Requirement:
The cybersecurity requirements for backup and recovery management must be implemented.
Control Implementation Guidelines:
- All cybersecurity requirements must be implemented for the organization's approved Backup and Recovery Management procedures. It is also recommended that the Backup and Recovery Management procedures cover the following, but not limited to:
- Appropriate and advanced technologies for backups must be used
- Scope and coverage of critical information and technology systems backups
- Fast recovery of data and systems after exposure to cybersecurity incidents must be implemented
- Periodic inspection of backup recovery effectiveness must be implemented
- Period required for backup must be defined, including but not limited to, backup of changing data in the last 24 hours
Expected Deliverables:
- An action plan to implement cybersecurity requirements for backup and recovery management
- Evidence such as, but not limited to, a screenshot of a backup tool showing the latest backups taken, schedule and scope of backups
Quick & Simple
Discover Our Cybersecurity Compliance Solutions:
Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you