// CPCSC TEMPLATES · 12 OF 14

Backup policy paragraph and restore test log

Last verified: 2026-10-05

Recovery is what makes incident response real. The log is the evidence most shops can't produce.

Free to use, edit, and share, including by an MSP for a client, under CC BY 4.0. Keep the credit "Hans Study, hans.study" and the licence with it. None of it is legal advice or a substitute for the contract clauses in front of you.

TPL-12 Static template

Policy paragraph

[Company] keeps 3 copies of enclave data on 2 media types with 1 copy off site, backed up [daily], retained for [90 days], and encrypted at rest. Restores are tested [quarterly] at file level and [annually] as a full system restore, timed, and logged. Backup credentials are separate from daily and admin accounts.

Restore test log

Date        System        Restore point   Method               Result   Time to restore   Tested by
[date]      [system]      [date]          [file / full VM]     [pass]   [minutes]         [name]
Next test: [date]

References

  1. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)April 2025, updated October 2025
    Canadian Centre for Cyber Securitycyber.gc.ca
  2. NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsRevision 3
    NISTcsrc.nist.gov

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.