ISO 27002:2022
Technological controls – ISO 27002:2022

ISO 27002:2022 8.13: Information backup

Backups of information, software and systems are to be kept and tested regularly as the agreed topic-specific backup policy requires. Purpose: be able to get data and systems back after they are lost. Guidance: set a backup policy reflecting retention and security requirements, provide backup facilities sufficient to recover all essential information and software after an incident, failure or media loss, and develop and implement plans for backing up information, software and systems. A backup plan should consider: accurate, complete records of backup copies and documented restore procedures; the extent (full or differential) and frequency of backups, set by business requirements such as the recovery point objective (5.30), the security needs of the information and how critical it is to continued operation; storage in a safe remote location far enough away to escape a disaster at the main site; physical and environmental protection of backups consistent with the main site (Clause 7, 8.1); regular testing of backup media so they can be relied on, restoring to a test system rather than over the originals in case the backup or restore fails and destroys data; encrypting backups according to risk, for example where confidentiality matters; and making sure accidental data loss is noticed before the backup runs. Operational procedures monitor backup runs and deal with failed scheduled backups so backups are complete. Backup arrangements for individual systems and services are tested regularly against incident response and continuity objectives, together with the restore procedures and the recovery time the continuity plan requires; for critical systems, backups cover all system information, applications and data needed to rebuild the whole system after a disaster. For cloud services, back up the organization's own data, applications and systems held in the cloud environment and decide whether and how the provider's backup service meets requirements. Set retention periods for essential information including archive copies, and consider deleting information from backup media when retention expires (8.10), within the law. Other information: ISO/IEC 27040 covers storage security and retention.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 115 controls across 33 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ACSC Essential Eight · 14 controls

  • E8-BACKUP-ML1 Regular Backups (ML1)
  • E8-BACKUP-ML2 Regular Backups (ML2)
  • E8-BACKUP-ML3 Regular Backups (ML3)
  • E8-BACKUP-ISM-1511 Regular backups (ISM-1511): Backups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements
  • E8-BACKUP-ISM-1515 Regular backups (ISM-1515): Restoration of data, applications and settings from backups to a common point in time is tested as part of disaster recovery exercises
  • E8-BACKUP-ISM-1705 Regular backups (ISM-1705): Privileged user accounts (excluding backup administrator accounts) cannot access backups belonging to other user accounts
  • E8-BACKUP-ISM-1706 Regular backups (ISM-1706): Privileged user accounts (excluding backup administrator accounts) cannot access their own backups
  • E8-BACKUP-ISM-1707 Regular backups (ISM-1707): Privileged user accounts (excluding backup administrator accounts) are prevented from modifying and deleting backups
  • E8-BACKUP-ISM-1708 Regular backups (ISM-1708): Backup administrator accounts are prevented from modifying and deleting backups during their retention period
  • E8-BACKUP-ISM-1810 Regular backups (ISM-1810): Backups of data, applications and settings are synchronised to enable restoration to a common point in time
  • E8-BACKUP-ISM-1811 Regular backups (ISM-1811): Backups of data, applications and settings are retained in a secure and resilient manner
  • E8-BACKUP-ISM-1812 Regular backups (ISM-1812): Unprivileged user accounts cannot access backups belonging to other user accounts
  • E8-BACKUP-ISM-1813 Regular backups (ISM-1813): Unprivileged user accounts cannot access their own backups
  • E8-BACKUP-ISM-1814 Regular backups (ISM-1814): Unprivileged user accounts are prevented from modifying and deleting backups

FedRAMP High · 9 controls

  • CP-10 System Recovery and Reconstitution
  • CP-6 Alternate Storage Site
  • CP-6(1) Alternate Storage Site | Separation from Primary Site (CP-6(1))
  • CP-6(3) Alternate Storage Site | Accessibility (CP-6(3))
  • CP-9 System Backup
  • CP-9(1) Testing for Reliability and Integrity
  • CP-9(8) System Backup | Cryptographic Protection (CP-9(8))
  • IR-3 Incident Response Testing
  • SI-7(1) Integrity Checks

FedRAMP Moderate · 9 controls

  • CP-10 System Recovery and Reconstitution
  • CP-6 Alternate Storage Site
  • CP-6(1) Alternate Storage Site | Separation from Primary Site (CP-6(1))
  • CP-6(3) Alternate Storage Site | Accessibility (CP-6(3))
  • CP-9 System Backup
  • CP-9(1) Testing for Reliability and Integrity
  • CP-9(8) System Backup | Cryptographic Protection (CP-9(8))
  • IR-3 Incident Response Testing
  • SI-7(1) Integrity Checks

ISO 22301:2019 · 8 controls

  • 7.5 Documented information
  • 7.5.3 Control of documented information
  • 8.3.3 Selection of strategies and solutions
  • 8.3.4 Resource requirements
  • 8.3.5 Implementation of solutions
  • 8.4 Business continuity plans and procedures
  • 8.4.4 Business continuity plans
  • 8.4.5 Recovery

CIS Controls v8 · 7 controls

  • CIS-11.1 Establish and Maintain a Data Recovery Process
  • CIS-11.2 Perform Automated Backups
  • CIS-11.3 Protect Recovery Data
  • CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data
  • CIS-11.5 Test Data Recovery
  • CIS-3.1 Establish and Maintain a Data Management Process
  • CIS-3.4 Enforce Data Retention
  • ISM-1511 Backups aligned to business criticality
  • ISM-1515 Testing restoration to a common point
  • ISM-1547 Data backup processes and procedures
  • ISM-1811 Secure and resilient retention of backups
  • ISM-1928 Securing identity server backups
  • ASBv3-BR-3 Monitor backups
  • ASBv3-BR-4 Regularly test backup
  • ASBv3-GS-8 Define and implement backup and recovery strategy
  • BR-1 Ensure regular automated backups
  • BR-2 Protect backup and recovery data

NIST SP 800-53 Rev 5 · 5 controls

C5 (Germany) · 4 controls

  • C5-OPS-06 Data Backup and Recovery - Concept
  • C5-OPS-07 Data Backup and Recovery - Monitoring
  • C5-OPS-08 Data Backup and Recovery - Regular Testing
  • C5-OPS-09 Data Backup and Recovery - Storage

HIPAA Security Rule · 4 controls

ISO 27701:2019 · 4 controls

  • 6.14 Information security aspects of business continuity management
  • 6.14.1 Information security continuity
  • 6.9.3 Backup
  • 7.3.6 Access, correction and/or erasure
  • NIST-CSF-PR.DS-11 Backups of data are created, protected, maintained, and tested
  • NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
  • NIST-CSF-RC.RP-03 The integrity of backups and other restoration assets is verified before using them for restoration
  • NIST-CSF-RC.RP-05 The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed

NIST SP 800-66 Rev 2 · 4 controls

PCI DSS 4.0 · 4 controls

  • 10.3.3 10.3.3 Audit logs promptly backed up to central secure storage
  • 12.3.1 12.3.1 Targeted risk analysis for flexible-frequency requirements
  • 9.4.1.1 9.4.1.1 Secure storage location for offline backups
  • 9.4.1.2 9.4.1.2 Annual review of offline backup location security

SOC 2 · 4 controls

  • SOC2-A1.2 A1.2 Environmental protection, backup and recovery infrastructure
  • SOC2-A1.3 A1.3 Testing recovery plan procedures
  • SOC2-PI1.4 PI1.4 Controls over output delivery
  • SOC2-PI1.5 PI1.5 Controls over stored inputs, work in process and outputs

MTCS (Singapore) · 3 controls

  • 12.8 Data backups
  • 20.3 Backup procedures
  • A.9 Disclosure: BCP / DR
  • ASD37-34 Regular backups (Essential)
  • ASD37-36 System recovery capabilities (Very Good)
  • CFTC-SS-11 Testing and Review of Business Continuity and Disaster Recovery Capabilities
  • CFTC-SS-8 Business Continuity and Disaster Recovery Plan and Resources

IEC 62443 · 2 controls

  • 62443-2-4-SP-06 Service Provider Backup and Restore Practices
  • 62443-3-3-FR7-SR-7-3 Control System Backup

ISO 27001:2022 · 2 controls

  • 8.13 Information backup
  • 8.14 Redundancy of information processing facilities

ISO/IEC 42001:2023 · 2 controls

  • 7.5 Documented information
  • 8.4 AI system impact assessment
  • ANSSI-HYG-37 Define and Apply a Backup Policy for Critical Components
  • CPS230-19 Tolerance Levels for Each Critical Operation

CMMC 2.0 · 1 control

DORA · 1 control

  • DORA-Art.12 Backup policies and procedures, restoration and recovery

GDPR · 1 control

ISO 27018:2019 · 1 control

NIS2 Directive · 1 control

  • Art.21.2.c Business continuity, backup management, disaster recovery and crisis management
  • 03.08.09 System Backup - Cryptographic Protection

NIST SP 800-218 · 1 control

  • 6.4.6.C.01 6.4.6.C.01 Backup of vital records with offsite storage and testing
  • TSA-SD-13 Backups and recovery for Critical Cyber Systems

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Technological controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 8.13 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 115 it maps to, and the evidence behind each claim, over MCP and REST.