+OPS-09 Data Backup and Recovery - Storage
---+OPS-09.01B
---+OPS-09.02B
---+OPS-09.03B
---+OPS-09.04B
---+OPS-09.05B
|
1. Übersicht
OPS-09 Data Backup and Recovery - Storage
-
| Bezeichnung |
Standard |
|
OPS-09.01B
|
The cloud service provider transfers cloud service provider data and, if contractually agreed upon, cloud service customer data and cloud service derived data to be backed up to a remote location or transports these on backup media to a remote location.
If the data backup has not been contractually agreed between the cloud service provider and the cloud service customer, this criterion is not applicable. The cloud service provider transparently presents this situation in the system description.
A remote location can be e.g. another data centre of the cloud service provider.
|
|
OPS-09.02B
|
The protection needs resulting from the data classification of the original data (e.g., encryption, access control) are also applied to backups.
If the data backup has not been contractually agreed between the cloud service provider and the cloud service customer, this criterion is not applicable. The cloud service provider transparently presents this situation in the system description.
|
|
OPS-09.03B
|
If the data backup is transmitted to the remote location via a network, the data backup or the transmission of the data takes place in an encrypted form that corresponds to the state of the art (cf. CRY-04).
If the data backup has not been contractually agreed between the cloud service provider and the cloud service customer, this criterion is not applicable. The cloud service provider transparently presents this situation in the system description.
A remote location can be e.g. another data centre of the cloud service provider.
|
|
OPS-09.04B
|
The distance to the main site is chosen after sufficient consideration of the factors recovery times and impact of disasters on both sites.
If the data backup has not been contractually agreed between the cloud service provider and the cloud service customer, this criterion is not applicable. The cloud service provider transparently presents this situation in the system description.
A remote location can be e.g. another data centre of the cloud service provider.
|
|
OPS-09.05B
|
The physical and environmental security measures at the remote site are equivalent to those at the main site.
If the data backup has not been contractually agreed between the cloud service provider and the cloud service customer, this criterion is not applicable. The cloud service provider transparently presents this situation in the system description.
A remote location can be e.g. another data centre of the cloud service provider.
|
1.1 Referenzen
1.2 Identifizierte Anforderungen
1.2 Related Regulation
2. Identifizierte Anforderungen
Anforderungen
| Source |
Anforderung |
3. Related Regulations
Regulations
| Source |
Regulierung |
|