A.8.13 Information backup
Maintain and regularly test backups of information, software and systems per the backup policy.
15
artefacts
5
held by a system
2
at each review
moderate
to go live
Backup / DR tooling
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Automated backup job configurations · Backup / DR tooling
- Test case execution log · Backup / DR tooling
- Decommissioned backup disposal log · Backup / DR tooling
- Backup system access log · Backup / DR tooling
- Audit trail of backup restores · Backup / DR tooling
periodic reviewEvidence produced at each review
- Quarterly restore test report · Backup / DR tooling
- Failure remediation record · Backup / DR tooling
governing documentDocuments that govern the control
- Documented backup policy · Policy repository / GRC workspace
- Policy approval minutes · Policy repository / GRC workspace
- Policy change log · Policy repository / GRC workspace
- Backup run calendar · Policy repository / GRC workspace
- Backup window approval email · Policy repository / GRC workspace
- Retention matrix · Policy repository / GRC workspace
- Archived backup inventory · Policy repository / GRC workspace
- Privileged account usage report · Policy repository / GRC workspace
First move
Start with the 5 of 15 artefacts that already live in a system (Backup / DR tooling); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- infrequent restore testing
- missing retention documentation
- undefined backup responsibilities
- inconsistent backup verification
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetA.8.12 Data leakage prevention · A.8.14 Redundancy of information processing facilities