Purpose
Protect Odoo backup archives in Microsoft 365 SharePoint and control their location, access, retention, archival and disposal.
Offsite Storage Rationale
Microsoft 365 SharePoint is the primary offsite storage solution because it provides:
- Existing enterprise infrastructure
- Strong access control and audit logging
- Integration with internal workflows
- Geographic redundancy
Storage Structure
Backups are stored in: Bitkaya Compliance / offsite Backups (Bitkaya) / Odoo (Bitkaya)
Security Controls
The Microsoft 365 SharePoint environment provides:
- Access control via role-based permissions
- Audit logging and monitoring
- Secure transmission (HTTPS)
Given these controls, additional encryption of backup files is not required under this policy. Access to backup files remains restricted to authorized personnel.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Maintain approved path | Maintain one approved SharePoint path for production Odoo backups: Bitkaya Compliance / offsite Backups (Bitkaya) / Odoo (Bitkaya) | Storage path configuration |
| 2 | Restrict access | Restrict access to named roles with documented business, technology or compliance need. Follow internal access control policies for Microsoft 365 | Access matrix |
| 3 | Rely on SharePoint controls | Rely on SharePoint’s role-based permissions, audit logging and monitoring, and HTTPS secure transmission. Resolve the separate-file encryption requirement before approval — the policy states additional encryption is not required given the existing SharePoint controls | Control reliance confirmation |
| 4 | Review access | Review access at least quarterly and after role change or departure | Access review record |
| 5 | Apply retention | Retain monthly backups for a minimum of 12 months. Apply extended retention based on regulatory requirements. Older backups may be archived or securely deleted | Retention schedule |
| 6 | Apply legal hold | Place records under legal, investigation or supervisory hold where applicable | Hold notice |
| 7 | Approve archival or deletion | Approve and evidence secure archival or deletion after retention expires | Archival or deletion approval |
| 8 | Monitor activity | Monitor storage, access and deletion events for unauthorized activity | Monitoring log |
| 9 | Enforce storage boundary | Store backups only within the approved SharePoint location. Do not distribute backup files outside the controlled environment | Storage boundary confirmation |
Records
- Approved storage path and configuration (
Bitkaya Compliance / offsite Backups / Odoo) - Access matrix, approvals and periodic reviews
- Microsoft 365 audit logs and security evidence (role-based permissions, HTTPS, monitoring)
- Retention schedule (minimum 12 months), holds, archival and deletion evidence
Relationships
- Policy: POL-ODOO-001 Odoo SaaS Backup Policy
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Control: CTRL-ODOO-003 Ensure Odoo Backup Storage Access Retention and Disposal Are Controlled
History
- 2026-07-26: Created from sections 6-8 and 15.5 of the final Odoo backup policy.