A practical checklist for backups
The version of this that works is simpler than the version most people imagine. Run through this the next time backups comes up.
The cheapest security work is the boring kind done on a schedule. Write the reasoning down alongside the decision, because the reasoning is what changes first.
The checklist
- An untested backup is a hope, not a backup
- Keep a copy somewhere the main system cannot reach
- Know how long a restore actually takes
- Someone is named as the owner
- There is a date to review it again
What is actually at stake
An untested backup is a hope, not a backup. The teams that handle this well are rarely the ones with the biggest budgets. The practical test is whether someone new to the project could tell, in a minute, that it had been handled.
How to tell if yours is fine
Security is a maintenance habit rather than a purchase, which is why it drifts. Three things worth confirming about backups before you move on:
- Someone can say what the current setup is without going to look
- Keep a copy somewhere the main system cannot reach — and you know whether that is true here
- There is a way to tell whether the last change to this helped
If any of that sounds like a description of your current setup, it is fixable.