Objective

Ensure a complete Odoo database and filestore archive is independently downloaded and stored each month.

Verification Requirements

The control must verify that each monthly backup:

  • Is performed once per month (first business day preferred).
  • Follows the SOP: navigate to https://www.bitkaya.io/odoo/settings/my-subscription?debug=1, click “Backups”, download the file.
  • Is renamed using the format YYYYMMDD Bitakaya Database Backup Odoo.zip.
  • Is uploaded to the approved SharePoint path: Bitkaya Compliance / Offsite Backups / Odoo.
  • Covers the full database and filestore.
  • Additional backups are triggered during high transaction periods, system changes or prior to major releases.
  • Exception handling: if download fails, retry once; if failure persists, notify IT/Admin and log incident. If upload fails, retry upload and escalate if unresolved.

Control Activity

An assigned operator performs the full external backup monthly, preferably on the first business day, and Compliance monitors completion and escalates missed backups. The assigned staff member executes the procedure and the compliance officer oversees adherence.

Evidence

  • Expected evidence: Monthly schedule and assignment
  • Expected evidence: Odoo download evidence
  • Expected evidence: Timestamped archive in approved storage
  • Expected evidence: Additional-backup evidence where triggered
  • Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: reconcile scheduled months to stored full backups and investigate missing or late execution
  • Testing frequency: monthly

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: documented; approval pending

History

  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.