Section 58 of 101
57. Backup and Restore
Stable section ID: S05-CON-006-SECTION-58 · 53 content blocks
Backup and Restore shall protect the building’s identity, configuration, trust records, and essential lifecycle information against hardware failure, corruption, cyberattack, accidental deletion, disaster, or migration failure.
The backup scope shall include:
Building Manifest;
all registries;
topology and dependency records;
Configuration Baselines;
configuration versions;
Engineering Profiles;
policies and rules;
authorization configuration;
Digital Passport references;
commissioning and certification records;
critical event and audit logs;
recovery credentials;
BIOS software and schema references.
The backup architecture shall provide:
local recovery copy;
physically or logically separated copy;
integrity verification;
encryption where required;
version history;
retention policy;
restore testing;
authorized export;
vendor-independent format for essential data.
Backup frequency shall reflect data criticality and change rate. Configuration changes shall trigger a backup or protected transaction checkpoint before the new baseline becomes active.
A backup shall not be considered valid solely because a file was created. It shall be checked for:
completeness;
integrity;
readability;
schema compatibility;
credential availability;
restore feasibility.
Restore shall follow:
verify recovery authority;
verify BIOS platform integrity;
select an appropriate backup;
verify backup identity and signature;
evaluate physical-building changes since the backup;
restore into an isolated validation environment;
validate registries and topology;
reconcile with the observed building;
activate the restored configuration;
recommission affected systems;
record the recovery event.
The BIOS shall not restore an old configuration blindly when Cartridges, Interfaces, physical connections, or safety systems have changed since the backup.
Recovery objectives shall define:
maximum acceptable data loss;
maximum acceptable BIOS unavailability;
essential services to restore first;
permitted degraded operating condition;
responsibility for restoration.
Backup and restore procedures shall be tested periodically. A recovery plan that has never been verified shall not be treated as proven recovery capability.