SAMMY UI is optimized for resolutions with a width 1024px and higher.
Backup
BCR-08: Is cloud data periodically backed up?
Implementation of backups and/or other means of data preservation (e.g., replication) should follow the following guidelines.
a. The scope, frequency, and duration of cloud data retention should comply with:
Applicable laws
Contractual agreements with the cloud customers
The cloud provider’s business requirements

b. The backup approach, including the physical location of backup files, should comply with the privacy and data protection laws and regulations applicable to the data collected.
c. The data backup process should be monitored by employing technical and organizational safeguards. At a minimum, malfunctions should be examined and eliminated promptly by qualified employees to support compliance with the retention’s scope, frequency, and duration.
d. Backup and restoration procedures should be periodically tested and the results documented to ensure data can be successfully restored. Tests should be designed so that the reliability of the backup media and the restoration time (RPO, RTO) can be established with sufficient certainty. Any errors and identified improvements (corrective and preventive actions) should be addressed promptly.
e. Restorations should be carried out only after they have been approved by authorized persons (according to contractual agreements with cloud customers or the internal policies of the cloud provider).
f. The cloud service provider, when appropriate, should be able to disclose the exercise results to the cloud services customer as part of the assurance of business continuity and resilience.

Additional guidance is also available in the NIST Special Publication 800-53 (Rev. 4) CP-9 INFORMATION SYSTEM BACKUP (latest revision).
Control implemented
Control ownership
Description

Periodically backup data stored in the cloud. Ensure the confidentiality, integrity and availability of the backup, and verify data restoration from backup for resiliency.

Backup
BCR-08: Is the confidentiality, integrity, and availability of backup data ensured?
Implementation of backups and/or other means of data preservation (e.g., replication) should follow the following guidelines.
a. The scope, frequency, and duration of cloud data retention should comply with:
Applicable laws
Contractual agreements with the cloud customers
The cloud provider’s business requirements

b. The backup approach, including the physical location of backup files, should comply with the privacy and data protection laws and regulations applicable to the data collected.
c. The data backup process should be monitored by employing technical and organizational safeguards. At a minimum, malfunctions should be examined and eliminated promptly by qualified employees to support compliance with the retention’s scope, frequency, and duration.
d. Backup and restoration procedures should be periodically tested and the results documented to ensure data can be successfully restored. Tests should be designed so that the reliability of the backup media and the restoration time (RPO, RTO) can be established with sufficient certainty. Any errors and identified improvements (corrective and preventive actions) should be addressed promptly.
e. Restorations should be carried out only after they have been approved by authorized persons (according to contractual agreements with cloud customers or the internal policies of the cloud provider).
f. The cloud service provider, when appropriate, should be able to disclose the exercise results to the cloud services customer as part of the assurance of business continuity and resilience.

Additional guidance is also available in the NIST Special Publication 800-53 (Rev. 4) CP-9 INFORMATION SYSTEM BACKUP (latest revision).
Control implemented
Control ownership
Description

Periodically backup data stored in the cloud. Ensure the confidentiality, integrity and availability of the backup, and verify data restoration from backup for resiliency.

Backup
BCR-08: Can backups be restored appropriately for resiliency?
Implementation of backups and/or other means of data preservation (e.g., replication) should follow the following guidelines.
a. The scope, frequency, and duration of cloud data retention should comply with:
Applicable laws
Contractual agreements with the cloud customers
The cloud provider’s business requirements

b. The backup approach, including the physical location of backup files, should comply with the privacy and data protection laws and regulations applicable to the data collected.
c. The data backup process should be monitored by employing technical and organizational safeguards. At a minimum, malfunctions should be examined and eliminated promptly by qualified employees to support compliance with the retention’s scope, frequency, and duration.
d. Backup and restoration procedures should be periodically tested and the results documented to ensure data can be successfully restored. Tests should be designed so that the reliability of the backup media and the restoration time (RPO, RTO) can be established with sufficient certainty. Any errors and identified improvements (corrective and preventive actions) should be addressed promptly.
e. Restorations should be carried out only after they have been approved by authorized persons (according to contractual agreements with cloud customers or the internal policies of the cloud provider).
f. The cloud service provider, when appropriate, should be able to disclose the exercise results to the cloud services customer as part of the assurance of business continuity and resilience.

Additional guidance is also available in the NIST Special Publication 800-53 (Rev. 4) CP-9 INFORMATION SYSTEM BACKUP (latest revision).
Control implemented
Control ownership
Description

Periodically backup data stored in the cloud. Ensure the confidentiality, integrity and availability of the backup, and verify data restoration from backup for resiliency.