BACKUP-ML2 Regular Backups (ML2)
All ML1 requirements plus: Privileged user accounts (excluding backup administrator accounts) cannot access backups belonging to other user accounts. Privileged user accounts (excluding backup administrator accounts) are
8
artefacts
3
held by a system
3
at each review
moderate
to go live
Backup / DR tooling
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Backup platform RBAC export showing only Backup Operators / Backup Admins have read and modify rights · Backup / DR tooling
- Audit log evidence of any privileged non-backup-admin access attempts to backups (none, or alerted) · Backup / DR tooling
- Sample alert from SIEM if a non-backup-admin attempts to read or modify backup data · Backup / DR tooling
periodic reviewEvidence produced at each review
- AD or IAM group membership evidence: Domain Admins are NOT a member of Backup Admins by default · Backup / DR tooling
- Quarterly review of who holds backup admin entitlements · Backup / DR tooling
- Documented break-glass process for backup admin loss with seal evidence · Backup / DR tooling
governing documentDocuments that govern the control
- Separation of duties documentation between backup administrator role and other privileged roles · Policy repository / GRC workspace
- Backup repository ACLs showing inheritance is blocked from broader admin groups · Policy repository / GRC workspace
First move
Start with the 3 of 8 artefacts that already live in a system (Backup / DR tooling); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Domain Admins implicitly hold backup admin rights via inheritance
- Backup admin role not separated; the same identity holds Tier 0 and backup admin
- Backup vault on the same identity plane (same AD forest) as production with admin reachability
- No alert when a non-backup-admin reads the backup repository
- Backup admin role granted permanently rather than via JIT
- Audit logs of backup access not retained or not monitored
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetBACKUP-ML1 Regular Backups (ML1) · BACKUP-ML3 Regular Backups (ML3)