ISO 27018:2019
Operations security – ISO 27018:2019

ISO 27018:2019 12.3.1: Information backup

Extends ISO/IEC 27002:2013 12.3.1. Cloud systems add or substitute mechanisms for off-site backup to guard against data loss, keep processing going and restore it after disruption; several copies of data are created or kept in physically or logically separate locations, which may be inside the system itself, for backup or recovery. Responsibility for PII backup may lie with the customer, but where the processor explicitly offers backup and restore it tells the customer clearly what the service can do. Procedures let processing be restored within a stated, documented time after a disruption, and backup and recovery procedures are reviewed at a stated, documented frequency (notes: some jurisdictions fix how often backups and reviews happen). Sub-contractors holding replicated or backup copies fall under the sub-contracted processing controls, and physical media transfers under this document's controls too. The processor keeps a policy covering backup requirements and any further contractual or legal requirements for erasing PII held in backups.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27002:2022 · 1 control

  • 8.13 Information backup

PCI DSS 4.0 · 1 control

  • 12.3.1 12.3.1 Targeted risk analysis for flexible-frequency requirements

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Operations security – ISO 27018:2019

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.