Onam Security

RTO, RPO & Drills

DRM keeps three kinds of recovery figure apart, because mixing them is how a plan looks better than it is.

KindWhere it comes from
RequiredYou enter it per application. A calculated value never overwrites it.
PredictedCalculated by DRM from the approved plan and protection.
ActualRecorded from a drill you ran.

Predicted RTO

The critical path through the application's approved recovery plan. Steps that can run at the same time cost the longest of them, not the sum. A step nobody has timed still carries its default duration, so it never drops off the path. With no approved plan, there is no predicted RTO — the field is left blank rather than showing zero.

Predicted RPO

The worst data-loss window across the application's replication links. For each link DRM takes the larger of the lag last observed and the configured target, so a quiet moment does not improve the reported figure. An application protected only by backups, with no backup frequency recorded, gets no predicted RPO rather than a guess.

Drills

A drill is planned, started and completed in DRM, and the prediction at planning time is captured on it — so the result is compared with what was promised then, not with whatever the model says today. The measured recovery time, data loss, success and issues found are entered by the person who ran it. DRM does not run the drill; it records it.