Offline media backup and location review
The shortest fixed clock in the held texts is 8,760 hours (yearly), set by PCI DSS 9.4.1.1. Paste one job that feeds this consumer, for example offsite_tape_rotation, weekly, and the register reads its period against the clocks below, names the gap in hours, and carries the question for its owner.
Matched on the job name or the consumer column by these words: offsite, offline media, tape, media inventory, vault rotation, media review, tape rotation.
The clock each rule sets
| Regime | Clock | Clause |
|---|---|---|
| PCI DSS | 8,760h | PCI DSS 9.4.1.1 Offline media backup securitysecurity reviewed at least once every 12 months |
| ISO 27001 | no clock | ISO 27001 8.13 Information backup |
Questions this page answers
How often does PCI DSS v4.0 require offline media backup and location review?
Yearly (8,760 hours): PCI DSS 9.4.1.1, Offline media backup security. Offline media backups containing cardholder data are stored in a secure location, with security reviewed at least once every 12 months.
How often does ISO/IEC 27001:2022 require offline media backup and location review?
The held text of ISO 27001 8.13 (Information backup) sets no fixed period: no period set by the text. Maintain and regularly test backups of information, software and systems per the backup policy.
What does the register ask the owner of a offline media backup and location review job?
Who reviews the location where the media rests, and when was that review last recorded?
The clauses in full
Offline media backups containing cardholder data are stored in a secure location, with security reviewed at least once every 12 months.
What an assessor asks to see: Offsite vendor agreement and SOC report; Annual site security review evidence; Inventory of backup media offsite; Chain of custody records for media transfers. Where it usually falls short: Annual review skipped
Maintain and regularly test backups of information, software and systems per the backup policy.
Guidance beside it, ISO 27002 8.13: Requires backup copies of information, software and systems to be maintained and regularly tested, in line with the agreed topic specific policy on backup. Supporting SME guidance treats regular creation of backups together with tested recovery as the substance of the control, not the copy on its own.
What an assessor asks to see: backup_policy; backup_schedule; backup_test_reports; retention_records. Where it usually falls short: infrequent restore testing
Requirement text quoted from the standards themselves, published at compliance.theartofservice.com, the same publisher as this register, read against the held text of each standard: our statement of each clause, not the instrument verbatim. Run this job through the register