PlumbTrackLive demoGRC Risk System

← internal audit

Audit — CP-9 — System Backup

Framework: NIST SP 800-53 Rev.5 CP-9 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 7 checked
Examine Examine the backup policy, procedures, and System Security Plan to confirm defined backup frequencies for user-level information, system-level information, and system/security documentation are documented and consistent with the organization's Recovery Time Objective (RTO) and Recovery Point Objective (RPO).
Examine Examine backup job logs and schedules across a sample period to verify backups of user-level and system-level information completed successfully at the defined frequency, and that failures generated alerts and were remediated (CIS Control 11.2, Perform Automated Backups).
Test Test an actual restoration from backup media for a sampled dataset to confirm the backup is readable, complete, and integrity-intact, and that restoration finishes within the expected timeframe (CIS Control 11.5, Test Data Recovery).
Examine Examine encryption and hashing configuration/records to verify backup data confidentiality and integrity are protected at rest and in transit (for example cryptographic protection of backup media and verified checksums) (CIS Control 11.3, Protect Recovery Data).
Examine Examine storage-location records to confirm at least one backup copy is retained offsite or in an isolated, offline, or immutable location physically and logically separate from the primary system (CIS Control 11.4, Establish and Maintain an Isolated Instance of Recovery Data).
Test Test the access controls on backup repositories and management consoles to confirm only authorized personnel can read, modify, or delete backups, so that a compromised production account (or ransomware) cannot destroy recovery copies.
Interview Interview backup administrators to confirm assigned roles and responsibilities, defined retention periods, and the documented process for verifying backup completion and escalating and correcting failed jobs.