Extends ISO/IEC 27002:2013 12.3.1. Cloud systems add or substitute mechanisms for off-site backup to guard against data loss, keep processing going and restore it after disruption; several copies of data are created or kept in physically or logically separate locations, which may be inside the system itself, for backup or recovery. Responsibility for PII backup may lie with the customer, but where the processor explicitly offers backup and restore it tells the customer clearly what the service can do. Procedures let processing be restored within a stated, documented time after a disruption, and backup and recovery procedures are reviewed at a stated, documented frequency (notes: some jurisdictions fix how often backups and reviews happen). Sub-contractors holding replicated or backup copies fall under the sub-contracted processing controls, and physical media transfers under this document's controls too. The processor keeps a policy covering backup requirements and any further contractual or legal requirements for erasing PII held in backups.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.