Objective
Ensure every scheduled backup has documented upload, apparent integrity, responsible ownership and exception evidence.
Verification Requirements
The control must verify for each backup:
- File integrity is verified after upload.
- File size and completeness are checked.
- Upload completed successfully; file size is consistent; optionally download the file to confirm accessibility.
- The backup log includes: date of backup, file name, responsible person, verification status.
- The log ensures auditability, accountability and compliance evidence.
Control Activity
The operator verifies each uploaded archive and records required metadata; Compliance reconciles the schedule, backup log and stored files monthly.
Evidence
- Expected evidence: Backup log
- Expected evidence: File size, filename and accessibility check
- Expected evidence: Schedule-to-storage reconciliation
- Expected evidence: Exception and remediation records
- Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: sample log entries to stored files and verify date, filename, owner, size, status and exception resolution
- Testing frequency: monthly
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: documented; approval pending
History
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.