Key takeaways
Coverage, isolation, immutability, RPO, RTO and testing: audit backups beyond the green status light.
A relevant audit starts with the services the business must continue to deliver, the information it cannot afford to lose and the commitments it must meet. Technical scope follows. This prevents teams from spending time on a peripheral device while overlooking a cloud account, supplier or restoration process on which operations genuinely depend.
The NIST Cybersecurity Framework 2.0 organises risk management around six functions — govern, identify, protect, detect, respond and recover — while the Centre for Cybersecurity Belgium's CyberFundamentals Framework translates these principles into practical, proportionate measures. Frameworks do not replace judgement; they reduce blind spots and create a common management and technical language. [1][2]
In this guide, a control is reliable only when it has an owner, consistent configuration, known coverage and recent evidence. A purchased licence, enabled checkbox or old document is not enough. Effectiveness is demonstrated through use, monitoring, testing and the ability to remediate exceptions.
The result must remain understandable over time. For each conclusion, record the observation date, covered systems and populations, method, sample and limitations. Separate observed facts from statements and auditor assumptions. This traceability lets another person understand the rating, repeat the verification after remediation and measure progress during the next review. It also prevents two common errors: assuming a control applies everywhere when only part of the scope was checked, or keeping an action open indefinitely without an objective closure criterion. Provide two reporting levels: a concise management view for decisions and technical detail for implementation. Both should use the same priorities and clearly identify risks that are accepted, transferred, reduced or avoided. The report then becomes a governed working instrument rather than a snapshot forgotten after presentation.
- ✓Backups and restoration
A successful job does not prove operations can resume. Link coverage to loss and time objectives, then observe a restoration test.
- ✓Continuity, recovery and crisis management
Continuity coordinates business priorities, human and technical dependencies and decisions under pressure. An untested plan may be unusable.
- ✓Data, GDPR and protection
Safeguards must match sensitivity, volume and the consequences of loss, alteration or disclosure. Location, retention and transfers must be understood.
- ✓Identity, MFA and privilege
Identity is a central security perimeter. Examine individual accounts, administrators, MFA, leavers, guests and emergency access.
- ✓Logging, detection and incident response
Without useful logs and clear roles, compromise can remain invisible. Collection should support concrete detection and response scenarios.
Backups
Backups and restoration
A successful job does not prove operations can resume. Link coverage to loss and time objectives, then observe a restoration test. [1]
This domain must be examined through real operations rather than a declared procedure alone. The auditor links people, technology and data flows to the business scenario in this guide. Exceptions matter too: a protection enabled broadly may still leave critical accounts, devices or data outside its coverage.
The method compares the expected, configured and actually observed states. Interviews explain intent; administration screens, exports, logs and tests demonstrate application. Where intrusive verification is not authorised, that limitation must be explicit in the report to avoid an overconfident conclusion.
Checks to perform
- Map covered and uncovered data
- Separate at least one copy from production identities
- Check encryption, immutability and administration
- Compare frequency and retention with business needs
- Observe restoration and measure time
Evidence to request
- Job reports and alerts
- Restoration test history
- Architecture and backup accounts
Each gap is then qualified by likelihood, impact and ease of exploitation. The recommendation should name the expected result, action owner, dependencies and evidence needed for closure. This discipline turns a technical list into a governance decision.
Expected decisions and actions
- 1Isolate a copy
- 2Close coverage gaps
- 3Schedule restorations
Backups
Continuity, recovery and crisis management
Continuity coordinates business priorities, human and technical dependencies and decisions under pressure. An untested plan may be unusable. [2]
This domain must be examined through real operations rather than a declared procedure alone. The auditor links people, technology and data flows to the business scenario in this guide. Exceptions matter too: a protection enabled broadly may still leave critical accounts, devices or data outside its coverage.
The method compares the expected, configured and actually observed states. Interviews explain intent; administration screens, exports, logs and tests demonstrate application. Where intrusive verification is not authorised, that limitation must be explicit in the report to avoid an overconfident conclusion.
Checks to perform
- Identify critical activities, RTO and RPO
- Document dependencies, contacts and workarounds
- Align IT recovery and business continuity
- Plan internal, customer and authority communication
- Run an exercise and track lessons
Evidence to request
- Business impact analysis
- Continuity and recovery plans
- Exercise reports
Each gap is then qualified by likelihood, impact and ease of exploitation. The recommendation should name the expected result, action owner, dependencies and evidence needed for closure. This discipline turns a technical list into a governance decision.
Expected decisions and actions
- 1Validate priorities
- 2Test procedures
- 3Remove single points of failure
Backups
Data, GDPR and protection
Safeguards must match sensitivity, volume and the consequences of loss, alteration or disclosure. Location, retention and transfers must be understood. [3]
This domain must be examined through real operations rather than a declared procedure alone. The auditor links people, technology and data flows to the business scenario in this guide. Exceptions matter too: a protection enabled broadly may still leave critical accounts, devices or data outside its coverage.
The method compares the expected, configured and actually observed states. Interviews explain intent; administration screens, exports, logs and tests demonstrate application. Where intrusive verification is not authorised, that limitation must be explicit in the report to avoid an overconfident conclusion.
Checks to perform
- Identify critical and personal data
- Review rights, sharing and locations
- Check encryption, retention and deletion
- Link IT incidents to breach procedures
- Examine transfers and processors
Evidence to request
- Processing register and classification
- Retention and access rules
- Processor contracts
Each gap is then qualified by likelihood, impact and ease of exploitation. The recommendation should name the expected result, action owner, dependencies and evidence needed for closure. This discipline turns a technical list into a governance decision.
Expected decisions and actions
- 1Reduce unnecessary data
- 2Restrict sensitive access
- 3Document security measures
Backups
Identity, MFA and privilege
Identity is a central security perimeter. Examine individual accounts, administrators, MFA, leavers, guests and emergency access. [4]
This domain must be examined through real operations rather than a declared procedure alone. The auditor links people, technology and data flows to the business scenario in this guide. Exceptions matter too: a protection enabled broadly may still leave critical accounts, devices or data outside its coverage.
The method compares the expected, configured and actually observed states. Interviews explain intent; administration screens, exports, logs and tests demonstrate application. Where intrusive verification is not authorised, that limitation must be explicit in the report to avoid an overconfident conclusion.
Checks to perform
- Measure actual MFA coverage including administrators
- Review privileged and dormant accounts
- Test joiner, mover and leaver processes
- Check methods and legacy authentication
- Review emergency accounts and monitoring
Evidence to request
- User, role and MFA exports
- Conditional Access policies
- Joiner and leaver tickets
Each gap is then qualified by likelihood, impact and ease of exploitation. The recommendation should name the expected result, action owner, dependencies and evidence needed for closure. This discipline turns a technical list into a governance decision.
Expected decisions and actions
- 1Protect privilege first
- 2Remove unnecessary access
- 3Schedule access reviews
Backups
Logging, detection and incident response
Without useful logs and clear roles, compromise can remain invisible. Collection should support concrete detection and response scenarios. [5]
This domain must be examined through real operations rather than a declared procedure alone. The auditor links people, technology and data flows to the business scenario in this guide. Exceptions matter too: a protection enabled broadly may still leave critical accounts, devices or data outside its coverage.
The method compares the expected, configured and actually observed states. Interviews explain intent; administration screens, exports, logs and tests demonstrate application. Where intrusive verification is not authorised, that limitation must be explicit in the report to avoid an overconfident conclusion.
Checks to perform
- Identify critical log sources
- Check alerts, recipients and coverage hours
- Test escalation with a realistic scenario
- Check retention, time and access
- Connect technical, legal and communication response
Evidence to request
- Log catalogue and alert rules
- Incident tickets and reports
- Response plan and contacts
Each gap is then qualified by likelihood, impact and ease of exploitation. The recommendation should name the expected result, action owner, dependencies and evidence needed for closure. This discipline turns a technical list into a governance decision.
Expected decisions and actions
- 1Cover critical signals
- 2Define escalation
- 3Run an exercise
Turn the audit into a roadmap
Turn the audit into a roadmap
A good audit does not end with a score. It organises the move from the observed state to a chosen level of control, with an owner, deadline and closure evidence for every action.
Frame the risk
Confirm critical activities, important data, dependencies, obligations and risk appetite with management. Without that context, every fix appears urgent and budgets become scattered.
Treat immediate exposure
Start with scenarios combining high likelihood and impact: weakly protected administrator accounts, backups reachable from production, exposed or unsupported systems and insufficient detection capability.
Stabilise the foundations
Assign responsibilities, complete the inventory, standardise configurations, document procedures and introduce recurring checks. Security should be repeatable rather than dependent on one person.
Prove and steer
Retain configuration reports, logs, test records and risk acceptance decisions. A small number of stable indicators is more useful than a crowded dashboard that triggers no decisions.
Reassess
Schedule a review after major changes and at least at a defined frequency. An audit is a snapshot; new users, cloud services, suppliers and equipment continuously change risk.
Preparation checklist
Preparation checklist
Collect these items before the interview. Missing evidence does not automatically mean the control is absent, but it increases verification time and weakens assurance.
- Map covered and uncovered data
- Separate at least one copy from production identities
- Job reports and alerts
- Identify critical activities, RTO and RPO
- Document dependencies, contacts and workarounds
- Business impact analysis
- Identify critical and personal data
- Review rights, sharing and locations
- Processing register and classification
- Measure actual MFA coverage including administrators
- Review privileged and dormant accounts
- User, role and MFA exports
Frequently asked questions
Frequently asked questions
How much time should this type of audit take?+
It depends on the number of sites, users, devices, cloud tenants and suppliers. A targeted review may take a few hours; a documented engagement covering governance, configurations and evidence usually requires several interviews and analysis time. Write down the scope before work begins.
Is a questionnaire enough to reach a conclusion?+
No. A questionnaire is excellent for directing discussion and revealing unknown areas. A professional conclusion still requires suitable evidence, observation or testing. Unverified answers must be clearly identified in the report.
Must every observation be fixed immediately?+
No. Actions should be prioritised by risk, business impact, effort and dependencies. Some measures reduce several risks at once; others can wait or be replaced by a documented compensating control.
Does an audit guarantee that no incident will occur?+
No audit can guarantee the absence of outages, errors or cyberattacks. It reduces uncertainty, highlights known exposure and improves prevention, detection, response and recovery. Its limitations should be explicit.
How often should the situation be reassessed?+
Set a risk-based frequency and add reviews after major changes: cloud migration, acquisition, new site, supplier change, incident, new obligation or business transformation. Critical actions deserve more frequent follow-up than the full audit.
Official sources and references
Official sources and references
The sources below support the principles and requirements discussed. GVISION recommendations are an operational interpretation for a business context and do not replace legal advice or official certification.
- 01CISA — #StopRansomware Guide2023https://www.cisa.gov/stopransomware/ransomware-guide ↗
- 02NIST — Ransomware Risk Management: A CSF 2.0 Community Profile2026https://csrc.nist.gov/pubs/ir/8374/r1/final ↗
- 03NIST — SP 800-34 Rev. 1 — Contingency Planning Guide2010https://csrc.nist.gov/pubs/sp/800/34/r1/upd1/final ↗
- 04CCB · Safeonweb@work — CyberFundamentals Framework2025https://atwork.safeonweb.be/tools-resources/cyberfundamentals-framework ↗
- 05Union européenne — RGPD — Article 32, sécurité du traitement2016https://eur-lex.europa.eu/eli/reg/2016/679/art_32/oj ↗
