Discussion
Open questionLast verified: 2026-08-13
- AuthorPosts
- 7th September 2026 at 8:37 am #3461
A statement that data is backed up does not prove that the service can recover within the buyer’s required timeframe. What should be tested?
8th September 2026 at 2:28 am #3462Accepted answerDefine recovery time, acceptable data loss, systems and data covered, backup frequency, geographic and account separation, encryption, retention, deletion, and restoration responsibilities. Ask for recent restore-test evidence and how partial or corrupt data is handled. Align the contract and continuity plan with service criticality. The NIST Cybersecurity Framework includes recovery outcomes as part of cybersecurity risk management.
- AuthorPosts
- You must be logged in to reply to this topic.