From risk to response
A risk describes an uncertain condition and its effect on an objective. Record cause, event, consequence, likelihood, impact, owner, and response. A materialized problem should be managed as an issue or incident while retaining its link to the original risk. Risk acceptance requires appropriate authority; a project manager should not personally accept risks beyond their mandate.
Recovery is a testable requirement
RTO represents the recovery time objective; RPO represents tolerable data loss measured in time. Agree both with the service owner and translate them into design and tests. Replicas do not prove recovery: corruption may replicate too. Backups do not prove restoration within the deadline. Exercises must include dependencies, credentials, networking, procedures, and functional validation.
Obsolescence with a complete plan
Inventory operating systems, runtimes, middleware, databases, and external components. Compare support dates with the migration schedule. Include compatibility tests, regression, automation updates, and support capability. If upgrading before end of support is infeasible, present options and residual risk for formal decision; an intention to migrate does not resolve the risk.
Workplace application
To rehearse recovery of a fictional application, combine infrastructure, data, identity, and functional validation. Record where measurement starts and what data state is recoverable. If machines start but credentials or reconciliation are missing, the service has not demonstrated its objective. The NIST reference teaches recovery concepts; it does not represent an internal standard or a specific banking requirement.
Agreed RTO: 60 minutes. An exercise restores servers in 35 minutes, but functional validation finishes at minute 82. Service recovery has not met the objective: validation and dependencies must be included in measurement.
Common pitfalls
Equating backup with demonstrated recovery; accepting risk outside the mandate.
Related topics: Prepare the change and hand over autonomy · Dependencies and the critical path
Resilience requires agreed objectives and demonstrated recovery of the complete service.
Reference: Contingency Planning Guide for Federal Information Systems · DR Technical Project Manager 2026.4; independent professional curriculum