EvidenceSheet

BACKUP-ML1 Regular Backups (ML1)

Backups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements. Backups of data, applications and settings are synchronised to enable re

8
artefacts
3
held by a system
1
at each review
moderate
to go live
Backup / DR tooling
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Backup tool configuration (Veeam, Commvault, Rubrik, Azure Backup, AWS Backup) showing scope covers data, applications and OS settings/system state · Backup / DR tooling
  • Synchronisation evidence: backup job schedules showing common-point-in-time consistency or application-consistent quiesce · Backup / DR tooling
  • Sample restore tickets to demonstrate restorability · Backup / DR tooling

periodic reviewEvidence produced at each review

  • Off-site or offline backup evidence (immutable storage, air-gapped tape, separate cloud tenant) · Backup / DR tooling

governing documentDocuments that govern the control

  • Backup policy with RTO, RPO and retention by data classification · Policy repository / GRC workspace
  • DR test plan and most recent test report with restoration evidence (file, application, settings) to a common PIT · Policy repository / GRC workspace
  • Access control matrix showing unprivileged users cannot read other users' backups (NTFS / IAM) · Policy repository / GRC workspace
  • Backup repository ACLs showing unprivileged users have no modify or delete rights · Policy repository / GRC workspace

First move

Start with the 3 of 8 artefacts that already live in a system (Backup / DR tooling); keep the periodic reviews but log each one as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

APP-ML3 Application Control (ML3) · BACKUP-ML2 Regular Backups (ML2)