What Is a Disaster Recovery Plan?

A disaster recovery plan documents how technology services and data will be restored after a disruptive event.

A disaster recovery plan documents how technology services and data will be restored after a disruptive event. It translates business requirements into recovery priorities, responsibilities, procedures and evidence that the arrangements work.

What should the plan cover?

  • Critical systems, dependencies and owners
  • Recovery time and recovery point objectives
  • Backup, replication and restoration procedures
  • Alternative infrastructure and access controls
  • Incident command and communications
  • Testing, maintenance and return-to-normal steps

RTO vs. RPO

The recovery time objective, or RTO, is the target time to restore a service. The recovery point objective, or RPO, is the maximum targeted period of data loss measured backward from the incident. A four-hour RTO and one-hour RPO describe different requirements.

Disaster recovery vs. business continuity

Disaster recovery focuses primarily on restoring technology and data. Business continuity addresses how the organization continues critical operations across people, facilities, suppliers, communications and technology. The plans should be coordinated.

How should the plan be tested?

Use backup restoration tests, technical failovers, tabletop exercises and full simulations appropriate to the risk. Record actual recovery times, data gaps, access failures, decisions and remediation owners.

What should a BPO customer verify?

Confirm which services and locations are covered, whether subcontractors are included, where recovery data resides and what happens if both the primary site and local workforce are unavailable. Contractual recovery claims should match tested capabilities.

Related Terms