Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 8.13

Information Backup: A Practical Implementation Guide

Create protected, recoverable copies of information and prove they meet business recovery needs.

This control concerns maintaining and regularly testing backup copies according to agreed policy.

Practical interpretation: A successful backup job does not prove recovery. Scope, retention, isolation, encryption, credentials, dependencies and restore testing determine usefulness.

What should the control achieve?

  • Backup requirements follow business and legal needs.
  • Critical data and configuration are covered.
  • Copies resist loss, corruption and ransomware.
  • Restores are tested and evidenced.

Step-by-step implementation

1

Define requirements

Set scope, frequency, RPO, retention, location and recovery priority.

2

Design architecture

Use versioning, isolation, immutability, geographic separation and encryption.

3

Automate and monitor

Alert on failed, incomplete or unusual backup activity.

4

Protect administration

Separate privilege, use MFA and secure keys.

5

Test restoration

Restore representative data and complete services, not only files.

6

Review lifecycle

Update coverage after systems, data and retention change.

What this could look like in practice

A business service uses hourly database backups, daily immutable copies and separate administrative credentials. Quarterly tests restore the application into an isolated environment and business owners validate data.

ActivityPractical implementationEvidence
Backup jobAutomated schedule covers data and configuration.Job log
ProtectionImmutable repository uses separate administration.Configuration
Restore testTeam rebuilds service and validates transactions.Test report
FailureAlert creates owned remediation ticket.Incident ticket

Implementation evidence

  • Backup policy
  • Coverage matrix
  • Schedules
  • Job reports
  • Encryption and immutability
  • Admin access
  • Restore tests
  • Corrective actions

Useful metrics

  • Successful backup jobs
  • Critical data outside coverage
  • Restore tests passed
  • RPO/RTO achieved

Common mistakes

  • Backing up data but not configuration or keys.
  • Keeping backups under production credentials.
  • Testing only small file restores.
  • Ignoring SaaS data.
  • Declaring success without business validation.

Questions an auditor may ask

  • What is backed up and why?
  • How are copies protected from ransomware?
  • Show a complete service restore.
  • How are failures handled?
Implementation test: Recover a critical service using documented backups without relying on the original environment and validate business data.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.