OPS-07 Data Backup and Recovery - Monitoring
Watch backup execution through technical and organisational measures and have qualified staff investigate and rectify malfunctions promptly, so the agreed scope, frequency and retention of data backup are still achieved.
4
artefacts
3
held by a system
0
at each review
easy
to go live
Backup / DR tooling
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Backup job status report for a sampled period showing successes, failures and reruns · Backup / DR tooling
- Ticket trail following a failed job through to successful completion · Backup / DR tooling
- Alerting rule configuration for backup failure notifications · Backup / DR tooling
periodic reviewEvidence produced at each review
none for this control
governing documentDocuments that govern the control
- List of protected objects reconciled against the scheduled job definitions · Policy repository / GRC workspace
First move
Automate the pull from your Backup / DR tooling. Backup job success history and restore-test logs from the backup platform.
Common gaps auditors find
- Failures visible in the backup console but never raised as tickets or owned
- Jobs reported successful while individual volumes or files were skipped
- Alerting configured only for hard failures so silent partial backups pass unnoticed
- No responsible owner outside business hours so weekend failures wait until Monday
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetOPS-06 Data Backup and Recovery - Concept · OPS-08 Data Backup and Recovery - Regular Testing