Objective

Ensure every scheduled backup has documented upload, apparent integrity, responsible ownership and exception evidence.

Verification Requirements

The control must verify for each backup:

  • File integrity is verified after upload.
  • File size and completeness are checked.
  • Upload completed successfully; file size is consistent; optionally download the file to confirm accessibility.
  • The backup log includes: date of backup, file name, responsible person, verification status.
  • The log ensures auditability, accountability and compliance evidence.

Control Activity

The operator verifies each uploaded archive and records required metadata; Compliance reconciles the schedule, backup log and stored files monthly.

Evidence

  • Expected evidence: Backup log
  • Expected evidence: File size, filename and accessibility check
  • Expected evidence: Schedule-to-storage reconciliation
  • Expected evidence: Exception and remediation records
  • Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: sample log entries to stored files and verify date, filename, owner, size, status and exception resolution
  • Testing frequency: monthly

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: documented; approval pending

History

  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.