.
✅ IT then designs the disaster recovery solution to meet a 1-hour RTO, staying well within the MTD threshold.
๐ Found In CISSP Domains
| Domain | Focus |
|---|---|
| ๐ Domain 7: Security Operations | Covers BCP/DRP metrics like MTD, RTO, and RPO. |
| ๐ Domain 1: Security and Risk Management | Helps establish acceptable risk and continuity objectives. |
๐ Memory Hook
“MTD is the absolute limit—the point of no return.”
Your recovery target must beat the clock—or the damage becomes irreversible.
Comments
Post a Comment