9.4.1.2 Offsite backup location reviewed
The security of the offline media backup location is reviewed at least once every 12 months.
5
artefacts
1
held by a system
3
at each review
hard
to go live
Document repository
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Remediation tickets for findings · Ticketing / ITSM
periodic reviewEvidence produced at each review
- Annual offsite site visit report · Document repository
- Review checklist completed and signed · Document repository
- Approval to continue use post-review · Document repository
governing documentDocuments that govern the control
- Vendor SOC 2 or equivalent report · Vendor register / contract repository
First move
Mostly documents and reviews. Pull the 1 system-held artefact from your Ticketing / ITSM on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.
Common gaps auditors find
- No site visits
- Findings not remediated
- Review checklist absent
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet9.4.1.1 Offline media backup security · 9.4.2 Media classified by sensitivity