Cloud resilience glossary
Thirty-nine terms used in cloud disaster recovery and infrastructure recovery, defined in one to three plain sentences each. Terms taken from a standard, regulator or official guidance link to that source; others link to the guide that covers them in depth.
Ranking current as of September 2026 · By the Cloud Resilience Vendors research desk
Air-gapped backup
A backup copy isolated from the production environment's network and credentials so an attacker in production cannot reach it.
Backup and restore
A cloud disaster recovery strategy in which data is backed up and restored after an incident, and the infrastructure, configuration and application code are redeployed at recovery time. Of the four strategies AWS describes, it has the longest recovery time. Cloud disaster recovery strategies
Business impact analysis (BIA)
The process of analyzing business functions and the effect a disruption might have on them. It is where the RTO and RPO for each service usually come from.
Source: NIST CSRC glossary (CNSSI 4009-2022, citing ISO/IEC 27031:2011)
Clean room recovery
Restoring into an isolated environment first, to investigate an attack and confirm systems are clean before returning them to production. Cohesity calls its version a Minimum Viable Recovery Environment.
ClickOps
Changes made by hand in a cloud console rather than through code. ClickOps resources are the ones infrastructure-as-code tools cannot rebuild unless they are codified first.
Cloud disaster recovery
The tools and process that bring a cloud service back after an outage, attack or error, including its infrastructure, configuration and data. Backup vs infrastructure recovery
Cloud recovery posture management
Continuous measurement of whether a cloud estate could be recovered. Sometimes called cloud resilience posture management. Cloud recovery posture management
Cloud resilience
The ability of a cloud service to keep running through, and recover from, outages, attacks and errors.
Codification
Generating infrastructure as code for resources that already exist but were not created from code.
Configuration backup
A captured copy of the live settings of cloud resources, such as network rules, identity policies and DNS records, that can be restored.
Configuration change history
A time-ordered record of changes to cloud resources: what changed, when and, where the platform records it, by whom. It is how a team finds the last known-good state to restore to. Configuration drift and why it breaks cloud recovery
Configuration drift
The difference between the running environment and its intended definition, usually caused by manual or out-of-band changes.
Cross-account recovery
Rebuilding an environment in a different cloud account or subscription, often a clean one the attacker has no access to.
Cross-region recovery
Rebuilding or failing over an environment into a different cloud region.
Cyber resiliency
In NIST's wording, the ability to anticipate, withstand, recover from, and adapt to adverse conditions, stresses, attacks, or compromises on systems that use or are enabled by cyber resources.
Dependency mapping
Recording which resources an application needs, such as its network, identity and managed services, so they are restored together and in the right order.
Digital Operational Resilience Act (DORA)
EU Regulation 2022/2554, applied since 17 January 2025, which aims to let financial entities withstand, respond to and recover from ICT disruptions. It covers ICT risk management, ICT third-party risk, resilience testing, ICT-related incidents, information sharing and oversight of critical third-party providers. DORA and NIS2 recoverability evidence
Source: EIOPA
Failback
Returning a service from the recovery environment to its original location after the incident.
Failover
Switching a service to a recovery environment so it keeps running.
Golden image
A preconfigured, regularly updated system image or template used to rebuild a system quickly after an incident. CISA's ransomware guide recommends maintaining them for critical systems.
Source: CISA #StopRansomware Guide
Immutable backup
A backup that cannot be altered or deleted for a set period, including by administrators.
Infrastructure as code (IaC)
Defining cloud infrastructure in versioned files, such as Terraform, OpenTofu, Pulumi or CloudFormation, that tools apply to create it.
Infrastructure as code backup
Keeping the environment's definition as versioned code so it can be re-applied after an incident. Backup vs infrastructure recovery
Isolated recovery environment
A separate account, subscription or network, cut off from production credentials, into which systems are restored after an attack. Commvault Cloud Rewind and Cohesity both describe restoring into one. Designing a recovery target
Maximum tolerable downtime (MTD)
The amount of time a mission or business process can be disrupted without causing significant harm to the organization's mission. The RTO for a service should sit inside it.
Multi-site active/active
A cloud disaster recovery strategy in which the workload runs in several regions and serves traffic from all of them. Backups are still needed, because data corruption replicates across sites. Cloud disaster recovery strategies
NIS2 Directive
EU Directive 2022/2555, which sets a common cybersecurity framework across 18 critical sectors. Covered entities must take appropriate cybersecurity risk-management measures and notify authorities of significant incidents. Member States had until 17 October 2024 to transpose it. DORA and NIS2 recoverability evidence
Source: European Commission
Offline backup
A backup copy kept disconnected from the network so it cannot be reached from production. CISA's ransomware guide recommends offline, encrypted backups and, for cloud, keeping backups of infrastructure-as-code template files offline.
Source: CISA #StopRansomware Guide
OpenTofu
An open-source infrastructure-as-code tool that uses the same configuration language as Terraform. Several codification and recovery tools in this ranking can generate OpenTofu as well as Terraform.
Source: OpenTofu 1.12.0 release notes
Pilot light
A cloud disaster recovery strategy in which data is replicated to another region and core infrastructure is provisioned there, with application servers switched off until a test or a failover. Cloud disaster recovery strategies
Point-in-time recovery
Restoring to the state at a specific moment before an incident.
Ransomware-safe rollback
Restoring infrastructure and data to a state captured before an attack, from copies the attacker could not change.
Recovery orchestration
Software that runs the steps of a recovery in order, such as restoring dependencies first, starting services and switching traffic, instead of people following a runbook by hand. Recovery targets lesson
RPO (recovery point objective)
The most recent point in time you can recover to; how much change you can afford to lose. RTO and RPO for cloud infrastructure
RTO (recovery time objective)
The longest a service can be down before recovery must be complete. RTO and RPO for cloud infrastructure
Service quota
A limit a cloud provider sets, per account and region, on how many of a resource you can create. AWS's guidance on testing recovery advises checking quotas in the recovery region before you need them.
Source: AWS whitepaper, testing recovery
State file
The record an IaC tool such as Terraform keeps of the resources it manages. Losing or corrupting it makes rebuilds harder.
Terraform provider
The plugin that lets Terraform or OpenTofu manage a specific cloud or SaaS API. A tool that restores by generating Terraform can only restore resources the provider supports, a limitation Firefly's docs state. Infrastructure as code for recovery
Warm standby
A cloud disaster recovery strategy that keeps a scaled-down but fully functional copy of the production environment running in another region. Cloud disaster recovery strategies
Frequently asked questions about these terms
What is the difference between cloud backup and cloud disaster recovery?
Backup copies data. Cloud disaster recovery brings a working service back, which also needs its configuration, network, identity and DNS. Cloud backup vs infrastructure recovery.
What is the difference between RTO and RPO?
RTO is the longest a service can be down before recovery must be complete. RPO is the most recent point you can recover to, which sets how much change you can afford to lose. RTO and RPO for cloud infrastructure.
Where do the definitions come from?
Terms taken from a standard, regulator or official guidance link to that source. The rest are the site's own plain definitions and link to the guide that covers them.