EvidenceSheet

BACKUP-ML2 Regular Backups (ML2)

All ML1 requirements plus: Privileged user accounts (excluding backup administrator accounts) cannot access backups belonging to other user accounts. Privileged user accounts (excluding backup administrator accounts) are

8
artefacts
3
held by a system
3
at each review
moderate
to go live
Backup / DR tooling
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Backup platform RBAC export showing only Backup Operators / Backup Admins have read and modify rights · Backup / DR tooling
  • Audit log evidence of any privileged non-backup-admin access attempts to backups (none, or alerted) · Backup / DR tooling
  • Sample alert from SIEM if a non-backup-admin attempts to read or modify backup data · Backup / DR tooling

periodic reviewEvidence produced at each review

  • AD or IAM group membership evidence: Domain Admins are NOT a member of Backup Admins by default · Backup / DR tooling
  • Quarterly review of who holds backup admin entitlements · Backup / DR tooling
  • Documented break-glass process for backup admin loss with seal evidence · Backup / DR tooling

governing documentDocuments that govern the control

  • Separation of duties documentation between backup administrator role and other privileged roles · Policy repository / GRC workspace
  • Backup repository ACLs showing inheritance is blocked from broader admin groups · Policy repository / GRC workspace

First move

Start with the 3 of 8 artefacts that already live in a system (Backup / DR tooling); keep the periodic reviews but log each one as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

BACKUP-ML1 Regular Backups (ML1) · BACKUP-ML3 Regular Backups (ML3)