ASUME

Trust Center

BC/DR

Backup and availability practices documented today, and the formal continuity and disaster-recovery artefacts that remain planned.

Availability

ASUME maintains technical and organisational measures designed to support the availability and resilience of material production systems, as described in Security Measures.

These measures are not a published uptime SLA or an independently verified availability attestation.

Data backup and backup protection

Material production data stores are backed up or protected using database, storage, replication, snapshot, or provider-supported recovery mechanisms. Access to backups is restricted through controls provided by ASUME or the applicable infrastructure provider. Current practices are described in Security Measures.

Backup frequency and retention vary by system, data category, and recovery need. A published risk-based backup calendar with named recovery-time and recovery-point objectives is still being formalized.

Business Continuity Planning Standard

A standalone Business Continuity Planning Standard — covering contingency procedures for disruptions ranging from security incidents to operational outages — is a roadmap item.

Until it is published, current availability, backup, and recovery handling lives in Security Measures. Listing the standard here is not a representation that a comprehensive continuity framework has been independently verified.

Disaster Recovery Plan

A standalone Disaster Recovery Plan (DRP) for restoring critical systems after a major disruptive event is a roadmap item.

Until it is published, recovery of material systems follows the backup and recovery practices in Security Measures. Regular recovery tests of every critical information asset are not independently verified.

Recovery testing

A published programme of restoration drills against named recovery objectives is a roadmap item. Security Measures describe periodic review or testing of backup and recovery mechanisms for material systems where appropriate.

Annual full-restoration drills for every critical information asset are not independently verified.