Short answer
ISO 27001 Annex A control 8.13, Information backup, requires backup copies of information, software and systems to be maintained and regularly tested in line with an agreed topic-specific backup policy. That means defined scope, frequency and retention, copies protected from the threats they guard against, and recorded restore tests.
Key takeaways
- Write a backup policy: what, how often, how long, where.
- Protect copies from the same event, such as ransomware, with separation or immutability.
- Test restores regularly and record the results.
- Cloud services still need a clear backup responsibility.
What the control says
A.8.13 requires backup copies of information, software and systems to be maintained and regularly tested in accordance with the agreed topic-specific policy on backup. ISO/IEC 27002 guidance covers accurate records of backups, frequency and extent matching business needs, storage in a remote location, protection including encryption where appropriate, regular testing of backup media and restore procedures, and retention periods.
What the backup policy should state
| Element | Example |
|---|---|
| Scope | Production databases, file shares, SaaS data, configuration |
| Frequency | Daily incremental, weekly full |
| Retention | 35 days daily, 12 months monthly |
| Location | Separate account or region from production |
| Protection | Encryption, immutability or offline copy |
| Testing | Quarterly restore test of each critical system |
Ransomware often targets backups. Keep at least one copy that an attacker with production admin rights can't delete or encrypt.
Restore testing
Auditors care most about whether you can restore. A good test restores a real system or dataset, checks it is complete and usable, records how long it took, and compares that with your recovery time objective. Failed tests become corrective actions.
Cloud and SaaS
Cloud providers back up their platform, not necessarily your data in a way you can restore. Check each service's shared responsibility, and record who backs up what under .
Evidence auditors sample
- Approved backup policy
- Backup job logs showing success, with failures followed up
- Restore test records with dates, scope, result and time taken
- Evidence that copies are separated or immutable
- Retention settings matching the policy
A.8.13Information backupSOC 2 A1.2Backup and recoveryA.8.13Information backupNIST CSF PR.DS-11Backups created, protected and testedA.8.13Information backupISO 22301 8.4Continuity plans
Put this into practice on QULDEX
Frequently asked questions
How often should backups be tested for ISO 27001?
The standard says regularly; set the frequency in your policy based on risk. Quarterly tests of critical systems are common.
Do SaaS applications need backups?
Often yes. Check each provider's responsibilities; many don't offer point-in-time restore of your data on your terms.