ISO 27001

ISO 27001 A.8.13 Information backup: policy, protection and restore tests

Backups only count if you can restore from them. A.8.13 asks for a backup policy, protected copies and regular testing. Here is how to evidence it.

Short answer

ISO 27001 Annex A control 8.13, Information backup, requires backup copies of information, software and systems to be maintained and regularly tested in line with an agreed topic-specific backup policy. That means defined scope, frequency and retention, copies protected from the threats they guard against, and recorded restore tests.

Key takeaways

  • Write a backup policy: what, how often, how long, where.
  • Protect copies from the same event, such as ransomware, with separation or immutability.
  • Test restores regularly and record the results.
  • Cloud services still need a clear backup responsibility.

What the control says

A.8.13 requires backup copies of information, software and systems to be maintained and regularly tested in accordance with the agreed topic-specific policy on backup. ISO/IEC 27002 guidance covers accurate records of backups, frequency and extent matching business needs, storage in a remote location, protection including encryption where appropriate, regular testing of backup media and restore procedures, and retention periods.

What the backup policy should state

ElementExample
ScopeProduction databases, file shares, SaaS data, configuration
FrequencyDaily incremental, weekly full
Retention35 days daily, 12 months monthly
LocationSeparate account or region from production
ProtectionEncryption, immutability or offline copy
TestingQuarterly restore test of each critical system

Ransomware often targets backups. Keep at least one copy that an attacker with production admin rights can't delete or encrypt.

Restore testing

Auditors care most about whether you can restore. A good test restores a real system or dataset, checks it is complete and usable, records how long it took, and compares that with your recovery time objective. Failed tests become corrective actions.

Cloud and SaaS

Cloud providers back up their platform, not necessarily your data in a way you can restore. Check each service's shared responsibility, and record who backs up what under .

Evidence auditors sample

  • Approved backup policy
  • Backup job logs showing success, with failures followed up
  • Restore test records with dates, scope, result and time taken
  • Evidence that copies are separated or immutable
  • Retention settings matching the policy
ISO 27001:2022Other frameworks
  1. A.8.13Information backupSOC 2 A1.2Backup and recovery
  2. A.8.13Information backupNIST CSF PR.DS-11Backups created, protected and tested
  3. A.8.13Information backupISO 22301 8.4Continuity plans
Full mappingPartial mappingIndicative mapping for planning.

Put this into practice on QULDEX

Frequently asked questions

How often should backups be tested for ISO 27001?

The standard says regularly; set the frequency in your policy based on risk. Quarterly tests of critical systems are common.

Do SaaS applications need backups?

Often yes. Check each provider's responsibilities; many don't offer point-in-time restore of your data on your terms.

Sources

  1. ISO/IEC 27001:2022 Information security management systems: Requirements, ISO
  2. ISO/IEC 27002:2022 Information security controls, ISO
  3. NIST SP 800-34 Rev. 1 Contingency Planning Guide for Federal Information Systems, NIST