EvidenceSheet

8.13 Information backup

Requires backup copies of information, software and systems to be maintained and regularly tested, in line with the agreed topic specific policy on backup. Supporting SME guidance treats regular creation of backups toget

5
artefacts
2
held by a system
1
at each review
moderate
to go live
Backup / DR tooling
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Backup job records for the period showing successes and failures, and the follow up on failures · Backup / DR tooling
  • Restoration test records showing actual restores performed, what was restored and whether it met the recovery objective · Backup / DR tooling

periodic reviewEvidence produced at each review

  • Evidence of backup protection, including encryption, access restriction and immutability or offline copies against ransomware · Backup / DR tooling

governing documentDocuments that govern the control

  • The backup policy setting scope, frequency, retention and recovery objectives per system · Policy repository / GRC workspace
  • Evidence the backup scope matches the current environment, reconciled against the asset inventory · Policy repository / GRC workspace

First move

Start with the 2 of 5 artefacts that already live in a system (Backup / DR tooling); keep the periodic reviews but log each one as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

8.12 Data leakage prevention · 8.14 Redundancy of information processing facilities