{"description":"Runs on the existing system item. Test recoverability for a system by performing an actual restoration and measuring the result against recovery objectives. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","edges":[{"id":"e-backup-scope-backup-closure","source":"backup-scope","target":"backup-closure"}],"isPublic":true,"itemTypeSlug":"system","metadata":{"capabilities":["backup-recovery-testing"],"controlVerbs":{"UC-BCDR-03":"operates"},"controls":["UC-BCDR-03"],"department":"it","domains":["controls"],"kind":"backup-recovery-testing","library":{"aliases":[{"source":"studio-seed","sourceTemplateId":"coworkcanvas:template:backup-recovery-testing"}],"canonicalUrl":"https://workflow-library.com/all/?w=controls-system-backup-restoration-test","contentDigest":"sha256:daf5fa339d6abca65f52e24586c6311d2d88cfb5fed227d441397871bd4e2bec","prerequisites":{"anchorItemType":{"slug":"system"},"evidenceDestinations":[{"description":"Restricted native step results, attached documents, durable item fields and native approvals.","id":"review-evidence"}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:controls-bcdr-test-exercise"}],"roles":[{"contribution":"approval","description":"Business recovery owner. Confirm backup scope and recovery objectives.","id":"reviewer-1","nodeIds":["backup-scope"]},{"contribution":"approval","description":"Independent recovery reviewer. Approve recovery test record.","id":"reviewer-2","nodeIds":["backup-closure"]}],"status":"declared"},"provenance":[{"source":"brain/scripts/studio-seed","sourceTemplateId":"coworkcanvas:template:backup-recovery-testing"}],"releaseId":"sha256:daf5fa339d6abca65f52e24586c6311d2d88cfb5fed227d441397871bd4e2bec","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-system-backup-restoration-test"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"controls-system-backup-restoration-test","source":"coworkcanvas-gallery","standards":[],"teams":["it"]},"name":"Backup & Recovery Testing","nodes":[{"data":{"instructions":"**Objective**\nConfirm backup scope and recovery objectives. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, the backup configuration and retention schedule, business impact analysis with RPO and RTO, the continuity plan, prior restoration test results, and dependency maps.\n\n**Procedure**\n1. Confirm the objectives come from business impact analysis rather than from what the backup tooling currently achieves, identify data in scope that is not backed up, and select a restoration scenario that exercises a realistic failure.\n\n**Record in AssureSwarm**\n1. Capture the test period, RPO and RTO with their business basis, data and configuration in scope, items not covered by backup, the restoration scenario selected, and dependencies required for recovery. Also record recovery objectives (RPO/RTO) and data in scope.\n\n**Exit criteria**\nBusiness recovery owner provides approval: Objectives are traced to business impact rather than to tooling capability, unbacked-up data is named, and the test scenario exercises a realistic failure rather than a convenient one.","kind":"task","label":"Confirm backup scope and recovery objectives","requiredApprovals":1},"id":"backup-scope"},{"data":{"controls":["UC-BCDR-03"],"instructions":"**Objective**\nApprove recovery test record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the selected backup set and its age, restoration tooling and runbooks, an isolated restore target, data completeness checks against the source, application startup and integrity checks, and elapsed timing.\n2. Use the restoration evidence and timings, the backup set age against RPO, the stated RTO, dependency recovery sequencing, and resource constraints observed during the test.\n3. Review all stage records, objectives and their business basis, unbacked-up data, restoration evidence and timings, computed achieved values, scale assumptions, and open gaps.\n\n**Procedure**\n1. RESTORE rather than inspect backup job status, verify restored data completeness against known source values, start the application against the restored data where feasible, and record elapsed time from initiation to usable state.\n2. Compute achieved RPO from the restored backup age and achieved RTO from measured elapsed time, test whether the result would hold at production scale, and record an untested dependency as a gap rather than an assumption.\n3. Trace achieved values to measured evidence, verify unbacked-up data and untested dependencies carry owners, confirm the scenario was realistic, and return job-status-only evidence with precise comments.\n\n**Record in AssureSwarm**\n1. Document the backup set restored and its age, restoration steps and elapsed timings, completeness and integrity checks with results, application startup verification, failures encountered, and manual intervention required. Also record restoration evidence; restoration outcome.\n2. Record objectives met or missed with computed achieved values, scale assumptions and their basis, untested dependencies, gaps with remediation owners and dates, and constraints that would worsen a real recovery. Also record gap detail and remediation.\n3. Capture the authorized reviewer, the summary, accepted conclusion, test date, achieved RPO and RTO, gaps with owners and dates, scope not covered by backup, and linked issues raised. Also record recovery test summary.\n\n**Exit criteria**\nIndependent recovery reviewer provides approval: Recoverability is evidenced by an actual restoration verified for completeness and usability, elapsed time is measured, and manual interventions are recorded rather than normalized. An approver accepts that achieved values are computed from the test rather than asserted, scale limitations are stated, and gaps carry remediation owners. The authorized reviewer accepts the record as evidence the recovery control was tested, and closure implies no assurance for data, systems, or scale not exercised by this test.","kind":"task","label":"Approve recovery test record","requiredApprovals":1},"id":"backup-closure"}],"sourceTemplateId":"workflow-library:controls-system-backup-restoration-test"}
