← Inspection rules
SEC-013 / v1.0.0 / 2026-10-02
Inspect containment and backup restoration
Editorial inspection guidance. Start with read-only permissions; fixes, credential revocation, and production changes follow the owner’s authorization.
Applicability
Applies to shared systems, cloud, and data stores for containment and recovery inspection.
Where to look first
- System dependencies, isolation procedures and owners, backup locations, and deletion privileges.
Inspection steps
- Use privilege metadata to check whether compromised production authority can alter or delete backups.
- Inspect restoration-test dates, revisions, and outcomes against recovery-time and data-loss requirements.
- Compare shared-system containment procedures, operational impact, and decision ownership with records.
Remediation direction
- Separate backup privileges and administration from production and define protection and retention policies.
- Conduct authorized restoration and containment tests and update procedures from outcomes.
Evidence required for completion
- Backup privilege and protection settings, plus restoration-test records with scoped revisions.
- Records verifying containment decision ownership, procedures, and operational dependencies.
Limits and unverified scope
- Backup existence does not prove successful restoration; missing restoration evidence remains unverified.
- This inspection rule does not authorize production isolation or destructive recovery.