ISO27001:2022 – A8.13 Information backup

Want to fast track your ISO 27001 journey? 

Our “ISO 27001:2022 Policy Pack” gives you everything you need to comply with this, and all ISO 27001 requirements.

Introduction to ISO 27001 – A8.13

To ensure you can recover from loss of data or systems, ISO 27001 – A8.13 requires that you have put in place some form of information backup. Of course, it’s easy to imagine why you would need this kind of control. But what does it mean to implement a truly robust backup process?

What does ISO 27001 – A8.13 require?

The standard states that “Backup copies of information, software and systems shall be maintained and regularly tested in accordance with the agreed topic-specific policy on backup.” (A8.13 – Information backup)

This control is asking you to focus on backups for information, software and systems. ISO27001 clearly sees these as three different aspects, all of which require some form of backup solution.

Why is this required?

Imagine the scenario where your systems have been attacked, or a natural disaster has occurred which results in servers failing, or data becomes corrupted.  Having a robust backup strategy ensures that the critical data you rely on is available as soon as possible.

Imagine you sit down at your computer, only to find that all files have been encrypted and no longer accessible. This is what happens when you’re hit with Ransomware.

Ransomware is one of the most prevalent forms of malware which infects organisations, rendering their data inaccessible. The business disruption when this happens can be devastating, and one of the first questions we ask (when this happens), is; Where are your backups?!

Without a backup in place, you’re not going to be able to recover the data, or if you are able to, it’s going to take a long time to do it. 

What the auditor is looking for

For this ISO27001 control, the auditor will expect to see;

What do you need to do?

Review the data classification scheme you developed as part of ISO27001 Annex A control (A5.12 – Classification of information) and identify what data needs to be backed up. This process should include some form of Business Impact Analysis (BIA), whereby you determine the Recovery Time Objective (RTO) and Recovery Point Objective (RPO). This will ensure you have a clear understanding of what is critical to you and your business.

Once you are clear in this, you can decide on the best backup strategy for you.  This can be a cloud solution, or copying the data to an external drive, which is only connected and used for the purpose of recovery. If you decide to copy data to an external data source, you will need to determine how that drive will be secured and managed.

Now you know what your strategy is, you need to document a topic-specific policy related to your approach to backup and testing of recovery. To ensure the policy reflects reality, speak to the person or team responsible for backing up your data. This is probably your IT representative, or someone else responsible for taking a copy of the data and storing it securely.

Backup strategies might include the ‘3-2-1’ method;

  • 3 Copies
  • 2 different media types
  • 1 offsite copy

Having three copies of your critical data ensures redundancy in case one copy is corrupted, lost, or inaccessible. Relying on two different forms of storage, such as external hard drives, and Cloud storage reduces the risk of one form of medium becoming inaccessible.  Finally, having one copy offsite ensures that if your primary location is not accessible (e.g. due to fire), you can still access your data.  This final, offsite copy is often addressed using Cloud storage.

Keep in mind that the 3-2-1 strategy is a general guideline. The specific number of copies you need and chosen media types will vary depending on your needs and the criticality of your data.

Along with this policy, you might consider documenting a process for managing backups and the recovery tests, however this is not mandatory.

For total confidence that your backups are working, you need to ask for confirmation that backups have been completed and run periodic tests to recover data. This ensures that backups are reporting they have completed correctly, when in fact they have failed.

Finally, keep in mind that this control asks you to consider backup copies of information, software and systems. Therefore, don’t just focus on ‘data’. Do you have backup copies of systems and software?

Difficulty rating

We rate this a 1.5 out of 5 difficulty rating. This isn’t a difficult control to implement but requires careful consideration in terms of what your strategy will be. Backing up data is your final line of defence if you are unfortunate to be impacted by a cyber-attack.

Q&A

If I use Cloud for storage, do I need a backup solution?

The simple answer is, yes you do. Cloud computing isn’t immune to outages or attack. It’s true that Cloud solutions will maintain version history, and if you delete a file in error, then it can quickly be recovered. However, this is not the only risk that you are faced with. 

What happens if you suffer a ransomware attack and all your data is encrypted? What about service disruptions? Google, Amazon, and Microsoft have all suffered outages and service interruptions which have caused some form of business impact.

If you decide that you’re happy with the resilience in the Cloud solution you have in place, then you should recognise this fact and add this to your risk register, because not having a backup solution in place is a risk.

Do I need a Backup Policy?

Yes, this is a requirement of this ISO27001 Annex A control, so you need to document what your strategy is. If you decide that Cloud computing is your backup strategy, then you’ll need to detail this within your policy.

Irrespective of what your approach to backups is, you’ll need to document what your approach to recovery tests is, and how these are to be conducted..

More questions?

We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it…. “The Real Easy Guide to ISO27001” which is available on Amazon.

Fastback your journey to ISO27001 and buy our Policies to get started TODAY!

Take a look at our “ISO 27001:2022 Policy Pack” and when coupled with our book you’ll have everything you need to succeed in achieving ISO 27001 certification!

ISO 27001 – A8.13 - Information backup