---
name: backup-recovery-verification
description: Checks backup coverage, retention, failures, and recovery-test evidence against system criticality and recovery objectives, then produces a verification report and remediation list. Use for backup audits, disaster-recovery readiness, RTO/RPO reviews, resilience checks, and recurring IT control evidence.
license: Apache-2.0
metadata:
  adlass.categories: "it-security/audit-evidence, it-security/runbooks"
  adlass.industries: ""
  adlass.tags: "backup, recovery, resilience, rto, rpo, verification"
  adlass.adaptation: "reference-doc"
  adlass.source: "original"
  adlass.version: "1"
---

# Backup and recovery verification

## Purpose

Determine whether critical systems have documented backup coverage and credible recovery evidence aligned with their recovery objectives. Make failed jobs, retention gaps, and untested restores actionable.

## Scope

System inventory, backup logs, retention settings, restore tests, RTO/RPO requirements, and prior remediation. **Excluded:** running backups, restoring systems, changing configurations, or declaring business continuity.

## Data basis

- System inventory with criticality and owner.
- Backup job history, retention records, and storage coverage.
- Recovery-test records, RTO/RPO targets, and prior findings.

## Result

A coverage sheet, verification report, and remediation document with system-level evidence and explicit limitations.

## Quality criteria

- Every in-scope system has coverage and last-success status.
- Retention and recovery evidence are compared with documented targets.
- RTO and RPO calculations show timestamps and units.
- Every gap has a priority and source citation.

## Instructions

Separate backup-job success from recoverability. Treat a planned restore as unperformed. Use the system criticality and recovery policy; when absent, do not invent targets. Explain sampling and period limits. Never claim a system is protected based only on the existence of a backup product.

The review should make the population, calculation basis, and exception treatment understandable to a second operator. Preserve source identifiers in every working table, and state the effect of missing evidence on the decision. A reviewer must be able to reproduce each material result from the cited rows, clauses, dates, or policy rules. Where two sources disagree, show both values and explain which source was treated as authoritative.

Use the outputs as review workpapers: retain the source locator beside every material value, and keep planned action separate from completed evidence. The final document must identify the consequence of each gap for the relevant operational or control decision.

## Adapt before use

- Add system criticality, RTO/RPO, backup, and retention policies.
- Define acceptable log period, restore-test evidence, and severity labels.
- Map system, job, storage, and owner identifiers.
