Cloud resilience glossary

Short answer

Thirty-nine terms used in cloud disaster recovery and infrastructure recovery, defined in one to three plain sentences each. Terms taken from a standard, regulator or official guidance link to that source; others link to the guide that covers them in depth.

Ranking current as of September 2026 · By the Cloud Resilience Vendors research desk

Air-gapped backup

A backup copy isolated from the production environment's network and credentials so an attacker in production cannot reach it.

Backup and restore

A cloud disaster recovery strategy in which data is backed up and restored after an incident, and the infrastructure, configuration and application code are redeployed at recovery time. Of the four strategies AWS describes, it has the longest recovery time. Cloud disaster recovery strategies

Source: AWS whitepaper, recovery options in the cloud

Business impact analysis (BIA)

The process of analyzing business functions and the effect a disruption might have on them. It is where the RTO and RPO for each service usually come from.

Source: NIST CSRC glossary (CNSSI 4009-2022, citing ISO/IEC 27031:2011)

Clean room recovery

Restoring into an isolated environment first, to investigate an attack and confirm systems are clean before returning them to production. Cohesity calls its version a Minimum Viable Recovery Environment.

ClickOps

Changes made by hand in a cloud console rather than through code. ClickOps resources are the ones infrastructure-as-code tools cannot rebuild unless they are codified first.

Cloud disaster recovery

The tools and process that bring a cloud service back after an outage, attack or error, including its infrastructure, configuration and data. Backup vs infrastructure recovery

Cloud recovery posture management

Continuous measurement of whether a cloud estate could be recovered. Sometimes called cloud resilience posture management. Cloud recovery posture management

Cloud resilience

The ability of a cloud service to keep running through, and recover from, outages, attacks and errors.

Codification

Generating infrastructure as code for resources that already exist but were not created from code.

Configuration backup

A captured copy of the live settings of cloud resources, such as network rules, identity policies and DNS records, that can be restored.

Configuration change history

A time-ordered record of changes to cloud resources: what changed, when and, where the platform records it, by whom. It is how a team finds the last known-good state to restore to. Configuration drift and why it breaks cloud recovery

Configuration drift

The difference between the running environment and its intended definition, usually caused by manual or out-of-band changes.

Cross-account recovery

Rebuilding an environment in a different cloud account or subscription, often a clean one the attacker has no access to.

Cross-region recovery

Rebuilding or failing over an environment into a different cloud region.

Cyber resiliency

In NIST's wording, the ability to anticipate, withstand, recover from, and adapt to adverse conditions, stresses, attacks, or compromises on systems that use or are enabled by cyber resources.

Source: NIST CSRC glossary (NIST SP 800-160 Vol. 2 Rev. 1)

Dependency mapping

Recording which resources an application needs, such as its network, identity and managed services, so they are restored together and in the right order.

Digital Operational Resilience Act (DORA)

EU Regulation 2022/2554, applied since 17 January 2025, which aims to let financial entities withstand, respond to and recover from ICT disruptions. It covers ICT risk management, ICT third-party risk, resilience testing, ICT-related incidents, information sharing and oversight of critical third-party providers. DORA and NIS2 recoverability evidence

Source: EIOPA

Failback

Returning a service from the recovery environment to its original location after the incident.

Failover

Switching a service to a recovery environment so it keeps running.

Golden image

A preconfigured, regularly updated system image or template used to rebuild a system quickly after an incident. CISA's ransomware guide recommends maintaining them for critical systems.

Source: CISA #StopRansomware Guide

Immutable backup

A backup that cannot be altered or deleted for a set period, including by administrators.

Infrastructure as code (IaC)

Defining cloud infrastructure in versioned files, such as Terraform, OpenTofu, Pulumi or CloudFormation, that tools apply to create it.

Infrastructure as code backup

Keeping the environment's definition as versioned code so it can be re-applied after an incident. Backup vs infrastructure recovery

Isolated recovery environment

A separate account, subscription or network, cut off from production credentials, into which systems are restored after an attack. Commvault Cloud Rewind and Cohesity both describe restoring into one. Designing a recovery target

Maximum tolerable downtime (MTD)

The amount of time a mission or business process can be disrupted without causing significant harm to the organization's mission. The RTO for a service should sit inside it.

Source: NIST CSRC glossary (NIST SP 800-34 Rev. 1)

Multi-site active/active

A cloud disaster recovery strategy in which the workload runs in several regions and serves traffic from all of them. Backups are still needed, because data corruption replicates across sites. Cloud disaster recovery strategies

Source: AWS whitepaper, recovery options in the cloud

NIS2 Directive

EU Directive 2022/2555, which sets a common cybersecurity framework across 18 critical sectors. Covered entities must take appropriate cybersecurity risk-management measures and notify authorities of significant incidents. Member States had until 17 October 2024 to transpose it. DORA and NIS2 recoverability evidence

Source: European Commission

Offline backup

A backup copy kept disconnected from the network so it cannot be reached from production. CISA's ransomware guide recommends offline, encrypted backups and, for cloud, keeping backups of infrastructure-as-code template files offline.

Source: CISA #StopRansomware Guide

OpenTofu

An open-source infrastructure-as-code tool that uses the same configuration language as Terraform. Several codification and recovery tools in this ranking can generate OpenTofu as well as Terraform.

Source: OpenTofu 1.12.0 release notes

Pilot light

A cloud disaster recovery strategy in which data is replicated to another region and core infrastructure is provisioned there, with application servers switched off until a test or a failover. Cloud disaster recovery strategies

Source: AWS whitepaper, recovery options in the cloud

Point-in-time recovery

Restoring to the state at a specific moment before an incident.

Ransomware-safe rollback

Restoring infrastructure and data to a state captured before an attack, from copies the attacker could not change.

Recovery orchestration

Software that runs the steps of a recovery in order, such as restoring dependencies first, starting services and switching traffic, instead of people following a runbook by hand. Recovery targets lesson

RPO (recovery point objective)

The most recent point in time you can recover to; how much change you can afford to lose. RTO and RPO for cloud infrastructure

RTO (recovery time objective)

The longest a service can be down before recovery must be complete. RTO and RPO for cloud infrastructure

Service quota

A limit a cloud provider sets, per account and region, on how many of a resource you can create. AWS's guidance on testing recovery advises checking quotas in the recovery region before you need them.

Source: AWS whitepaper, testing recovery

State file

The record an IaC tool such as Terraform keeps of the resources it manages. Losing or corrupting it makes rebuilds harder.

Terraform provider

The plugin that lets Terraform or OpenTofu manage a specific cloud or SaaS API. A tool that restores by generating Terraform can only restore resources the provider supports, a limitation Firefly's docs state. Infrastructure as code for recovery

Source: Firefly docs, Applications Backup and DR

Warm standby

A cloud disaster recovery strategy that keeps a scaled-down but fully functional copy of the production environment running in another region. Cloud disaster recovery strategies

Source: AWS whitepaper, recovery options in the cloud

Frequently asked questions about these terms

What is the difference between cloud backup and cloud disaster recovery?

Backup copies data. Cloud disaster recovery brings a working service back, which also needs its configuration, network, identity and DNS. Cloud backup vs infrastructure recovery.

What is the difference between RTO and RPO?

RTO is the longest a service can be down before recovery must be complete. RPO is the most recent point you can recover to, which sets how much change you can afford to lose. RTO and RPO for cloud infrastructure.

Where do the definitions come from?

Terms taken from a standard, regulator or official guidance link to that source. The rest are the site's own plain definitions and link to the guide that covers them.