Restore in business order
Identify critical services and their dependencies before deciding the restoration order. Identity, network access, application configuration and data may all be required for a service to work. Restoring the data alone does not establish operational readiness.
Separate targets from measured results
Recovery time objective (RTO) describes the target time to restore a service. Recovery point objective (RPO) describes the target tolerance for lost data. Record the actual result of a drill alongside these targets; a configured target is not evidence of an achieved recovery.
Validate the environment and the restore point
After compromise, restoration must account for the attacker’s access and persistence. Agree how credentials, dependencies and the recovery environment will be reviewed. Select restore points using available integrity and investigation evidence. No single check proves the absence of every threat.
- Review the trusted recovery environment
- Identify the restore point and its evidence
- Sequence the dependencies
- Validate application and business functionality
Keep evidence from the rehearsal
Record the scope, start and finish times, restore source, validation steps and exceptions. A useful exercise tells the team what succeeded, what failed and what needs to change before the next incident.