Backup & Disaster Recovery
On-premise DR systems and Microsoft 365 backup configuration checks
Every organisation has backups. Far fewer have restores. The distance between those two words is where most disaster recovery plans actually fail, and it only becomes visible on the worst day of the year.
This library treats a backup as unproven until a restore has been performed and recorded.
What this library checks
- Backup coverage measured against the asset and application inventory
- Retention schedules against the actual business and regulatory requirement
- Offsite and immutable copy configuration, and whether ransomware can reach it
- Restore testing cadence, scope and the evidence from the last test
- Recovery time and recovery point objectives, stated by leadership rather than assumed by IT
- Microsoft 365 backup coverage for mail, OneDrive, SharePoint and Teams
- Backup job failure monitoring and who sees a failed job
- Documented recovery runbook and the last time anyone followed it
Evidence you will be asked for
Every check in Spectra Core carries its own evidence. These are the artefacts an auditor, insurer or board most often wants to see for this area.
- Restore test record with date, scope, duration and outcome
- Backup job success rate over the review period
- Written RTO and RPO signed off by the business, not by IT
Where this usually goes wrong
Downtime tolerance is a leadership decision, not a technical one. IT can build to any target, but only the business can say which one it is paying for, and that conversation almost never happens until after an outage.
Run this library against your environment
Every check comes with a risk level, a review frequency, an assignee and a plain-language rationale, so the output reads for leadership as well as for engineers.
Other libraries
Remote Monitoring & Management
Alerting, patching, agent health, and endpoint visibility standards
Network Environment
Switching, routing, Wi-Fi, DNS, and network segmentation checks
Active Directory Configuration
GPOs, OU structure, password policies, and domain hygiene
Network Security
Identity, access management, and endpoint protection / EDR standards
Microsoft 365 Security
Identity threat detection and response, conditional access, and tenant hardening
Server Rooms
Physical environment, cooling, fire suppression, and monitoring standards