Purpose
Demonstrate that Odoo backups can be restored and govern controlled recovery after data loss or service failure.
Incident Handling Procedure
In case of data loss or system failure:
- Attempt recovery via Odoo internal backups.
- If unavailable, use the latest Bitkaya external backup.
- Document the incident and recovery process.
- Escalate to compliance if required.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Define restore-test plan | Define a periodic restore-test schedule, scope, environment, success criteria and authorized participants. Periodic restore testing is required by the policy’s verification and integrity section | Restore-test plan |
| 2 | Select backup | Select a representative verified backup and preserve its metadata | Selected backup record |
| 3 | Restore in isolated environment | Restore in an isolated, authorized environment without exposing production personal data unnecessarily | Restore environment record |
| 4 | Confirm restoration | Confirm database and filestore availability, record counts, key functions and observed data gap | Restore verification result |
| 5 | Record test results | Record duration, result, defects, security observations and corrective actions | Test result record |
| 6 | Attempt incident recovery | For an incident, attempt provider (Odoo internal) recovery first where appropriate, then use the latest verified Bitkaya external backup | Recovery attempt record |
| 7 | Obtain incident authority | Obtain incident authority before production recovery and communicate operational and regulatory impacts | Recovery authorization |
| 8 | Document and escalate | Document the incident and recovery process. Escalate to compliance if required | Incident and escalation record |
| 9 | Reconcile and close | Reconcile, remediate and close the recovery with management review | Closure record |
Records
- Restore-test plan and selected backup
- Restore evidence, success criteria and results
- Recovery authorization and incident record (including documented recovery process and compliance escalation if required)
- Data-gap assessment (up to one month under proportionality principle), reconciliation and remediation
Relationships
- Policy: POL-ODOO-001 Odoo SaaS Backup Policy
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Control: CTRL-ODOO-005 Ensure Odoo Backups Are Restored and Recovery Is Tested
History
- 2026-07-26: Created from sections 9 and 11 of the final Odoo backup policy.