Backups of information, software and systems are to be kept and tested regularly as the agreed topic-specific backup policy requires. Purpose: be able to get data and systems back after they are lost. Guidance: set a backup policy reflecting retention and security requirements, provide backup facilities sufficient to recover all essential information and software after an incident, failure or media loss, and develop and implement plans for backing up information, software and systems. A backup plan should consider: accurate, complete records of backup copies and documented restore procedures; the extent (full or differential) and frequency of backups, set by business requirements such as the recovery point objective (5.30), the security needs of the information and how critical it is to continued operation; storage in a safe remote location far enough away to escape a disaster at the main site; physical and environmental protection of backups consistent with the main site (Clause 7, 8.1); regular testing of backup media so they can be relied on, restoring to a test system rather than over the originals in case the backup or restore fails and destroys data; encrypting backups according to risk, for example where confidentiality matters; and making sure accidental data loss is noticed before the backup runs. Operational procedures monitor backup runs and deal with failed scheduled backups so backups are complete. Backup arrangements for individual systems and services are tested regularly against incident response and continuity objectives, together with the restore procedures and the recovery time the continuity plan requires; for critical systems, backups cover all system information, applications and data needed to rebuild the whole system after a disaster. For cloud services, back up the organization's own data, applications and systems held in the cloud environment and decide whether and how the provider's backup service meets requirements. Set retention periods for essential information including archive copies, and consider deleting information from backup media when retention expires (8.10), within the law. Other information: ISO/IEC 27040 covers storage security and retention.
This control maps to 115 controls across 33 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
E8-BACKUP-ISM-1511 Regular backups (ISM-1511): Backups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements
E8-BACKUP-ISM-1515 Regular backups (ISM-1515): Restoration of data, applications and settings from backups to a common point in time is tested as part of disaster recovery exercises
E8-BACKUP-ISM-1705 Regular backups (ISM-1705): Privileged user accounts (excluding backup administrator accounts) cannot access backups belonging to other user accounts
E8-BACKUP-ISM-1706 Regular backups (ISM-1706): Privileged user accounts (excluding backup administrator accounts) cannot access their own backups
E8-BACKUP-ISM-1707 Regular backups (ISM-1707): Privileged user accounts (excluding backup administrator accounts) are prevented from modifying and deleting backups
E8-BACKUP-ISM-1708 Regular backups (ISM-1708): Backup administrator accounts are prevented from modifying and deleting backups during their retention period
E8-BACKUP-ISM-1810 Regular backups (ISM-1810): Backups of data, applications and settings are synchronised to enable restoration to a common point in time
E8-BACKUP-ISM-1811 Regular backups (ISM-1811): Backups of data, applications and settings are retained in a secure and resilient manner
E8-BACKUP-ISM-1812 Regular backups (ISM-1812): Unprivileged user accounts cannot access backups belonging to other user accounts
E8-BACKUP-ISM-1813 Regular backups (ISM-1813): Unprivileged user accounts cannot access their own backups
E8-BACKUP-ISM-1814 Regular backups (ISM-1814): Unprivileged user accounts are prevented from modifying and deleting backups
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 8.13 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.