ISO/IEC 27001:2022 Annex A · Control 8.13
Information Backup: A Practical Implementation Guide
Create protected, recoverable copies of information and prove they meet business recovery needs.
This control concerns maintaining and regularly testing backup copies according to agreed policy.
What should the control achieve?
- Backup requirements follow business and legal needs.
- Critical data and configuration are covered.
- Copies resist loss, corruption and ransomware.
- Restores are tested and evidenced.
Step-by-step implementation
Define requirements
Set scope, frequency, RPO, retention, location and recovery priority.
Design architecture
Use versioning, isolation, immutability, geographic separation and encryption.
Automate and monitor
Alert on failed, incomplete or unusual backup activity.
Protect administration
Separate privilege, use MFA and secure keys.
Test restoration
Restore representative data and complete services, not only files.
Review lifecycle
Update coverage after systems, data and retention change.
What this could look like in practice
A business service uses hourly database backups, daily immutable copies and separate administrative credentials. Quarterly tests restore the application into an isolated environment and business owners validate data.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Backup job | Automated schedule covers data and configuration. | Job log |
| Protection | Immutable repository uses separate administration. | Configuration |
| Restore test | Team rebuilds service and validates transactions. | Test report |
| Failure | Alert creates owned remediation ticket. | Incident ticket |
Implementation evidence
- Backup policy
- Coverage matrix
- Schedules
- Job reports
- Encryption and immutability
- Admin access
- Restore tests
- Corrective actions
Useful metrics
- Successful backup jobs
- Critical data outside coverage
- Restore tests passed
- RPO/RTO achieved
Common mistakes
- Backing up data but not configuration or keys.
- Keeping backups under production credentials.
- Testing only small file restores.
- Ignoring SaaS data.
- Declaring success without business validation.
Questions an auditor may ask
- What is backed up and why?
- How are copies protected from ransomware?
- Show a complete service restore.
- How are failures handled?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.