Two recovery targets
Recovery time objective is the target maximum time to restore a service or function after disruption. Recovery point objective is the target maximum data loss measured backward from the event. They are business and engineering targets, not guarantees produced by a backup setting.
Derive by function
Set objectives for specific functions and dependencies: authentication, policy decision, route enforcement, application access, audit, administration, and recovery. Identify harm during unavailability and harm from lost or inconsistent data.
Include detection, decision, access to recovery credentials, infrastructure provisioning, restore, reconciliation, validation, and safe reopening in recovery time. Include asynchronous replication, queues, caches, and cross-system consistency in recovery point.
Test and measure
Exercise realistic loss of data, region, identity provider, control plane, key, administrator, and trusted build. Measure from event or declared start according to the stated objective through verified user service and negative security tests. Record manual steps and staffing.
Test degraded modes and priorities. A lower-risk read-only service can recover before sensitive administration.
Failure and residual risk
Aggressive RPO can copy corruption quickly. Aggressive RTO can encourage unsafe fail-open access or unverified restore. Objectives can omit third-party and human delays. A test with pre-positioned staff can understate real recovery.
Meeting availability targets does not prove confidentiality, integrity, revocation, or evidence restoration.
Pomerium boundary
Pomerium is one component in the access path. Operators set objectives across DNS, certificates, keys, identity provider, policy, runtime, upstream, logs, and administration. Pomerium availability cannot make an unavailable identity provider or application meet its objective without a designed degraded mode.
Evaluation checklist
- Which exact function, users, security property, data, and dependencies does each objective cover?
- Does recovery time include detection, decision, credential access, provisioning, validation, and safe reopening?
- Does recovery point include queues, replicas, configuration, policy, identity, and cross-system consistency?
- Can faster replication preserve corruption or faster recovery restore unsafe authority?
- Do exercises measure real people, providers, credentials, dependencies, negative tests, and residual data loss?
