Controls / Backups
Restoring from backup is tested as part of a disaster recovery exercise
What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: test a restore from backup as part of a disaster recovery exercise.
In Australia
Maturity Level One
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1515 Essential Eight, Maturity Level One | Restoration of data, applications and settings from backups to a common point in time is tested as part of disaster recovery exercises. Required at Maturity Levels One, Two and Three of the Regular backups mitigation strategy (Appendices A, B and C); ISM control ISM-1515 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Disaster recovery exercise records with restoration to a common point in time; Test results and issues found |
In the United States
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 11.5 CIS Controls v8.1 | Test Data Recovery At least once a quarter, test recovery from backup for a sample of in-scope enterprise assets. The requirement's own words: At least once a quarter evidence an assessor asks for Quarterly recovery test reports naming the sample of assets restored, the restore time achieved and the integrity checks performed; Follow-up records for any recovery test failures, with the corrective actions taken and the retest result; Annual test schedule showing which systems are sampled each quarter so critical systems are covered over the year; Restore evidence such as application owner sign-off that restored data was complete and usable; Comparison of actual restore times achieved against the RTO targets, with gaps escalated |
| PR.DS-11 NIST CSF 2.0 | Backups of data are created, protected, maintained, and tested. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect. evidence an assessor asks for Backup policy with frequency and retention; Backup integrity test reports; Immutable backup configuration evidence; Restoration test records with success criteria; Backup access control and audit logs |
HIPAA Security Rule, when it applies
HIPAA covered entities (health plans, health care clearinghouses, health care providers that transmit health information electronically) and their business associates.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| 164.308(a)(7)(ii)(D) HIPAA Security Rule (add-on) | Testing and Revision Procedures (Addressable) Implement procedures for periodic testing and revision of contingency plans. NIST recommends annual tabletop, biennial functional, and post-incident lessons-learned updates. evidence an assessor asks for Test schedule; Test reports; After-action reports; Plan revision history |
In United Kingdom
No requirement in the core list for the United Kingdom covers this control; it is on the schedule as a condition beyond the core list.
Also cited: ISO/IEC 27001:2022 Annex A
A lens in any jurisdiction, never a gap on its own.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.13 ISO/IEC 27001:2022 (lens) | Information backup Backups of information, software and systems are to be kept and tested regularly as the agreed topic-specific backup policy requires. Purpose (stated in ISO/IEC 27002:2022): makes it possible to recover lost data or systems. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.13. evidence an assessor asks for Statement of Applicability entry for control A.8.13, showing inclusion or justified exclusion, implementation status and the risks it treats; The topic-specific backup policy and backup plans stating scope, extent, frequency and retention per system aligned with RPO; Backup job monitoring reports with evidence that failed jobs were investigated and rerun; Restore test records onto test systems, checked against the recovery time in the continuity plan; Evidence of off-site or geographically separate backup storage with suitable physical protection |
Questions
- What does the applicant report for this control?
- Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
- When is it due on the 90-day schedule?
- Day 30 by the default rule (backups), unless it is marked not sure (day 90). The underwriter or broker can move it.
- Does this page check the control?
- No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.