The Backup & Recovery process ensures that data is backed up and made available in the event of a disaster to protect organizations against data loss. In the event of a failure, the back-up copy of the data can be used to restore critical information. Failures can come in all forms, from hardware and software failures to data deletion due to malicious events or accidents. In Such cases, restoring the lost or affected data from a backup allows the organization to resume key business functions.
The Objective of the process:
- Ensure that critical data is backed up, tested at regular intervals, and available to restore in the case of an unplanned event.
Sample list of benefits:
- Recover from an unplanned event, meeting RPO and RTO objectives
- Backing up at agreed to frequency and manner ensures that data is available and there is minimal impact to the organization
Sample list of observations:
- Critical applications are not defined
- Critical Infrastructure components are not defined
- Backups are not tested
- High volume of backup failures with no action
- Lack of reporting
Sample list of recommendations:
- Identify backup software
- Identify what is being backed up
- Identify types of backup
- Identify if the backed-up data is encrypted
- Identify if the backed-up data is compressed
- Identify frequency of backups
- Identify location of backups
- Identify Recovery Time Objective
- Identify Recovery Point Objective
- Ensure backups are being verified
- Ensure backup media is being monitored to avoid space issues
- Perform recovery tests at set frequency to ensure backups can be restored within the expected timeframes
Assessment Questions:
- What backup software are you using?
- What is being backed up?
- What types of backup are you doing?
- Is the backed-up data is encrypted?
- Is the backed-up data is compressed?
- What is the frequency of the backups?
- What is the location of the backups?
- What is the Recovery Time Objective?
- What is the Recovery Point Objective?
- How are backups being verified?
- How is the backup media being monitored to avoid space issues?
- How often are you performing recovery tests to ensure backups can be restored within the expected timeframes?