RPO defines the maximum tolerable data loss in case of a disruption - i.e., how much data the enterprise can afford to lose between the last backup and an incident. ISACA's business continuity and CRISC guidance: "The recovery point objective (RPO) is based on the amount of acceptable data loss determined by business requirements." * A, C, D are logistical concerns; only B defines the RPO itself. CRISC Reference: Domain 3 - Risk Response and Mitigation, Topic: Business Continuity Objectives (RTO /RPO).