01 / PLANNING NOTE
Describe the business impact
Name the applications and information the team needs first. Discuss acceptable interruption and data loss with the business owner. These are planning objectives to validate, not assumptions to hide in a technical document.
02 / PLANNING NOTE
Estimate the data to protect
Use the plan's backup-volume range as a first estimate of source data. Retention, additional copies, growth, and workload requirements affect the actual design and storage needs. Do not treat a rough volume band as final scope.
03 / PLANNING NOTE
Review test evidence
CISA's ransomware guidance recommends regular backup testing and protection of backup copies. Ask when an appropriate restore was last tested, what was included, how long it took, and what failed or remained untested.
04 / PLANNING NOTE
Connect the dependencies
A recovered file does not necessarily restore an application or business process. Include identity, connectivity, licensing, suppliers, and the people who authorize recovery decisions.
05 / PLANNING NOTE
Agree the next test
Choose a defined scenario, safe test boundary, success criteria, and responsible owner. Record the result and follow-up work so leadership can understand what the evidence does and does not establish.
