Batch Register

Offline media backup and location review

The shortest fixed clock in the held texts is 8,760 hours (yearly), set by PCI DSS 9.4.1.1. Paste one job that feeds this consumer, for example offsite_tape_rotation, weekly, and the register reads its period against the clocks below, names the gap in hours, and carries the question for its owner.

Matched on the job name or the consumer column by these words: offsite, offline media, tape, media inventory, vault rotation, media review, tape rotation.

The clock each rule sets

RegimeClockClause
PCI DSS8,760hPCI DSS 9.4.1.1 Offline media backup securitysecurity reviewed at least once every 12 months
ISO 27001no clockISO 27001 8.13 Information backup

Questions this page answers

How often does PCI DSS v4.0 require offline media backup and location review?

Yearly (8,760 hours): PCI DSS 9.4.1.1, Offline media backup security. Offline media backups containing cardholder data are stored in a secure location, with security reviewed at least once every 12 months.

How often does ISO/IEC 27001:2022 require offline media backup and location review?

The held text of ISO 27001 8.13 (Information backup) sets no fixed period: no period set by the text. Maintain and regularly test backups of information, software and systems per the backup policy.

What does the register ask the owner of a offline media backup and location review job?

Who reviews the location where the media rests, and when was that review last recorded?

The clauses in full

PCI DSS 9.4.1.1 Offline media backup securitythe standard's page

Offline media backups containing cardholder data are stored in a secure location, with security reviewed at least once every 12 months.

What an assessor asks to see: Offsite vendor agreement and SOC report; Annual site security review evidence; Inventory of backup media offsite; Chain of custody records for media transfers. Where it usually falls short: Annual review skipped

ISO 27001 8.13 Information backupthe standard's page

Maintain and regularly test backups of information, software and systems per the backup policy.

Guidance beside it, ISO 27002 8.13: Requires backup copies of information, software and systems to be maintained and regularly tested, in line with the agreed topic specific policy on backup. Supporting SME guidance treats regular creation of backups together with tested recovery as the substance of the control, not the copy on its own.

What an assessor asks to see: backup_policy; backup_schedule; backup_test_reports; retention_records. Where it usually falls short: infrequent restore testing

Requirement text quoted from the standards themselves, published at compliance.theartofservice.com, the same publisher as this register, read against the held text of each standard: our statement of each clause, not the instrument verbatim. Run this job through the register