← CISM: manage security, risk, and incidents
11 / 11 · 60 MIN

Recovery with criteria and capacity

Connect timelines, confidence, processing capacity and return-to-service criteria in a coordinated response.

Define milestones before comparing times

Detection, acknowledgement, containment and recovery are different milestones. On a UTC timeline, onset at 09:00, detection at 09:12 and containment at 09:32 mean twelve minutes to detect and twenty from detection to containment. Onset to containment is thirty-two minutes. None is an average across incidents. Define start, end, clock, cohort and incomplete-data treatment before comparing teams or periods. Preserve original evidence and document clock corrections. Without this discipline, two metrics with the same name can measure different activities and lead managers to an unsupported performance comparison.

Do not let the median hide the tail

Five durations of 30, 30, 30, 30 and 240 minutes have a mean of 72 and median of 30. The median describes the center but does not tell the whole story of the long incident. Show distribution, severity and impact when they affect decisions. If another incident has been open for two days, do not assign it zero resolution duration. Retain the closed-case definition and add age and exposure of open cases. Month-to-month comparison also needs context because population changes can produce apparent improvement without improving capability.

Confidence and impact guide different decisions

A low-confidence indication can point to a severe consequence and justify urgent validation. Do not automatically reduce potential severity because confirmation is missing, or communicate the hypothesis as fact. Record observations, who assessed them, which proportionate measures are authorized and when an update is due. For external communication, prepare confirmed facts, uncertainties and actions for competent functions to decide. Obligations depend on the case and applicable requirements; an invented universal deadline does not resolve the decision. Coordination should enable investigation and consistent communication without waiting for final root cause before acting.

Restore trust as well as data

An intact copy is necessary in many recovery plans but does not by itself establish trust in the environment where it will be restored. Assess administrative identities, deployment mechanisms, backup access and conditions that enabled the incident. If compromised credentials remain valid, restored data may be exposed again. Define criteria for selecting recovery assets, verifying integrity and confirming operation with the service owner. Return should follow authority and evidence specified in the plan. Starting a process does not automatically mean recovering a service accepted by the business.

Recovery includes required capacity

An available process may still be unable to meet the operational objective. In the teaching model, preparation takes five minutes and 1200 items exist when processing starts. Thirty arrive per minute and seventy are processed, so net reduction is forty. Drainage requires thirty minutes, totaling thirty-five from preparation start. The 1200 already include earlier arrivals; do not count them twice. Constant rates and no retries are assumptions, not guarantees. Compare the result with the business criterion and assess capacity, demand and integrity before declaring recovery.

Close with evidence and learn without double counting

A tabletop can demonstrate role understanding without proving recovery time or technical execution. Use its outcome to choose the next exercise and assign verifiable corrections. Before reopening a contained connection, confirm outstanding criteria, sessions, monitoring and authorization while also considering continuity. Then connect learning to risk and the control program. If two teams register the same entire consequence, reconcile scenarios to avoid adding the loss twice. Keep dependencies and local actions visible: correcting aggregation does not complete treatment or remove shared responsibilities for the service.

IN PRACTICE

A health check turns green at five minutes, but the exercise requires the queue cleared by minute 25. With net capacity of 40 items per minute and 1200 pending, the forecast is 35 minutes: ten beyond the objective.

Common pitfalls

Calling one case a mean; imputing zero to open incidents; confusing an intact backup with a trusted environment; ignoring new arrivals; treating a tabletop as proof of meeting RTO.

Related topics: Incident measures · BIA, RTO and RPO · Recovery and improvement

Take this idea with you

Recovery requires demonstrated trust, capacity and acceptance. Metrics support coordination when they preserve milestones, population, uncertainty and consequences for the service.

Create account

Reference: Incident Response Recommendations and Considerations · CISM current outline before November 3, 2026

CISM® is a registered trademark of ISACA. bigsavant.com is an independent preparation platform and is not affiliated with, associated with, sponsored, authorised or endorsed by ISACA. Content and questions are original, are not official exam questions, and completing our tests does not award or guarantee any certification. Names are used only to identify the subject. All other trademarks belong to their respective owners.