Backup Verification Data

Performing backups is necessary, but it is not the end of the process.

4 slides · 1 min read · Domain 6

Slide 1

The organization must verify that the data captured meets the compliance expectations and organizational requirements and can be restored within the prescribed time frame.

This measure, the Recovery Time Objective, is defined by the business owner of the data, and is influenced by the technology and business processes used to capture the backup information. The Recovery Point Objective is the measure of tolerable data loss, but is best expressed as the point in time to which the data is recovered.

The backup process must demonstrate that the system can actually be recovered. These verifications should be done with each backup performed consistent with the organization's practices. Failing to perform this verification gives the organization a false sense of trust that the control is actually working.

There is a broad range of artifacts the assessors will review to ensure the backup controls are working.

Some of those artifacts include:

  • the organization's systems inventories
  • control expectations
  • risk assessments
  • organizational policies and procedures
  • backup logs
  • backup inventories
  • and the verification and testing results.

These same artifacts will also be used to improve the operational performance of the backup environment and in a variety of other business processes.

The relationship between the activities and the artifacts is shown in the figure.

Text on this slide

Activity

Inventory (systems, information, processes)

Risk assessment

Backup plan

Backup execution

Artifacts

Compliance requirements Business expectations

Control priorities

Technical means Procedures Schedules

Performance logs: Onsite / Offsite

Verification

Verification results

Test this domain