Capability areas
Data center workload coverage (12)
Covers file-level backup of server operating systems, agentless VM backup through hypervisor APIs, image-level backup for bare-metal rebuild, application-consistent database backup with transaction logs, NAS shares over SMB/NFS, Kubernetes workloads, published version support and how quickly new versions are supported, agent footprint, and scale limits on sources and capacity. SaaS, public cloud and endpoint sources are covered in CLD.
SaaS, cloud-native and endpoint coverage (10)
Covers API-based backup of SaaS applications (mail, files, sites, chats) and how it works within each application's API limits, backup of cloud VMs, managed databases and object storage, laptops and desktops backed up over the internet without VPN, attached external drives, and automatic discovery and protection of new SaaS users and endpoints. Restore of these sources is covered in RES.
Backup policy, scheduling and backup performance (13)
Covers schedules and backup windows, include/exclude rules, incremental chain method, continuous protection for selected systems, retention tiers, deleted-file retention, version counts, policy assignment by group or tag, bandwidth and CPU/disk throttling, pre/post scripts, legal hold, resuming interrupted jobs, and meeting [initial backup window] and [daily backup window] at [daily change rate]. Retention enforcement against deletion is covered in IMM.
Storage targets, copies and efficiency (9)
Covers local plus offsite copies, replication to a second region or location, deduplication and compression, writing to storage in our own cloud account, drive-based seeding, tiering to lower-cost storage with stated restore times and retrieval costs, storage-used reporting, region placement of primary and secondary copies, and documented durability design. Licensing and price terms belong to the commercial module.
Immutability, isolation and backup tamper protection (11)
Covers the mechanism that enforces immutability and who can lift it, logically isolated copies with credentials and a control plane separate from production, second-administrator approval for destructive actions, recoverable holding of deleted backups, protection and rebuild of the backup catalog, MFA on every console sign-in, and administrator accounts separate from the production directory. Detection of ransomware inside backup data is covered in THR.
Threat detection and clean recovery point identification (10)
Covers anomaly detection on backup data (change rates, mass deletion, encryption), malware scanning of restore points, identification of the most recent clean restore point, alerts on agent removal, disabled policies or silent sources, and forensic restore into an isolated clean-room environment. General SIEM event delivery is covered in MON. Also covers discovery of sensitive data inside backups and the clean-room environment used to investigate and scan before data returns to production. Validation of restored systems before cutover in a planned recovery is covered in DRO.
Restore and granular recovery (12)
Covers file and folder restore with overwrite options, browse-by-date and cross-backup search, whole-machine restore to the same hardware, different hardware or a VM, running a VM directly from backup storage, database point-in-time restore, single-item SaaS restore, end-user self-service restore, preservation of permissions and metadata, restore throughput from cloud storage, and drive-shipped restores. Multi-system orchestrated recovery is covered in DRO.
Disaster recovery orchestration and recovery at scale (10)
Covers saved recovery plans that restore many machines in a set order and priority, recovery of servers as VMs in [cloud provider], restore into an isolated network before production cutover, failback, the break-glass restore process when the console or production identity provider is unavailable, and meeting [RTO] for [largest critical system]. Scheduled restore testing is covered in TST. Also covers journal-based continuous replication of tier-1 VMs to a secondary site or cloud, network and IP re-mapping at failover, and non-disruptive DR rehearsal of a plan without touching production.
Restore testing and verification (9)
Covers scheduled restore tests that restore, boot, run our check scripts and report pass or fail, measured restore time against [RTO], isolation of tests from production, checksum integrity verification on a schedule and at restore, auditor-ready test reports, and retention of test results for [test result retention period].
Encryption, key custody and restore access control (10)
Covers encryption of backup data in transit and at rest, customer-held keys in [key management service] or as a private key, the documented procedure if we lose a key we hold, role separation for backup, restore, delete and policy change, restricting users to restoring data they may access, administrator sign-in through our identity provider, logged and approved vendor staff access to backup data, and permanent deletion at end of retention that respects legal hold and immutability. The vendor's own corporate security program belongs to the security module.
Protection monitoring, reporting and SOC integration (9)
Covers the view of every protected and unprotected source with last successful backup, alerts on failed, missed and partial backups and their delay, reports of sources outside [RPO], scheduled CSV/PDF reports, the administrator audit log with its retention and tamper protection, event delivery to [SIEM] and response actions triggered from [SOAR platform], and ticket creation in [ticketing system].
Administration, automation and agent lifecycle (8)
Covers single-console management across all sources and locations, API coverage for policies, jobs, restores and reports, infrastructure-as-code support, silent agent deployment through [software distribution tools], staged automatic agent updates, and delegated administration limited to each business unit's sources. Generic API availability and SSO/SCIM belong to the integration module.