Recovery drill planning and results worksheet Mimir IT Consultation Services A successful backup job is only the starting point. Choose a realistic recovery scenario, agree what success means, and keep the evidence of what actually happened. System / scenario: ____________________ Exercise owner and approver: ____________________ Exercise date: ____________________ Target RTO: maximum recovery time: ____________________ Target RPO: maximum acceptable data loss: ____________________ Plan and authorise [ ] Write a scenario and success criteria Name the business task that must work, the required restore point, the expected recovery time and the person who will accept the result. [ ] Agree the exercise boundaries Choose a tabletop or isolated functional restore appropriate to the objective. A disruptive production test requires a separate approved change. [ ] Prepare an isolated recovery destination Check capacity, network separation, credentials and dependencies. Keep test integrations from sending real messages or changing live data. Prepare the recovery path [ ] Confirm the recovery copy and restore point Record its timestamp and how it is protected from the original incident. Verify that the needed backup and recovery tooling are accessible. [ ] Make the runbook reachable Confirm authorised access to recovery instructions, keys and emergency credentials if the affected systems are unavailable. Record references, not secrets. [ ] Map dependencies and the recovery order Include identity, DNS, network, databases, applications and external services. Name who handles each dependency. Run and verify [ ] Record the full timeline Start at the decision to recover. Capture access delays, restore start, restore completion and business validation, with timezones. [ ] Validate business use and data integrity Have a business owner open records and complete representative tasks. Check permissions and integrations inside the exercise boundary. [ ] Compare evidence with the objectives Record measured elapsed time and the actual restore point. Mark objectives met, missed or not tested; a partial test does not prove full recovery. Close the loop [ ] Assign corrective actions For each gap, record the evidence, action, owner, due date and retest condition. Preserve failures as findings. [ ] Close the exercise environment safely Confirm with the owner which temporary resources, test data and temporary access can be removed. Keep the agreed evidence. [ ] Set the next review and retest Retest corrections and revisit the plan after material system changes. Choose the exercise cadence to match business impact. Timeline, actual restore point and measured recovery time: ____________________________________________________________ ____________________________________________________________ Business validation, evidence and limitations: ____________________________________________________________ ____________________________________________________________ Corrective actions, owners, due dates and retest: ____________________________________________________________ ____________________________________________________________ Outcome, approver and next exercise date: ____________________________________________________________ ____________________________________________________________ Full guide: https://mimirpsa.com/insights/backup-testing-restore-drill/ Source guidance: NIST SP 800-34 Rev. 1: contingency planning: https://csrc.nist.gov/pubs/sp/800/34/r1/upd1/final This worksheet is a planning aid. Recheck current product guidance before executing a change.