Accreditation  Definition(s): Formal declaration by a Designated Accrediting Authority (DAA) or Principal Accrediting Authority (PAA) that an information system is approved to operate at an acceptable level of risk, based

Acceptable Risk  Definition(s): The level of residual risk that has been determined to be a reasonable level of potential loss/disruption for a specific IT System.  Source: NIST 800-16 A level

Disaster Recovery (DR)  Definition(s): The Strategies and plans for recovering and restoring the organization’s technological infra-structure and capabilities after a serious interruption.  Source: BCI The process, policies and procedures to

Maximum Allowable Downtime (MAD)  Definition(s): The absolute maximum time that the system can be unavailable without direct or indirect ramifications to the organization.  Source: BCM Institute The maximum time a