BACKUP-ML1 Regular Backups (ML1)
Backups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements. Backups of data, applications and settings are synchronised to enable re
8
artefacts
3
held by a system
1
at each review
moderate
to go live
Backup / DR tooling
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Backup tool configuration (Veeam, Commvault, Rubrik, Azure Backup, AWS Backup) showing scope covers data, applications and OS settings/system state · Backup / DR tooling
- Synchronisation evidence: backup job schedules showing common-point-in-time consistency or application-consistent quiesce · Backup / DR tooling
- Sample restore tickets to demonstrate restorability · Backup / DR tooling
periodic reviewEvidence produced at each review
- Off-site or offline backup evidence (immutable storage, air-gapped tape, separate cloud tenant) · Backup / DR tooling
governing documentDocuments that govern the control
- Backup policy with RTO, RPO and retention by data classification · Policy repository / GRC workspace
- DR test plan and most recent test report with restoration evidence (file, application, settings) to a common PIT · Policy repository / GRC workspace
- Access control matrix showing unprivileged users cannot read other users' backups (NTFS / IAM) · Policy repository / GRC workspace
- Backup repository ACLs showing unprivileged users have no modify or delete rights · Policy repository / GRC workspace
First move
Start with the 3 of 8 artefacts that already live in a system (Backup / DR tooling); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Backups exist but DR exercises only test infrastructure, not data restoration
- Backups stored on the same hypervisor or cloud account as production (not resilient)
- Application settings not backed up, only data
- Last DR test more than 12 months old
- User home drives backed up to a share where users can delete their own backups
- Common point-in-time restoration untested because each system uses different schedules
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetAPP-ML3 Application Control (ML3) · BACKUP-ML2 Regular Backups (ML2)