Objective
Ensure verified backups are recoverable and actual recovery is authorized, tested and reconciled.
Verification Requirements
The control must verify:
- Periodic restore testing is performed (required by the policy’s verification and integrity section).
- Incident handling follows the defined sequence: (1) attempt recovery via Odoo internal backups; (2) if unavailable, use latest Bitkaya external backup; (3) document incident and recovery process; (4) escalate to compliance if required.
- The accepted data-loss exposure (up to one month under the proportionality principle) is considered in restore-test results and data-gap assessment.
Control Activity
Technology performs a documented restore test at an approved periodic frequency and records recovery time, data gap, success criteria, defects and remediation.
Evidence
- Expected evidence: Restore-test schedule and plan
- Expected evidence: Selected backup and isolated environment evidence
- Expected evidence: Results, recovery duration and data-gap assessment
- Expected evidence: Defects, remediation and management review
- Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: inspect the latest restore test for representative scope, protected data, defined criteria, complete results and closed defects
- Testing frequency: periodic frequency to be approved; at least annual is recommended pending confirmation
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: documented; test frequency approval pending
History
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.