Skip to main content
This category contains 5 automated control definitions and 1 manual check across the sources named below. Similar controls from different standards are listed separately because names, thresholds or severity can differ. Whether the seeded Alignr Baseline is available depends on how your workspace was provisioned. Library templates are copied as disabled drafts. See Choose a baseline before enabling anything.

Automated controls

Expand a control to see the exact population, expectation and defaults. A pass requires usable evidence for the selected population. A known contrary observation can prove failure; missing observations or an empty population must not become a pass.
Each selected server should have a recorded backup product.Part of Alignr Baseline (seeded).Applies toDevices reported as managed by an RMM.The operating-system name must also match the case-sensitive pattern Server.What the result tells youRecorded product presence is not a successful backup or a tested restore. Missing evidence must be investigated rather than treated as passing.
Each selected job should report a healthy status.Part of Alignr Baseline (seeded).Applies toBackup jobs with a recorded status.What the result tells youThe expected state is the normalised value ok. Review the job/workload identity and timing; this is not a restore test.
Each selected workload should have a successful-backup timestamp within the configured day window.Part of Alignr Baseline (seeded).Applies toWorkloads with a recorded backup product.Default settingsClient overrides can change these values. Check the effective settings when interpreting a result.What the result tells youThis measures backup recency, despite any title mentioning a retention window. It does not inspect retention policy, recovery time or restored-data integrity.The time window includes timestamps before or after now. Investigate unexpected future timestamps.
Each selected job should report a healthy status.Part of BIOS Backup Health.Applies toBackup jobs with a recorded status.What the result tells youThe expected state is the normalised value ok. Review the job/workload identity and timing; this is not a restore test.
Each selected workload should have a successful-backup timestamp within the configured day window.Part of BIOS Backup Health.Applies toWorkloads with a recorded backup product.Default settingsClient overrides can change these values. Check the effective settings when interpreting a result.What the result tells youThis measures backup recency, despite any title mentioning a retention window. It does not inspect retention policy, recovery time or restored-data integrity.The time window includes timestamps before or after now. Investigate unexpected future timestamps.

Manual checks

These are human reviews, not automated evidence. The interval below is the template default; review ownership, evidence and suitability for the client.
Review every 30 days · BIOS Backup HealthRestore a representative workload, record recovery time and integrity evidence, and reconcile the result with the agreed RTO/RPO.Record: who performed the review, when it was performed, the evidence, the conclusion and any follow-up or approved exception. A due review is not evidence of a completed review.

Investigate a result

Confirm the client and the account, device or other item being assessed. Check the source, observation time and effective settings, then compare the recorded evidence with the expectation. Missing evidence needs investigation; a change to the environment requires a separate review.

Next steps

Create a custom control · Parameters and client overrides · Record a manual check