Establish and maintain a documented data recovery process. In the process, address the scope
of data recovery activities, recovery prioritization, and the security of backup data. Review and
update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
The media used for backups and the restoration of backups are tested regularly to ensure that they can be relied on in an emergency.
Accurate and complete instructions are maintained for restoring backups. The policy is used to monitor the operation of backups and to prepare for backup failures.
In connection with the data systems listing, we describe for which systems we are responsible for the implementation of the backup. The organization’s own backup processes are documented and an owner is assigned to each. The documentation includes e.g.:
The organization should have a clear, written step-by-step procedure for carrying out data restoration efforts. There should also be a log of data restorations carried out. The log should contain:
With adequate backups, all important data and programs can be restored after a disaster or media failure. To determine your backup strategy, it is important to map / decide on at least the following: