Home > Glossary > Certified Information Systems Auditor > Maximum Tolerable Downtime (MTD)

📖 What is Maximum Tolerable Downtime (MTD)?

Maximum Tolerable Downtime (MTD) is the total amount of time a business process can be disrupted before causing irreparable harm to the organization. It represents the absolute upper limit of downtime and informs the setting of RTOs.

🥋 Sensei Says:

"MTD is the 'ceiling.' Your RTO must always be less than or equal to your MTD to ensure the business survives the outage."

📚 Certification: Certified Information Systems Auditor (CISA)

🔑 What are the Key Concepts of Maximum Tolerable Downtime (MTD)?

  • MTD is derived from the Business Impact Analysis (BIA), which identifies critical processes and the exact point where losses become unacceptable.
  • The Recovery Time Objective (RTO) must always be less than or equal to the MTD to ensure the business recovers before catastrophic failure.
  • Irreparable harm includes critical factors such as total loss of customer trust, severe regulatory fines, or permanent loss of market share.
  • MTD focuses on the overall viability of the business entity rather than just the technical availability of a single server or application.
  • MTD calculations must account for interdependent systems, as the slowest critical component often dictates the overall MTD for a business process.

🎯 How does Maximum Tolerable Downtime (MTD) appear on the CISA Exam?

You may be asked to analyze a BIA report and determine if a proposed RTO is acceptable given the established MTD for a critical financial processing system.

A scenario might describe a business process where the cost of downtime increases exponentially after 24 hours; you would identify this threshold as the MTD.

Expect questions where you must distinguish between MTD, RTO, and RPO to determine which metric defines the absolute limit for business survival.

❓ Frequently Asked Questions

What happens if the RTO is set higher than the MTD?

If RTO exceeds MTD, the business may suffer irreparable harm before the system is restored. This indicates a failure in the disaster recovery strategy and requires adjusting the recovery plan or increasing resources.


Is MTD the same for every process in an organization?

No. MTD varies based on the criticality of the process. A core payment gateway will have a much shorter MTD than an internal employee training portal, reflecting different levels of business impact.

Related Terms from Certified Information Systems Auditor

📝 Related Study Guides

Deep Dive 10 min read

CISA Exam: What to Expect and How to Prepare in 2026

The CISA exam consists of 150 multiple-choice questions to be completed in 4 hours, requiring a scaled score of 450/800 to pass. Preparation requires mastering five domains focusing on IT auditing, governance, acquisition, operations, and asset protection. Success depends on a risk-based mindset and understanding frameworks like COBIT.

Deep Dive 10 min read

Mastering COBIT 2019 for the CISA Exam

COBIT 2019 is a comprehensive framework for the governance and management of enterprise IT. For CISA candidates, it provides the essential structure to evaluate how an organization aligns IT goals with business objectives, manages risk, and ensures value delivery through a clear distinction between governance and management activities.

Comparison 7 min read

Attribute vs. Variable Sampling: CISA Exam Guide

Attribute sampling is used for compliance testing to determine if a control is functioning (yes/no), while variable sampling is used for substantive testing to estimate a numerical value or monetary amount. For the CISA exam, remember that attribute sampling checks for existence, and variable sampling checks for value.

🧠

Test Your Knowledge

Think you understand Maximum Tolerable Downtime (MTD)? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium