Technology · Security · Component

Backup and recovery plan

What is backed up, how quickly each critical system must return, and dated evidence that restoring actually works.

The deliverable

What it is

Recovery is the function that decides how bad an incident becomes. Ransomware in particular goes after backups first, so the arrangements need at least one copy that cannot be altered or deleted from the main environment.

Recovery objectives are business decisions expressed in technical terms: how much data can be lost and how long a system can be down. Customer and regulatory handling of the same incident, including notification, sits with Compliance under incident response.

One level in

What it is made of

Each element is a constituent part of the component. Follow one to see the attributes it carries.

  1. Recovery objectives

    For each critical system, the maximum tolerable data loss and downtime, agreed with its business owner.

    4 attributes: System · Recovery point objective · Recovery time objective · Agreed by

    Learn
  2. Backup arrangement

    What is copied, how often, where it is held, and whether at least one copy is isolated from the main environment.

    3 attributes: Frequency · Held at · Isolated copy

    Learn
  3. Restore test

    The dated evidence that a system was restored from backup, how long it took, and what was learned in doing it.

    4 attributes: Tested · Actual restore time · Met objective · Findings

    Learn

A backup that has never been restored is a hypothesis. Test the restore, and time it.