Backup Verification Data
Performing backups is necessary, but it is not the end of the process.
4 slides · 1 min read · Domain 6
The organization must verify that the data captured meets the compliance expectations and organizational requirements and can be restored within the prescribed time frame.
This measure, the Recovery Time Objective, is defined by the business owner of the data, and is influenced by the technology and business processes used to capture the backup information. The Recovery Point Objective is the measure of tolerable data loss, but is best expressed as the point in time to which the data is recovered.
The backup process must demonstrate that the system can actually be recovered. These verifications should be done with each backup performed consistent with the organization's practices. Failing to perform this verification gives the organization a false sense of trust that the control is actually working.
There is a broad range of artifacts the assessors will review to ensure the backup controls are working.
Some of those artifacts include:
- the organization's systems inventories
- control expectations
- risk assessments
- organizational policies and procedures
- backup logs
- backup inventories
- and the verification and testing results.
These same artifacts will also be used to improve the operational performance of the backup environment and in a variety of other business processes.
The relationship between the activities and the artifacts is shown in the figure.
Text on this slide
Activity
Inventory (systems, information, processes)
Risk assessment
Backup plan
Backup execution
Artifacts
Compliance requirements Business expectations
Control priorities
Technical means Procedures Schedules
Performance logs: Onsite / Offsite
Verification
Verification results
