Skip to content
Singahi

Compliance · guide

ISO 27001 A.8.13: Information Backup

59 min read

Share
On this page

Quick Reference (60 Seconds)

Figure · At a glance

A.8.13 at a glance

Control ID
A.8.13
Control Name
Information backup
ISO 27002:2022 Section
8.13
Primary Purpose
Ensure that information and systems can
Key Activities
Define backup policy, schedule backups
Typical Owners
IT Operations Manager, Backup Administrator
The essentials before reading further. The full reference table follows.
AspectSummary
Control IDA.8.13
Control NameInformation backup
ISO 27002:2022 Section8.13
Primary PurposeEnsure that information and systems can be recovered in the event of data loss, corruption, or disaster through regular, tested backups
Key ActivitiesDefine backup policy, schedule backups, test recovery, secure backups, document procedures, monitor backup health, plan for disaster recovery
Typical OwnersIT Operations Manager, Backup Administrator, Disaster Recovery Manager, CISO
Implementation EffortMedium (4–8 weeks)
Annual overhead Range– for growing companies

Bottom Line: Backups are your insurance policy against data loss. Ransomware, hardware failure, human error, natural disasters, and cyberattacks can destroy your data. Without tested backups, recovery is impossible. With proper backups, you can recover from almost anything. Backup is not just about copying data, it is about ensuring you can restore it when you need it, where you need it, and how you need it.


What the Standard Actually Requires

Figure · Process

What A.8.13 asks you to do

The 7 requirements of ISO 27001 A.8.13, information backup, in order: backup policy and procedures; backup scheduling; backup testing; backup storage; off-site storage; retention; encryption.
The 7 things the control expects. Each is expanded in the section below.

ISO 27001:2022 Annex A.8.13 states:

ISO 27001:2022 Annex A 8.13 asks organizations to maintain and regularly test backups of information, software, and systems in line with the backup policy.

ISO 27002:2022 expands this into practical guidance covering:

  1. Backup policy and procedures, Documented rules for what, when, how, and where to back up
  2. Backup scheduling, Regular backups based on data criticality and change frequency
  3. Backup testing, Regular testing of backup integrity and recovery procedures
  4. Backup storage, Secure storage of backups with appropriate physical and logical protection
  5. Off-site storage, Store backups at a sufficient distance from the primary site
  6. Retention, Define retention periods for backups based on business and regulatory needs
  7. Encryption, Encrypt backups to protect data confidentiality
  8. Recovery procedures, Documented and tested procedures for restoring from backups

Why Information backup Matters

The Data Loss Threat

Data loss is one of the most common and devastating IT incidents. It can occur due to hardware failure, software corruption, human error, malware (especially ransomware), natural disasters, and cyberattacks. Without backups, data loss is permanent. With backups, recovery is possible.

Key Statistics

  • 70% of businesses that experience a major data loss without backups go out of business within 1 year
  • Ransomware attacks occur every 11 seconds; 60% of victims pay the ransom because they have no viable backups
  • Data loss overhead average per incident in India (IBM impact of Data Breach Report 2024)
  • Only 35% of organizations test their backups regularly (Veeam Data Protection Report)
  • 45% of backup restorations fail when actually needed (Veeam)
  • India ranks 3rd globally in ransomware attacks, making backups essential for survival
  • Natural disasters (floods, earthquakes, cyclones) affect Indian businesses regularly; off-site backups are critical
  • Human error accounts for 30% of data loss incidents (deletion, overwrite, misconfiguration)

Real-World Consequences

  • A hospital in Mumbai was hit by ransomware that encrypted all patient records, including the backup server (which was on the same network). The hospital had no offline or air-gapped backups. They paid in ransom and still lost 2 weeks of patient data. Surgeries were postponed, and patients had to be transferred to other hospitals.
  • A manufacturing company in Chennai had a server room flood during monsoon season. The flood destroyed all servers and the backup NAS (which was on the floor next to the servers). The company had no off-site backups. They lost 10 years of production data, inventory records, and supplier contracts. The company shut down within 6 months.
  • An IT services company in Bangalore accidentally deleted a client's production database during a routine maintenance task. The deletion was discovered 48 hours later. The backup had been failing for 3 weeks due to a disk space issue, but no one had noticed. The client terminated the contract, and the company faced a lawsuit.
  • A bank in Delhi had a fire in its data center that destroyed the primary storage and the backup tapes (which were stored in the same room). The bank had no off-site backup. All customer transaction records for the past 2 years were lost. The RBI imposed a penalty and restricted the bank's ability to open new accounts until the issue was resolved.
  • A school in Hyderabad had a ransomware attack that encrypted all student records, exam data, and financial records. The school had backups, but they had never been tested. When they tried to restore, they discovered the backup files were corrupted. The school had to manually recreate all records from paper archives, taking 6 months. The incident was widely reported, and enrollment dropped by 40%.

Regulatory and Business Drivers

  • RBI Cyber Security Framework mandates regular backups for critical banking systems, with off-site storage and quarterly recovery testing
  • SEBI Cybersecurity Circular requires trading systems to have tested backups with defined RTO and RPO
  • DPDP Act 2023 requires data fiduciaries to protect personal data, including through backup and recovery measures
  • IT Act 2000 requires reasonable security practices, including backup and recovery for sensitive data
  • Company Act 2013 requires companies to maintain records and have disaster recovery capabilities
  • ISO 27001 requires A.8.13 as part of the ISMS
  • Business Continuity requires backups as a foundation for disaster recovery and business continuity planning
  • Cyber Insurance policies increasingly require proof of backup and recovery testing as a condition of coverage

Scope and Applicability

What Is Covered

  • All electronic data (files, databases, documents, emails, configurations, code)
  • All application software and configurations
  • All system images and virtual machine snapshots
  • All operating system configurations and patches
  • All network device configurations (firewalls, routers, switches, load balancers)
  • All database schemas, stored procedures, and configurations
  • All cloud resources (IaaS VMs, PaaS data, SaaS configurations)
  • All container images and Kubernetes configurations
  • All security tool configurations (SIEM, DLP, EDR, firewall rules)
  • All authentication systems (Active Directory, LDAP, IAM configurations)
  • All log data (if retention requires backup)
  • All physical records that have been digitized

What Is Not Covered

  • Physical records that are not digitized (covered by physical records management)
  • Temporary data that is not needed for recovery (cache, temp files, swap)
  • Data that is explicitly excluded by backup policy (with documented justification)
  • Data that is backed up by third parties under contractual arrangement (but must be verified)

Applicability by Organization Type

Organization TypeApplicabilityKey Backup Concerns
IT/Software ServicesCriticalSource code, client data, project files, cloud resources, dev environments, CI/CD pipelines
BFSICriticalCore banking data, transaction records, KYC data, trading data, customer records, RBI compliance
HealthcareCriticalPatient records, EMR data, medical images, lab results, prescription data, NABH compliance
ManufacturingHighProduction data, ERP data, inventory, supplier contracts, R&D designs, SCADA configs
Government/DefenseCriticalCitizen records, tax data, classified information, defense systems, critical infrastructure
EducationMediumStudent records, exam data, research data, financial records, LMS data
SaaS/CloudCriticalCustomer tenant data, application code, database snapshots, multi-region backup, API configs
Retail/E-commerceHighCustomer data, transaction data, inventory, payment records, supplier data, marketing data

Key Definitions and Terminology

TermDefinition
BackupA copy of data made for the purpose of recovery in case the original data is lost or damaged
Full BackupA complete copy of all data in a system or dataset
Incremental BackupA backup that only copies data that has changed since the last backup (full or incremental)
Differential BackupA backup that copies all data changed since the last full backup
SnapshotA point-in-time copy of data, often used for virtual machines and databases
Image BackupA complete copy of a system including operating system, applications, and data
Recovery Point Objective (RPO)The maximum acceptable amount of data loss measured in time (e.g., 1 hour of data)
Recovery Time Objective (RTO)The maximum acceptable time to restore a system after a failure (e.g., 4 hours)
Retention PeriodThe length of time backups are kept before deletion
Backup WindowThe period of time during which backups are performed
Grandfather-Father-Son (GFS)A backup rotation scheme: daily (son), weekly (father), monthly (grandfather)
Tower of HanoiA backup rotation scheme with multiple media sets rotating at different frequencies
3-2-1 Backup RuleKeep 3 copies of data, on 2 different media types, with 1 copy off-site
3-2-1-1 Backup Rule3 copies, 2 different media, 1 off-site, 1 offline/air-gapped/immutable
Air-Gapped BackupA backup that is physically or logically isolated from the network, preventing remote access
Immutable BackupA backup that cannot be modified, deleted, or encrypted by ransomware
Off-Site BackupA backup stored at a different physical location from the primary data
Cloud BackupA backup stored in a cloud service provider's infrastructure
Disaster Recovery (DR)The process of restoring systems and data after a catastrophic event
Business Continuity (BC)The process of maintaining essential business functions during and after a disaster
Backup VerificationThe process of confirming that a backup is complete, uncorrupted, and restorable
Backup CatalogAn index of all backups with metadata (date, time, contents, location)
ReplicationThe real-time or near-real-time copying of data to a secondary location
FailoverThe automatic switching to a backup system when the primary system fails
RestoreThe process of recovering data from a backup to the original or new location
Bare Metal RestoreRestoring a complete system (OS, applications, data) to new hardware
Point-in-Time Recovery (PITR)Restoring a database to a specific moment in time using transaction logs and backups
Backup EncryptionThe encryption of backup data to protect confidentiality
Backup CompressionThe reduction of backup size to save storage space and transfer time
DeduplicationThe elimination of redundant data across backups to reduce storage

Relationship to Other Controls

ControlRelationship
A.5.1 Policies for information securityBackup policy aligns with overall security policy
A.5.30 ICT readiness for continuityBackups are essential for ICT continuity and disaster recovery
A.8.10 Information deletionBackup deletion must align with primary data deletion policy
A.8.14 Redundancy of information processing facilitiesBackups support redundancy and failover
A.8.15 LoggingBackup activities must be logged
A.8.16 Monitoring activitiesBackup health and success must be monitored
A.8.24 Use of cryptographyBackup encryption protects data confidentiality
A.8.33 Test dataTest data may need backup for test environment recovery
A.8.34 Protection of information systems during disruptionBackups protect data during disruptions
A.7.13 Equipment disposalBackup media must be sanitized before disposal
A.8.7 Protection against malwareImmutable backups protect against ransomware
A.8.9 Configuration managementSystem configurations must be backed up
A.8.32 Configuration of information systemsSystem configurations must be backed up and recoverable

Implementation Roadmap (Week-by-Week)

Week 1: Data and System Inventory

  • Inventory all critical systems, applications, and databases
  • Identify data owners for each system
  • Classify data by criticality (critical, high, medium, low)
  • Identify RPO and RTO requirements for each system
  • Map current backup practices (what is backed up, how often, where stored)
  • Identify backup gaps (systems not backed up, outdated backups, single points of failure)
  • Document current backup infrastructure (hardware, software, cloud, tape)
  • Assess backup storage capacity and growth trends

Week 2: Backup Policy and Strategy Development

  • Draft backup policy
  • Define backup schedules by data criticality:
    • Critical systems: Continuous replication or hourly backup
    • High-priority systems: Daily backup
    • Medium-priority systems: Weekly backup
    • Low-priority systems: Monthly backup or as needed
  • Define backup types (full, incremental, differential, snapshot)
  • Define retention periods (daily: 7 days, weekly: 4 weeks, monthly: 12 months, annual: 7 years)
  • Define storage locations (on-site, off-site, cloud, air-gapped)
  • Define RPO and RTO targets for each system
  • Define backup encryption requirements
  • Define backup testing schedule (monthly test restores, annual DR drill)
  • Approve policy by IT leadership and CISO

Week 3: Backup Infrastructure Setup

  • Select backup software (Veeam, Commvault, Acronis, AWS Backup, Azure Backup, etc.)
  • Select backup storage (on-premise NAS/SAN, cloud storage, tape, optical)
  • Set up backup servers and infrastructure
  • Configure backup network (dedicated backup VLAN, bandwidth allocation)
  • Set up off-site backup location (secondary data center, cloud region, tape vault)
  • Set up air-gapped or immutable backup storage (tape, WORM, cloud immutable)
  • Configure backup encryption (AES-256, key management)
  • Configure backup compression and deduplication
  • Test backup infrastructure connectivity and performance

Week 4: Backup Job Configuration and Scheduling

  • Configure backup jobs for all critical systems
  • Schedule backups within backup windows (minimize production impact)
  • Configure full backups (weekly or monthly)
  • Configure incremental or differential backups (daily or hourly)
  • Configure snapshot backups for databases and VMs
  • Configure application-aware backups (VSS, database quiescing)
  • Configure backup alerting (success, failure, warnings)
  • Configure backup cataloging and indexing
  • Test backup jobs on non-production systems

Week 5: Cloud Backup and Replication Setup

  • Configure cloud backup for on-premise systems (AWS, Azure, GCP)
  • Configure cross-region replication for cloud-native systems
  • Configure cloud-to-cloud backup (SaaS backup: Office 365, Google Workspace, Salesforce)
  • Configure cloud snapshot policies (VMs, databases, storage)
  • Configure cloud immutability (object lock, legal hold, retention policies)
  • Test cloud backup uploads and downloads
  • Verify cloud backup encryption and access controls
  • Document cloud backup architecture and procedures

Week 6: Immutable and Air-Gapped Backup Setup

  • Configure immutable backups (cannot be modified or deleted)
  • Set up air-gapped backup (physically disconnected from network)
  • Configure tape backup with offline rotation
  • Configure WORM (Write Once Read Many) storage
  • Configure cloud object lock (AWS S3 Object Lock, Azure Blob Immutable)
  • Test immutable backup behavior (attempt to modify/delete)
  • Verify air-gapped backup isolation (no network connectivity)
  • Document immutable and air-gapped backup procedures

Week 7: Backup Testing and Recovery Procedures

  • Document recovery procedures for each system type
  • Conduct test restore of critical system (file-level restore)
  • Conduct test restore of critical system (full system restore)
  • Conduct test restore of database (point-in-time recovery)
  • Conduct test restore of virtual machine (full VM restore)
  • Conduct test restore of cloud resource (cloud-to-cloud restore)
  • Conduct test restore from off-site backup (verify off-site accessibility)
  • Conduct test restore from immutable backup (verify immutability does not prevent recovery)
  • Measure actual RTO and compare to target
  • Document test results and any gaps

Week 8: Monitoring, Documentation, and Audit

  • Set up backup monitoring dashboard (success rate, failure rate, storage use)
  • Configure automated backup health checks
  • Configure backup failure alerts and escalation
  • Document all backup procedures (schedules, retention, recovery, testing)
  • Create quick reference guides for common recovery scenarios
  • Train IT staff on backup operations and recovery procedures
  • Conduct internal audit of backup implementation
  • Prepare documentation for external audit
  • Plan for continuous improvement

Detailed Implementation Guidance

Figure · Matrix

How the options compare: Copy 1 to Copy 4

LocationMediaPurpose
Copy 1On-sitePrimary storageOperational recovery
Copy 2On-siteBackup server / NASBackup recovery
Copy 3Off-siteSecondary data center /Disaster recovery
Copy 4Air-gapped / ImmutableTape / WORM / Cloud ObjectRansomware protection
Condensed from the table below, which carries the full detail for each cell.

Backup Strategy by Data Criticality

Backup Schedule Matrix:

Data CriticalityRPORTOBackup FrequencyBackup TypeRetentionStorage
Critical (e.g., core banking, EMR, trading)1 hour2 hoursHourly incremental; daily full; continuous replicationIncremental + Full + ReplicationDaily: 7 days; Weekly: 4 weeks; Monthly: 12 monthsOn-site + Off-site + Cloud + Immutable
High (e.g., ERP, CRM, customer portal)4 hours8 hoursEvery 4 hours incremental; daily fullIncremental + FullDaily: 14 days; Weekly: 8 weeks; Monthly: 6 monthsOn-site + Off-site + Cloud
Medium (e.g., HRIS, finance, intranet)24 hours24 hoursDaily incremental; weekly fullIncremental + FullDaily: 7 days; Weekly: 4 weeks; Monthly: 3 monthsOn-site + Off-site
Low (e.g., archives, old projects, non-critical files)1 week1 weekWeekly fullFullWeekly: 4 weeks; Monthly: 3 months; Annual: 1 yearOn-site + Off-site

3-2-1-1 Backup Rule Implementation:

CopyLocationMediaPurpose
Copy 1On-sitePrimary storage (SAN/NAS)Operational recovery (fast restore)
Copy 2On-siteBackup server / NASBackup recovery (local restore)
Copy 3Off-siteSecondary data center / cloudDisaster recovery (site failure)
Copy 4Air-gapped / ImmutableTape / WORM / Cloud Object LockRansomware protection (cannot be encrypted)

Backup Types and Use Cases

Backup TypeDescriptionProsConsBest For
Full BackupComplete copy of all dataFastest restore; simple recoveryLongest backup time; most storageWeekly baseline; small datasets
Incremental BackupOnly data changed since last backup (any type)Fastest backup; least storageSlower restore (must restore full + all incrementals)Frequent backups; large datasets
Differential BackupAll data changed since last full backupFaster restore than incremental (full + 1 differential)Slower backup than incremental; more storage than incrementalDaily backups with moderate storage
SnapshotPoint-in-time copy of data (often at block level)Instant creation; minimal performance impactNot true backup (depends on underlying storage); may not protect against storage failureVMs, databases; quick recovery points
Image BackupComplete system image (OS + apps + data)Complete system recovery; bare metal restoreLarge storage; long backup timeCritical servers; disaster recovery
ReplicationReal-time or near-real-time copy to secondary siteMinimal RPO; fast failoverNot a backup (corruption replicates); premium-tierCritical systems; high availability
Cloud BackupBackup to cloud storageOff-site by default; scalable; managedBandwidth dependent; ongoing overhead; security considerationsOff-site protection; cloud-native systems

Hybrid Backup Strategy (Recommended):

  • Use full backups weekly (Sunday night)
  • Use incremental backups daily (Monday–Saturday)
  • Use snapshots hourly for critical databases and VMs
  • Use replication for critical systems requiring minimal RPO
  • Use cloud backup for off-site protection
  • Use immutable backup for ransomware protection

Ransomware-Resistant Backup Strategy

Ransomware Protection for Backups:

LayerControlImplementation
Immutable backupsBackups cannot be modified or deleted by ransomwareS3 Object Lock, Azure Blob Immutable, tape WORM, immutable NAS
Air-gapped backupsBackups physically or logically disconnected from production networkTape rotation, offline NAS, disconnected cloud account
Network segmentationBackup network isolated from production networkSeparate VLAN, firewall rules, no direct connectivity
Access controlsStrict access to backup systems (no domain admin, separate credentials)Separate backup domain, MFA, role-based access, audit logging
MonitoringMonitor backup systems for ransomware indicatorsSIEM alerts, backup integrity checks, anomaly detection
Regular testingTest restores frequently to verify backup integrityMonthly test restores, integrity checks, catalog verification
Offline credentialsBackup credentials not stored on production systemsSeparate credential vault, hardware token, break-glass procedure
Backup encryptionEncrypt backups so ransomware cannot read them even if accessedAES-256, key management, encryption at rest and in transit

Immutable Backup Technologies:

TechnologyVendor/PlatformHow It WorksBest For
S3 Object LockAWSWORM at object level; retention mode (compliance/governance)Cloud-native, AWS environments
Immutable Blob StorageAzure AzureImmutable containers with time-based retentionMicrosoft environments
Retention LockGoogle CloudBucket-level WORM policiesGCP environments
Immutable BackupVeeamBackup files marked immutable; cannot be deleted or modifiedVeeam deployments
WORM TapeVarious (IBM, HPE, Quantum)Physical tape with write-once capabilityAir-gapped, long-term archive
Immutable NASVarious (Synology, QNAP, NetApp)Snapshot immutability; cannot be deleted or modifiedOn-premise NAS backup
Immutable Object StorageMinIO, Ceph, CloudianObject-level immutability with retention policiesSelf-hosted object storage

Cloud Backup and SaaS Backup

Cloud-Native Backup:

Cloud ServiceBackup TargetNative BackupThird-Party Backup
AWS EC2VMs, volumesAWS Backup, EBS snapshotsVeeam, Commvault, N2WS
AWS RDSDatabasesAutomated backups, manual snapshotsVeeam, Commvault
AWS S3Object storageVersioning, cross-region replicationVeeam, Commvault, CloudBerry
Azure VMsVirtual machinesAzure Backup, snapshotsVeeam, Commvault
Azure SQLDatabasesAutomated backups, long-term retentionVeeam, Commvault
Azure BlobObject storageSoft delete, versioning, immutableVeeam, Commvault
GCP ComputeVMsSnapshots, persistent disk backupsVeeam, Commvault
GCP Cloud SQLDatabasesAutomated backups, point-in-time recoveryVeeam, Commvault
GCP Cloud StorageObject storageVersioning, lifecycle, retentionVeeam, Commvault
Office 365Email, SharePoint, Teams, OneDriveRetention policies, eDiscoveryVeeam, AvePoint, Commvault
Google WorkspaceGmail, Drive, Calendar, SitesVault, TakeoutVeeam, Spanning, Backupify
SalesforceCRM dataData Export, Backup & RestoreOwnBackup, Veeam, Commvault
SAPERP dataSAP BR*Tools, DBA CockpitVeeam, Commvault, Backint

SaaS Backup Considerations:

  • SaaS providers (Microsoft, Google, Salesforce) do not guarantee backup of your data
  • Their "retention" is for their operational needs, not your recovery needs
  • Accidental deletion, ransomware, and malicious insiders can delete SaaS data permanently
  • Third-party SaaS backup tools are essential for business-critical SaaS data
  • SaaS backups should include: emails, files, contacts, calendars, configurations, metadata

Backup Testing and Verification

Testing Schedule:

Test TypeFrequencyScopeResponsible
Backup integrity checkDaily (automated)Verify backup file integrity, checksums, catalog consistencyBackup software (automated)
File-level restore testWeeklyRestore 1–2 files from each backup job to verify accessibilityBackup Administrator
Folder-level restore testMonthlyRestore a folder or dataset from each critical systemBackup Administrator
Database restore testMonthlyRestore a critical database and verify data consistencyDBA + Backup Administrator
VM restore testMonthlyRestore a critical VM and verify it boots and functionsIT Operations
Full system restore testQuarterlyRestore a complete system (OS + apps + data) to test hardwareIT Operations
Off-site restore testQuarterlyRestore from off-site backup to verify accessibility and integrityBackup Administrator
Immutable restore testQuarterlyRestore from immutable backup to verify immutability doesn't prevent recoveryBackup Administrator
DR drillAnnuallyFull disaster recovery simulation (failover, restore, verify, failback)DR Team + IT Operations
RTO/RPO validationAnnuallyMeasure actual recovery time and data loss against targetsDR Team + IT Operations

Backup Verification Checklist:

  • Backup completed successfully (no errors or warnings)
  • Backup size is reasonable (not too small or too large)
  • Backup catalog is updated and accurate
  • Backup checksum/hash matches (integrity verified)
  • Backup is accessible (can be mounted or read)
  • Backup is not corrupted (scan for corruption)
  • Backup contains expected data (sample verification)
  • Backup encryption is intact (verify key accessibility)
  • Backup retention is correct (not expired, not overwritten)
  • Backup storage has sufficient capacity (no imminent exhaustion)

Tools, Technologies, and Solutions

Enterprise Backup Software

VendorProductKey Featureslicensing Range (INR)
VeeamBackup & ReplicationVM backup, physical backup, cloud backup, immutable backup, replication, DR orchestration–1,200 per VM/year
CommvaultComplete Data ProtectionComplete backup, cloud, SaaS, DR, analytics, edge data–1,500 per VM/year
VeritasNetBackup / Backup ExecEnterprise backup, cloud, SaaS, tape, deduplication, DR–1,500 per VM/year
AcronisCyber BackupBackup, disaster recovery, cyber protection, anti-ransomware, blockchain verification–800 per VM/year
RubrikCloud Data ManagementCloud-native, immutable, ransomware protection, SaaS backup, DR–2,000 per VM/year
CohesityDataProtectHyperconverged backup, cloud, ransomware protection, dev/test provisioning–1,500 per VM/year
Dell EMCAvamar / NetworkerEnterprise backup, deduplication, cloud, tape, DR–1,500 per VM/year
IBMSpectrum ProtectEnterprise backup, tape, cloud, deduplication, DR–1,500 per VM/year
ArcserveUnified Data ProtectionBackup, DR, high availability, ransomware protection, cloud–1,000 per VM/year
** Nakivo**Backup & ReplicationVM backup, physical, cloud, affordable, easy to use–600 per VM/year
ManageEngineRecoveryManager PlusActive Directory backup, VM backup, affordable–800 per VM/year
BaculaEnterprise BackupOpen-source, enterprise, tape, cloud, scalableFree (open-source) or –800 per VM/year
UrBackupBackup SolutionOpen-source, client/server, image backup, file backupFree (open-source)

Cloud Backup Services

ServiceCloudKey Featureslicensing Range (INR)
AWS BackupAWSCentralized backup, cross-region, cross-account, policy-based, compliant–500 per VM/month
Azure BackupAzureVM backup, SQL backup, file share backup, SAP HANA, cross-region–600 per VM/month
Google Cloud BackupGCPVM backup, database backup, cross-region, policy-based–500 per VM/month
Veeam Backup for AWSAWSCloud-native, immutable, DR, cross-region, policy-based–800 per VM/month
Veeam Backup for AzureAzureCloud-native, immutable, DR, cross-region, policy-based–800 per VM/month
Veeam Backup for GCPGCPCloud-native, immutable, DR, cross-region, policy-based–800 per VM/month
Commvault MetallicMulti-cloudSaaS backup, cloud-native, no infrastructure, simple–800 per VM/month
DruvaMulti-cloudSaaS backup, cloud-native, no hardware, ransomware protection–1,000 per VM/month
ClumioAWSSaaS backup, cloud-native, no infrastructure, S3, EC2, RDS–800 per VM/month

SaaS Backup Tools

VendorProductKey Featureslicensing Range (INR)
VeeamBackup for Microsoft 365Email, SharePoint, Teams, OneDrive, immutable, eDiscovery
AvePointCloud BackupMicrosoft 365, Google Workspace, Salesforce, complete
Spanning (Kaseya)BackupGoogle Workspace, Microsoft 365, Salesforce, point-in-time restore
Backupify (Datto)BackupGoogle Workspace, Microsoft 365, Salesforce, automated
OwnBackupSalesforce BackupSalesforce backup, sandbox seeding, compare, restore
DropSuiteBackupMicrosoft 365, Google Workspace, immutable, encrypted
SpinOne (Spin.ai)BackupGoogle Workspace, Microsoft 365, ransomware protection, DLP
SysCloudBackupGoogle Workspace, Microsoft 365, automated, compliance

Immutable and Air-Gapped Storage

VendorProductKey Featureslicensing Range (INR)
AWSS3 Glacier Deep Archive + Object LockImmutable, air-gapped by design, extremely lightweight, long-term
AzureBlob Archive + ImmutableImmutable containers, WORM, legal hold, long-term
Google CloudArchive Storage + Retention LockImmutable, long-term, lightweight, compliance
QuantumScalar Tape LibraryAir-gapped, WORM tape, long-term, ransomware-proof–10,00,000 (hardware)
IBMTS4300 Tape LibraryAir-gapped, WORM tape, enterprise, long-term–15,00,000 (hardware)
HPEStoreEver TapeAir-gapped, WORM, enterprise, long-term archive–10,00,000 (hardware)
SynologyNAS with Snapshot ReplicationImmutable snapshots, air-gapped replication, affordable–2,00,000 (hardware)
MinIOObject StorageS3-compatible, object lock, immutable, self-hostedFree (open-source) or –2,00,000/year

Policy and Procedure Templates

Information Backup Policy Template

Template

Backup Testing and Recovery Runbook Template

Template


Risk Assessment and Treatment

Risk Assessment Matrix for Information backup

Risk IDThreatVulnerabilityLikelihoodImpactRisk LevelTreatment
R1Ransomware encrypts all data including backupsBackup on same network; no immutable backup; no air-gappingHighCriticalCriticalImmutable backup; air-gapped backup; network segmentation; offline credentials
R2Hardware failure destroys primary and backup storageBackup on same hardware; no off-site backup; single point of failureMediumCriticalCriticalOff-site backup; cloud backup; separate hardware; redundant storage
R3Natural disaster destroys primary site and on-site backupsNo off-site backup; no DR site; backup in same buildingMediumCriticalCriticalOff-site backup; cloud backup; DR site; geographic separation
R4Human error deletes or overwrites critical dataNo backup; outdated backup; backup failure unnoticedHighHighCriticalRegular backup; backup monitoring; retention; versioning; point-in-time recovery
R5Backup corruption makes restore impossibleNo backup testing; no integrity checks; silent backup failuresMediumHighHighRegular testing; integrity checks; monitoring; catalog verification
R6Backup failure goes unnoticedNo monitoring; no alerting; no verification; manual backupHighHighHighAutomated monitoring; alerting; daily health checks; dashboard
R7Insufficient backup storage capacityNo capacity planning; no growth forecasting; storage fullMediumHighHighCapacity monitoring; growth planning; storage tiering; deduplication; compression
R8Slow recovery exceeds RTONo DR planning; untested procedures; inadequate infrastructure; large data volumeMediumHighHighDR planning; regular testing; pre-staged DR infrastructure; incremental restore
R9Backup data breach (confidentiality)Unencrypted backups; weak access controls; backup media lost/stolenMediumHighHighBackup encryption; access controls; secure storage; media tracking; chain of custody
R10Cloud backup failure or vendor lock-inSingle cloud provider; no exit strategy; cloud outage; vendor failureLowHighMediumMulti-cloud strategy; data portability; exit strategy; cloud DR testing

Audit and Compliance Checklist

Internal Audit Checklist (30 Questions)

Policy and Governance (5 Questions)

  1. Is a backup policy documented and approved?
  2. Does the policy define backup schedules, retention, and testing?
  3. Are RPO and RTO defined for all critical systems?
  4. Is the policy reviewed annually?
  5. Are roles and responsibilities for backup defined?

Backup Operations (5 Questions)

  1. Are backups performed according to defined schedules?
  2. Are backup jobs monitored for success and failure?
  3. Are failed backups investigated and re-run promptly?
  4. Are backup logs maintained and reviewed?
  5. Is backup storage capacity monitored?

Backup Security (5 Questions)

  1. Are backups encrypted at rest?
  2. Are backups encrypted in transit?
  3. Are backup encryption keys managed securely?
  4. Is backup access restricted to authorized personnel?
  5. Is backup storage physically secure?

Off-Site and Immutable (5 Questions)

  1. Are off-site backups stored at a sufficient distance from the primary site?
  2. Are off-site backups encrypted and access-controlled?
  3. Are immutable backups configured for critical systems?
  4. Are air-gapped backups maintained for ransomware protection?
  5. Is off-site backup accessibility tested regularly?

Testing and Recovery (5 Questions)

  1. Are backups tested regularly (monthly minimum)?
  2. Are recovery procedures documented and tested?
  3. Are RTO and RPO validated through testing?
  4. Is a DR drill conducted annually?
  5. Are test results documented and reviewed?

Documentation and Compliance (5 Questions)

  1. Are backup catalogs maintained and accurate?
  2. Are backup retention periods enforced?
  3. Is backup deletion documented and automated?
  4. Are legal hold requirements accommodated in backup retention?
  5. Are backup audit trails maintained?

Audit Scoring

  • 30–27: Excellent (Green), Full compliance
  • 26–22: Good (Yellow), Minor gaps, address within 30 days
  • 21–15: Needs Improvement (Orange), Significant gaps, address within 60 days
  • 14–0: Critical (Red), Major non-compliance, immediate action required

Metrics and KPIs

Figure · Measures

The measures that show A.8.13 is working

  • Backup Success Rate>= 99%Daily
  • Backup Failure Resolution Time<= 4 hoursPer failure
  • Backup Integrity Check Pass Rate100%Daily
  • Test Restore Success Rate100%Monthly
  • RTO Achievement Rate>= 95%Quarterly
Targets and reporting cadence as defined in the table below, where the formula for each is given.

Key Performance Indicators

KPIFormulaTargetMeasurement Frequency
Backup Success Rate(Successful backups / Total backup jobs) x 100>= 99%Daily
Backup Failure Resolution TimeAverage time to resolve failed backup<= 4 hoursPer failure
Backup Integrity Check Pass Rate(Integrity checks passed / Total checks) x 100100%Daily
Test Restore Success Rate(Successful test restores / Total test restores) x 100100%Monthly
RTO Achievement Rate(Tests meeting RTO / Total tests) x 100>= 95%Quarterly
RPO Achievement Rate(Tests meeting RPO / Total tests) x 100>= 95%Quarterly
Off-Site Backup Accessibility(Off-site backups accessible / Total off-site backups tested) x 100100%Quarterly
Immutable Backup Integrity(Immutable backups verified / Total immutable backups) x 100100%Quarterly
Backup Storage Use(Used backup storage / Total backup storage) x 100<= 80%Weekly
Backup overhead per TBTotal backup overhead / Total backup storageTrending downwardMonthly
DR Drill Completion(DR drills completed / Planned drills) x 100100%Annually
DR Drill Pass Rate(DR drills passed / Total drills) x 100>= 90%Annually
Backup Coverage(Systems with defined backup / Total systems) x 100100%Monthly
Backup Encryption Coverage(Encrypted backups / Total backups) x 100100%Monthly
Policy Review Cycle Adherence(Reviews on time / Required reviews) x 100100%Annually
Audit Finding Closure Rate(Closed findings / Total findings) x 100100% within 60 daysPer audit

Common Pitfalls and How to Avoid Them

Pitfall 1: "We Have Backups, We're Fine"

Problem: Organizations assume that having backups is sufficient. They never test restores. When disaster strikes, they discover backups are corrupted, incomplete, or unrecoverable. The backup was a false sense of security. Solution: Test backups regularly. A backup is not a backup until it has been successfully restored. Implement monthly test restores, quarterly full system restores, and annual DR drills. Document test results. Fix any issues immediately. The only way to know a backup works is to restore from it. Untested backups are Schrödinger's backups, they simultaneously exist and don't exist until you try to restore.

Pitfall 2: Backups on the Same Network as Production

Problem: Backup servers are on the same network as production systems, using the same credentials, and accessible from the same endpoints. When ransomware hits production, it encrypts the backup server too. The backup and production are destroyed together. Solution: Isolate backups from production: (1) Separate backup VLAN with firewall rules, (2) Different credentials for backup systems (not domain admin), (3) Immutable backups that cannot be encrypted, (4) Air-gapped backups physically disconnected from the network, (5) Offline credentials stored separately. Ransomware is designed to find and encrypt backups, make it impossible to reach them.

Pitfall 3: No Off-Site Backup

Problem: Backups are stored in the same building as production. A fire, flood, earthquake, or explosion destroys both production and backups. The organization has no way to recover. Solution: Maintain off-site backups at least 50 km from the primary site. Use cloud backup for geographic separation. Use tape rotation to an off-site vault. Test off-site restore quarterly. India is prone to floods, earthquakes, and cyclones, off-site backup is not optional. The 2015 Chennai floods and 2023 Himachal Pradesh floods destroyed many on-site backups. Off-site backup saved organizations that had it.

Pitfall 4: Backup Failure Ignored

Problem: Backup jobs fail silently or generate warnings that are ignored. Disk space runs out. Network issues interrupt backups. Backup software licenses expire. No one notices until a restore is needed. Solution: Implement automated backup monitoring with alerting. Send alerts for any backup failure, warning, or anomaly. Review backup dashboards daily. Set up escalation for unaddressed failures. Implement backup integrity checks (checksums, catalog verification). Monitor backup storage capacity. A backup failure is a critical incident, not a minor issue.

Pitfall 5: No Immutable Backup

Problem: Backups can be modified, deleted, or encrypted by ransomware or attackers. The backup is only as secure as the system it protects. If an attacker gains admin access, they can destroy backups. Solution: Implement immutable backups that cannot be modified or deleted for a defined retention period. Use S3 Object Lock, Azure Blob Immutable, tape WORM, or immutable NAS snapshots. Maintain air-gapped backups (physically disconnected). Test immutable restore to ensure immutability doesn't prevent recovery. Immutable backup is the single most effective defense against ransomware.

Pitfall 6: Over-Reliance on Cloud Backup Without Testing

Problem: Organizations assume cloud backup is infallible. They never test cloud restores. When needed, they discover slow download speeds, unexpected overhead, or data corruption. The cloud backup exists but cannot be recovered in time. Solution: Test cloud restores regularly. Measure actual download speeds and restore times. Verify cloud backup integrity. Understand cloud egress overhead for large restores. Maintain a local copy for fast recovery. Cloud backup is not magic, it is just another storage location that requires testing and verification.

Pitfall 7: No Backup for SaaS Data

Problem: Organizations assume SaaS providers (Microsoft 365, Google Workspace, Salesforce) back up their data. They don't. When an employee accidentally deletes emails, or ransomware encrypts SharePoint files, or a malicious admin deletes data, the organization has no backup. Solution: Implement third-party SaaS backup for all business-critical SaaS data. Backup Office 365 (email, SharePoint, Teams, OneDrive). Backup Google Workspace (Gmail, Drive, Calendar). Backup Salesforce. Backup any other SaaS that contains critical data. SaaS providers offer retention, not backup. Retention is for their operational needs; backup is for your recovery needs. They are not the same.

Pitfall 8: No Disaster Recovery Plan

Problem: Organizations have backups but no DR plan. When a disaster occurs, they don't know who does what, in what order, with what resources. Recovery is chaotic, slow, and incomplete. The backup exists, but the recovery process doesn't. Solution: Develop a formal DR plan: (1) Define DR team roles and responsibilities, (2) Define recovery procedures for each system type, (3) Define failover and failback procedures, (4) Pre-stage DR infrastructure (warm standby, pilot light, or cold standby), (5) Document runbooks with step-by-step instructions, (6) Conduct annual DR drills, (7) Measure and improve RTO and RPO. Backup is the fuel; DR is the engine. Both are needed to recover from disaster.


Illustrative Scenarios

Illustrative scenario, a composite example for guidance, not a specific Singahi engagement or a verified outcome.

Illustrative Scenario 1: Indian SME, Ransomware Recovery via Immutable Backups (Growing company)

Organization: A 200-employee manufacturing SME in Ahmedabad with ERP, file servers, and email Challenge: The company was hit by LockBit ransomware that encrypted all 50 servers, 200 endpoints, and the file server. The attackers demanded in Bitcoin. The company had backups but they were on a NAS connected to the same network. The ransomware encrypted the NAS backups too. The company had no immutable backups, no air-gapped backups, and no off-site backups. The company faced a existential crisis, pay the ransom (with no guarantee of recovery) or lose all data and potentially shut down. The CEO had 48 hours to decide. Before State:

  • 50 servers and 200 endpoints encrypted by ransomware
  • Backup NAS on same network, encrypted by ransomware
  • No immutable backups
  • No air-gapped backups
  • No off-site backups
  • No cloud backup
  • No DR plan
  • No backup testing (last test was 2 years ago)
  • No backup monitoring (backup had been failing for 2 weeks due to disk space; unnoticed)
  • Ransom demand:
  • Company had 2 days of cash reserves; would shut down if data not recovered

Emergency Response: Hour 1: Engaged Singahi for emergency incident response. Isolated all infected systems. Preserved evidence for forensics. Assessed backup situation. Hour 2: Discovered that the backup NAS was encrypted but the backup software catalog was partially intact. Identified that 3-month-old tape backups existed in a storage closet (forgotten, never rotated). Tapes were not connected to the network and were not encrypted by ransomware. Hour 3–12: Engaged tape recovery vendor. Restored tape backups to clean hardware. Restored ERP database (3 months old). Restored file server (3 months old). Restored email from cloud (Office 365 retention saved 30 days of email). Hour 12–48: Rebuilt all servers from scratch. Installed clean OS and applications. Restored data from tape and cloud. Verified data integrity. Rebuilt endpoints with clean images. Implemented emergency security controls (MFA, EDR, network segmentation). Week 1: Company operational with 3-month-old data. Lost 3 months of transactions and documents. Re-entered data from paper records and customer confirmations. Contacted customers to reconcile orders. Week 2–4: Implemented proper backup infrastructure. Deployed Veeam with immutable backups. Implemented cloud backup (AWS S3 with Object Lock). Implemented air-gapped tape rotation. Implemented backup monitoring and testing. Trained staff on new procedures.

Results (After 6 Months):

  • 100% immutable backup coverage (Veeam + AWS S3 Object Lock + tape)
  • 100% off-site backup coverage (cloud + off-site tape vault)
  • 100% backup monitoring (daily health checks, alerting)
  • 100% backup testing (monthly test restores, quarterly DR drill)
  • 100% backup encryption (AES-256 at rest and in transit)
  • Zero backup failures in 6 months (automated monitoring and alerting)
  • DR drill completed successfully (RTO: 8 hours, RPO: 1 hour, targets met)
  • Company survived the ransomware attack (lost 3 months of data, but survived)
  • Customer trust maintained (transparent communication about incident and recovery)
  • New customers signed citing "strong backup and recovery practices"

Investment: (emergency recovery: ; Veeam, AWS, tape, consulting, training: ) ROI: The company avoided paying ransom. The company survived and continued operations. The investment in proper backup was 3% of the ransom demand. The CEO stated: "The best money we ever spent was on backup. The worst money we ever saved was by not having backup."

Key Lesson: Immutable and air-gapped backups are the difference between surviving ransomware and shutting down. The forgotten tape backups saved the company, but the lack of recent, tested, immutable backups caused massive data loss. For growing companies, backup is not an IT expense, it is business insurance.


Illustrative Scenario 2: Large Indian Bank, Complete Backup and DR Transformation

Organization: A large public sector bank with 3,000 branches, 30 million customers, and 5,000 servers Challenge: The bank had a fragmented backup infrastructure with 15 different backup tools across various departments and branches. Core banking system (CBS) backups were failing 30% of the time due to network issues at rural branches. The bank had no immutable backups. The DR site had outdated data (last updated 6 months ago). The RBI cyber audit found 20 critical backup deficiencies and required a complete overhaul within 9 months. The bank faced potential operational restrictions if not resolved. A recent ransomware incident at a peer bank (which paid ) highlighted the existential risk of inadequate backup. Before State:

  • 15 different backup tools with no central management
  • CBS backup failure rate: 30% (rural branches with poor connectivity)
  • No immutable backups on any system
  • DR site with 6-month-old data (no replication, manual updates)
  • No cloud backup
  • No backup testing program (last test was 2 years ago)
  • No backup monitoring (failures unnoticed for weeks)
  • No off-site backup for 500 branch servers
  • Tape backups stored in the same building as servers
  • RBI audit: 20 critical backup findings
  • Peer bank ransomware incident: paid ransom

Implementation: Phase 1 (Months 1–3): Centralized backup infrastructure. Replaced 15 tools with Commvault as the enterprise backup platform. Deployed Commvault across all 3,000 branches (centralized management with local caching for rural branches). Implemented deduplication and compression to reduce network load. Implemented bandwidth throttling for rural branches. Reduced CBS backup failure rate from 30% to 2%. Phase 2 (Months 4–5): Immutable and cloud backup. Implemented Commvault immutable backups for all critical systems (CBS, core networks, AD, email). Implemented AWS S3 Object Lock for cloud backup. Implemented tape WORM for air-gapped backups. Implemented 3-2-1-1 strategy for all critical systems. Phase 3 (Months 6–7): DR site modernization. Upgraded DR site with current infrastructure. Implemented continuous replication for CBS (RPO: 15 minutes). Implemented automated DR failover for critical systems. Implemented network monitoring and bandwidth optimization for DR replication. Updated DR site data from 6 months old to real-time. Phase 4 (Months 7–8): Testing and validation. Implemented automated backup testing (weekly integrity checks, monthly restore tests, quarterly DR drills). Conducted first DR drill for CBS (failover: 2 hours, restore: 4 hours, failback: 6 hours). Conducted ransomware recovery drill (restore from immutable backup: 8 hours). All tests passed. Phase 5 (Months 8–9): RBI audit and compliance. RBI empanelled auditor conducted complete backup and DR audit. All 20 previous findings resolved. New audit: zero critical findings. RBI satisfied; no operational restrictions. Bank passed RBI cyber security audit with "commendable" rating for backup practices.

Results (After 18 Months):

  • 100% centralized backup coverage (5,000 servers, 3,000 branches, all critical systems)
  • 100% immutable backup coverage for critical systems
  • 100% cloud backup coverage (AWS S3 with Object Lock)
  • 100% off-site backup coverage (DR site + cloud + tape vault)
  • 100% air-gapped backup coverage (tape rotation)
  • CBS backup failure rate: 2% (down from 30%)
  • DR site: real-time replication (RPO: 15 minutes, RTO: 2 hours)
  • 100% automated backup testing (weekly integrity, monthly restore, quarterly DR drill)
  • Zero RBI audit findings related to backup
  • Ransomware recovery capability: tested and validated (8 hours from immutable backup)
  • DR drill completion: 100% (4 drills in 18 months, all passed)
  • Backup overhead optimization: 25% reduction through deduplication and compression
  • Bank received "Best DR Practices" award from Indian Banks' Association

Investment: (Commvault, AWS, DR site upgrade, tape infrastructure, network optimization, consulting, training, audit) ROI: Avoided potential ransomware payment of + crore. Avoided RBI operational restrictions that would have overhead /year. Retained customer trust and regulatory standing. The bank's backup transformation became a model for public sector banks. The investment was essential for regulatory compliance and operational continuity.

Key Lesson: For large, distributed organizations like banks, backup is not just about copying data, it is about ensuring recoverability across thousands of locations, managing network constraints, and meeting regulatory requirements. The RBI's mandate accelerated transformation, but the bank's complete approach (centralized management, immutable backups, real-time DR, automated testing) created a resilient foundation for any future disaster.


Multi-Framework Mapping

ISO 27001:2022 A.8.13 to Other Frameworks

ISO 27001:2022 A.8.13NIST 800-53 Rev 5PCI DSS v4.0SOC 2 CC6.1CIS Controls v8COBIT 2019
Information backupCP-9 (Information System Backup)Req 12.3.1 (Backup Procedures)CC6.1 (System Operations)CIS 11.1 (Establish Maintain Data Recovery Process)DSS05.04 (Manage Physical Security)
Backup testingCP-9 (b)Req 12.3.1CC6.1CIS 11.2 (Perform Automated Backups)DSS05.04
Off-site storageCP-9 (c)Req 12.3.1CC6.1CIS 11.3 (Protect Recovery Data)DSS05.04
Immutable backupCP-9 (d)Req 12.3.1CC6.1CIS 11.4 (Test Data Integrity)DSS05.04
DR planningCP-10 (Information System Recovery and Reconstitution)Req 12.3.1CC6.1CIS 11.5 (Test Restoration)DSS05.04

NIST 800-53 Rev 5:

  • CP-9: Information System Backup, Maps to backup policy, scheduling, testing, and storage
  • CP-10: Information System Recovery and Reconstitution, Maps to DR planning and recovery procedures
  • IR-4: Incident Handling, Maps to backup as part of incident response (ransomware recovery)

PCI DSS v4.0:

  • Requirement 12.3.1: Backup procedures for critical security parameters and systems
  • Requirement 9.5: Physical security for backup media

SOC 2 CC6.1:

  • System operations including backup and recovery

CIS Controls v8:

  • CIS Control 11: Data Recovery, Backup procedures, automated backups, recovery data protection, integrity testing, restoration testing

Regulatory and Industry Context

India-Specific Regulatory Requirements

RBI Cyber Security Framework:

  • Banks must maintain regular backups of critical systems (CBS, payment systems, customer data)
  • Backups must be tested quarterly for critical systems
  • Off-site backups mandatory for all critical systems
  • Backup retention: 7 years for transaction data, 5 years for KYC data
  • Ransomware-resistant backups (immutable or air-gapped) recommended
  • Annual cyber audit must review backup practices, testing, and recovery capabilities
  • DR site must have current data and tested failover procedures

SEBI Cybersecurity Circular:

  • Trading systems must have real-time or near-real-time backup
  • DR site must have RPO <= 15 minutes for trading systems
  • DR drill must be conducted annually for trading systems
  • Backup and DR must be tested before major market events (IPOs, large listings)
  • Annual compliance audit must include backup and DR review

IRDAI Guidelines:

  • Insurance core systems must have regular backups with defined RPO and RTO
  • Customer data must be backed up and recoverable
  • DR site must be maintained for business continuity
  • Backup testing must be conducted at least annually

CERT-In Guidelines:

  • Organizations must maintain backups as part of cyber resilience
  • Backups should be immutable or air-gapped to protect against ransomware
  • Organizations should test backup restoration regularly
  • Backup is part of the incident response plan for ransomware

Company Act 2013:

  • Companies must maintain books and records (electronic or physical)
  • Electronic records must be backed up and recoverable
  • Auditor access to electronic records requires backup availability

IT Act 2000 (as amended):

  • Section 43A: Reasonable security practices include backup and recovery for sensitive data
  • Section 79: Intermediaries must maintain data and systems, including backup

Industry-Specific Context

BFSI:

  • RBI mandates backup and DR for all critical banking systems
  • CBS backup failure is a critical RBI audit finding
  • Core banking DR must have RPO <= 1 hour and RTO <= 4 hours
  • Payment systems (UPI, RTGS, NEFT) require real-time backup and DR
  • Trading systems require sub-minute RPO and sub-hour RTO
  • Customer data backup must be encrypted and access-controlled
  • Ransomware-resistant backup is a top priority for banks
  • Public sector banks face additional scrutiny from RBI and Ministry of Finance

Healthcare:

  • NABH requires backup and DR for patient data systems
  • EMR data must be backed up with RPO <= 4 hours and RTO <= 8 hours
  • Medical images (PACS) require large-scale backup (petabytes)
  • Patient data backup must be encrypted and HIPAA-equivalent (DPDP Act)
  • Telemedicine data must be backed up (video recordings, chat logs)
  • Research data must be backed up with long-term retention
  • Health data backup must be immutable for ransomware protection
  • NABH accreditation requires DR drill evidence

Government/Defense:

  • Government records must be backed up per the Public Records Act
  • Citizen data portals must have DR capabilities
  • Classified data backup requires air-gapping and physical security
  • Defense systems require backup with strict access controls
  • RTI data must be backed up and accessible
  • Election data must be backed up with immutable storage
  • Aadhaar data backup must follow UIDAI guidelines
  • Government exam portals must have DR for high-traffic events

SaaS/Cloud:

  • Multi-tenant SaaS must back up customer data with tenant isolation
  • Cloud-native systems must use cloud backup services (AWS Backup, Azure Backup)
  • SaaS providers must offer backup SLAs to customers
  • Customer data must be backed up across multiple regions
  • API and configuration data must be backed up (not just customer data)
  • SOC 2 and ISO 27001 require backup and DR evidence
  • Customer audit rights often require backup and DR documentation
  • Ransomware-resistant backup is essential for SaaS providers

Retail/E-commerce:

  • Customer transaction data must be backed up in real-time or near-real-time
  • Payment data backup must comply with PCI DSS
  • Inventory data must be backed up frequently (hourly or daily)
  • E-commerce platform configurations must be backed up
  • Marketing data and customer lists must be backed up
  • Supplier and licensing data must be backed up
  • Peak season (Diwali, year-end) requires pre-season backup verification

Roles and Responsibilities (RACI)

ActivityCISOIT Operations ManagerBackup AdministratorDBASystem AdminCloud ArchitectDR ManagerData Owner
Policy DevelopmentARCCCCRC
Backup StrategyCRRCCRRC
Backup SchedulingIRRCCCII
Backup ExecutionICRCCCII
Backup MonitoringCRRIIIII
Backup SecurityACRIICII
Off-Site ManagementCRRIICRI
Immutable BackupCRRIICCI
Restore TestingCRRRRCRI
DR PlanningCRCCCCRC
DR DrillCRCRRCRI
RTO/RPO ValidationCRCCCCRR
Incident ResponseARRCCCRI
AuditARCCCCRI
Continuous ImprovementARRCCCRC

Documentation and Evidence Requirements

DocumentPurposeRetention PeriodOwner
Backup PolicyDefines backup requirementsDuration + 3 yearsCISO
Backup ScheduleDocuments all backup jobsDuration + 3 yearsBackup Administrator
Backup LogsEvidence of backup execution1 yearBackup Administrator
Backup Test ReportsEvidence of restore testingDuration + 3 yearsBackup Administrator
DR PlanDocuments disaster recovery proceduresDuration + 3 yearsDR Manager
DR Drill ReportsEvidence of DR testingDuration + 3 yearsDR Manager
RTO/RPO AssessmentEvidence of recovery objectivesDuration + 3 yearsDR Manager
Backup Storage RecordsEvidence of storage locations and capacity1 yearBackup Administrator
Backup Encryption RecordsEvidence of encryption and key managementDuration + 3 yearsCISO
Off-Site Backup RecordsEvidence of off-site storage and rotationDuration + 3 yearsBackup Administrator
Immutable Backup RecordsEvidence of immutable backup configurationDuration + 3 yearsBackup Administrator
Recovery RunbooksStep-by-step recovery proceduresDuration + 3 yearsIT Operations
Audit Checklist and ResultsAudit evidenceDuration + 3 yearsInternal Audit
Risk AssessmentRisk treatment evidenceDuration + 3 yearsCISO
Training RecordsAwareness evidenceDuration + 3 yearsHR

Continuous Improvement

Figure · Tiers

Maturity levels for information backup

  1. OptimizedAI-powered backup optimization
  2. ManagedAutomated backups; automated testing
  3. DefinedFormal policy; scheduled backups
  4. DevelopingSome backups; informal scheduling
  5. InitialNo backup policy; ad-hoc backups
Where most organisations sit, and what the next level asks for. Full characteristics per level are in the table below.

Maturity Model for A.8.13

LevelNameCharacteristicsEvidence
1InitialNo backup policy; ad-hoc backups; no testing; no off-site; no monitoring; no DR; backup failures unnoticedNo policy; no schedule; no testing; no off-site; no monitoring; no DR plan
2DevelopingSome backups; informal scheduling; occasional testing; no off-site; basic monitoring; no DR; manual processesPartial backups; informal schedule; rare testing; no off-site; basic monitoring; no DR
3DefinedFormal policy; scheduled backups; regular testing; off-site storage; monitoring; DR plan; documented procedures; encryptionPolicy; schedule; monthly testing; off-site; monitoring; DR plan; procedures; encryption; quarterly DR drill
4ManagedAutomated backups; automated testing; immutable backups; cloud backup; DR drills; metrics-driven; RTO/RPO validated; centralized management; overhead optimizationAutomation; immutable; cloud; quarterly DR drills; metrics; validated RTO/RPO; centralized; overhead optimization
5OptimizedAI-powered backup optimization; self-healing backups; predictive failure detection; autonomous DR; zero RPO for critical systems; continuous testing; fully integrated BC/DR; immutable by default; air-gapped as standardAI optimization; self-healing; predictive detection; autonomous DR; zero RPO; continuous testing; integrated BC/DR; immutable default; air-gapped standard

Continuous Improvement Activities

Monthly:

  • Backup success rate review and trend analysis
  • Backup failure investigation and remediation
  • Backup storage capacity review
  • Backup integrity check review
  • Backup overhead analysis and optimization
  • Off-site backup rotation verification

Quarterly:

  • Backup policy review
  • Backup test restore execution and review
  • Immutable backup verification
  • DR site data currency verification
  • Cloud backup performance review
  • Backup encryption and key management review
  • Internal audit of backup controls
  • RTO/RPO assessment and validation

Annually:

  • Full backup policy review
  • Complete DR drill (full failover, restore, failback)
  • Technology evaluation (new backup tools, new cloud services)
  • Benchmark against industry best practices
  • External audit preparation
  • Maturity assessment against target level
  • Vendor security assessment (backup software vendors, cloud providers)
  • BC/DR plan integration review
  • Regulatory compliance review (RBI, SEBI, DPDP Act updates)

Trigger-Based:

  • After any data loss incident or ransomware attack
  • After any failed restore or backup corruption
  • Upon new system or application introduction
  • Upon significant infrastructure change (cloud migration, data center move)
  • After any DR drill or test
  • Upon new regulatory requirement
  • After significant audit findings
  • Upon merger, acquisition, or divestiture
  • After industry peer incident ("could this happen to us?")

FAQ

Q1: What is the difference between backup and disaster recovery? A: Backup is the process of copying data to protect against loss. Disaster Recovery (DR) is the process of restoring systems and operations after a catastrophic event. Backup is the "what" (data protection); DR is the "how" (recovery execution). You need both: backup provides the data, and DR provides the plan and infrastructure to use that data. Backup without DR is like having a spare tire but no jack. DR without backup is like having a jack but no spare tire.

Q2: How often should we test our backups? A: At minimum: daily automated integrity checks, weekly file-level restore tests, monthly database and VM restore tests, quarterly full system restore tests and off-site restore tests, and annual DR drills. More frequent testing is better. Critical systems should be tested monthly. After any infrastructure change, test immediately. The only way to know a backup works is to restore from it. Testing is not optional, it is the most important part of backup.

Q3: What is the 3-2-1-1 backup rule, and why is the extra "1" important? A: The 3-2-1 rule: 3 copies of data, on 2 different media types, with 1 copy off-site. The extra "1" in 3-2-1-1 is 1 immutable or air-gapped copy. The extra "1" is critical because ransomware and sophisticated attackers can destroy or encrypt all online backups. An immutable or air-gapped backup cannot be modified, providing a last-resort recovery option. For 2024 and beyond, 3-2-1-1 is the minimum standard, not 3-2-1. The extra "1" is your ransomware insurance policy.

Q4: Should we use tape backup in the cloud era? A: Yes, tape remains relevant for specific use cases: (1) Air-gapped backup (tape is naturally offline when not in the drive), (2) Long-term archive (7+ years retention), (3) efficient bulk storage (tape is cheaper than disk for long-term), (4) Ransomware protection (tape is immune to network-based ransomware), (5) Compliance (some regulators prefer tape for audit trails). However, tape is slow for restore, requires physical handling, and needs environmental control. Best practice: Use disk/cloud for operational recovery (fast), and tape for archive and air-gapped backup (secure). Tape is not dead, it is a specialized tool in the backup toolkit.

Q5: What is the most common audit finding for A.8.13? A: The most common findings are: (1) No backup testing (backups never restored), (2) No off-site backup, (3) No immutable backup, (4) Backup failure not addressed, (5) No DR plan, (6) No DR drill conducted, (7) RTO and RPO not defined or validated, (8) Backup on same network as production, (9) No backup encryption, (10) No backup monitoring. Auditors will check backup schedules, test results, DR plans, drill reports, and storage locations.

Q6: How do we handle backup for cloud-native systems (containers, serverless, microservices)? A: Cloud-native backup requires cloud-native tools: (1) Use cloud provider backup services (AWS Backup, Azure Backup, GCP Backup) for IaaS/PaaS, (2) Use container image registries with backup for container images, (3) Use configuration management tools (Terraform, Ansible) with state backup for infrastructure, (4) Use Git for code and configuration backup (with repository backup), (5) Use database backup tools for cloud databases (RDS automated backups, Cloud SQL backups), (6) Use object storage versioning and replication for S3/Blob buckets, (7) Use Kubernetes etcd backup for cluster state. Cloud-native systems are ephemeral, backup the data, configuration, and state, not just the running instances.

Q7: What is the impact of implementing A.8.13 for a growing company? A: For a company with 50 servers and 200 endpoints: Backup software (Veeam or similar, –/year), backup storage (on-premise NAS + cloud, –/year), tape or immutable storage (–/year), cloud backup (–/year), SaaS backup (–/year), DR infrastructure (warm standby or cloud DR, –/year), consulting (–), training (–). Total: –/year. The impact of a data loss incident for a growing company is –50 crore. Backup is one of the highest-ROI security investments. The impact of not backing up is far higher than the impact of backing up.

Q8: How do we handle backup for large databases (terabytes or petabytes)? A: Large databases require specialized backup approaches: (1) Use incremental backups with block-level change tracking (reduces backup time), (2) Use database-native backup tools (Oracle RMAN, SQL Server Backup, PostgreSQL pg_basebackup) for efficiency, (3) Use snapshot-based backup for storage-level consistency, (4) Use parallel backup streams to maximize throughput, (5) Use deduplication to reduce storage (essential for large databases), (6) Use compression to reduce transfer time and storage, (7) Use dedicated backup network to avoid production impact, (8) Use cloud tiering for older backups (hot storage for recent, cold storage for old), (9) Use database replication for near-zero RPO (not a substitute for backup, but complementary). Large database backup is an engineering challenge, plan for capacity, bandwidth, and time.

Q9: How do we balance backup frequency with production impact? A: Backup impact on production can be minimized: (1) Use incremental backups (faster than full), (2) Use application-aware backup (VSS for Windows, quiescing for databases) to ensure consistency without downtime, (3) Use snapshots (near-instant, minimal impact), (4) Schedule backups during low-usage periods (nights, weekends), (5) Use dedicated backup network (isolated from production traffic), (6) Use throttling to limit backup bandwidth, (7) Use changed block tracking (CBT) to minimize data transfer, (8) Use storage-level replication (offloads backup from application servers). The goal is to protect data without disrupting business. Modern backup tools are designed to minimize impact, use their features.

Q10: What is the relationship between backup and business continuity planning (BCP)? A: Backup is a component of BCP, but BCP is broader. BCP includes: (1) Backup and recovery (data restoration), (2) Disaster recovery (system restoration), (3) Business processes (how to operate during disruption), (4) Communication (internal and external communication during crisis), (5) Personnel (who does what during disruption), (6) Facilities (alternative work locations), (7) Supply chain (alternative suppliers and logistics), (8) Crisis management (leadership decision-making during crisis). Backup provides the data foundation for BCP, but BCP requires planning for all aspects of business continuity. Do not confuse having backups with having a BCP. Backup is necessary but not sufficient for business continuity.

Q11: How do we handle backup for remote and branch offices? A: Remote and branch office backup requires: (1) Local backup appliance at each branch (for fast local recovery), (2) Replication to central data center or cloud (for DR), (3) Bandwidth optimization (deduplication, compression, WAN acceleration), (4) Backup scheduling that accommodates limited bandwidth (nights, weekends, incremental only), (5) Cloud backup as primary for small branches (no local infrastructure), (6) Centralized management (manage all branch backups from HQ), (7) Remote testing capability (test restores without shipping media). For banks with 3,000 branches, branch backup is a major challenge, use appliances with local caching, deduplication, and cloud replication.

Q12: How do we handle backup for mobile devices and BYOD? A: Mobile and BYOD backup requires: (1) Mobile device backup via MDM (backup corporate data, not personal data), (2) Containerization (backup only the corporate container, not the entire device), (3) Cloud sync for corporate apps (Office 365, Google Drive corporate), (4) Endpoint backup tools for laptops (Veeam Endpoint, Acronis), (5) Remote wipe capability for lost/stolen devices, (6) Backup of mobile app configurations and data, (7) Separate backup policies for BYOD vs. corporate devices. BYOD backup is tricky, respect user privacy while protecting corporate data. Backup corporate data only, with user consent and transparency.

Q13: What is the difference between backup and archiving? A: Backup is for recovery (restoring data after loss or corruption). Archive is for long-term retention (keeping data for compliance, legal, or historical purposes). Backup is active and operational; archive is passive and historical. Backup is typically stored on fast, accessible storage for quick recovery. Archive is typically stored on slow, cheap storage (tape, cold cloud) for long-term retention. Backup retention is short (days to months); archive retention is long (years to decades). Backup data is current; archive data is historical. Both are necessary but serve different purposes. Do not use archive as backup (too slow for recovery) or backup as archive (too premium-tier for long-term).

Q14: How do we handle backup when migrating to cloud or changing infrastructure? A: Infrastructure changes require backup planning: (1) Before migration: ensure current backups are complete and tested, (2) During migration: maintain backup of both source and destination until migration is verified, (3) After migration: implement new backup for cloud infrastructure, (4) Test new backup immediately after migration, (5) Update DR plan to reflect new infrastructure, (6) Retain old backups until new backups are validated, (7) Update backup runbooks and procedures, (8) Train staff on new backup tools and procedures. Never migrate without a verified backup. Migration is a high-risk period for data loss, backup is your safety net.

Q15: What is the future of backup? A: Backup is evolving rapidly: (1) AI-powered backup optimization (predictive scheduling, anomaly detection, self-healing), (2) Immutable backup as default (all backups protected against ransomware by design), (3) Continuous data protection (CDP) for near-zero RPO, (4) Backup as a service (BaaS), fully managed backup without infrastructure, (5) Integration with SASE and Zero Trust (backup as part of unified security architecture), (6) Blockchain verification for backup integrity (proof that backup has not been tampered with), (7) Instant recovery (boot directly from backup without restore), (8) Backup-driven dev/test (use backup copies for development and testing). The future of backup is intelligent, immutable, instant, and integrated.


References and Further Reading

Standards and Frameworks

  • ISO/IEC 27001:2022, Information Security, Cybersecurity and Privacy Protection, Information Security Management Systems, Requirements
  • ISO/IEC 27002:2022, Information Security, Cybersecurity and Privacy Protection, Information Security Controls
  • NIST SP 800-53 Rev 5, Security and Privacy Controls for Information Systems and Organizations
  • PCI DSS v4.0, Payment Card Industry Data Security Standard
  • CIS Controls v8, CIS Controls Version 8
  • COBIT 2019, Control Objectives for Information and Related Technologies
  • ISO 22301:2019, Security and Resilience, Business Continuity Management Systems

Indian Regulations

  • RBI Cyber Security Framework for Banks
  • SEBI Circular CIR/ISD/2019 on Cyber Security and Cyber Resilience
  • CERT-In Guidelines for Information Security Practices
  • Information Technology Act, 2000 (as amended)
  • Digital Personal Data Protection Act, 2023 (India)
  • Company Act, 2013

Books and Publications

  • ISO 27001/27002: A Pocket Guide by Alan Calder
  • Backup & Recovery: Inexpensive Backup Solutions for Open Systems by W. Curtis Preston
  • Disaster Recovery Planning: Preparing for the Unthinkable by Jon William Toigo
  • The Backup Book: Disaster Recovery from Desktop to Data Center by Dorian Cougias
  • Veeam Best Practices Guide (Veeam)

Backup Resources

How Singahi can help

Singahi is one team for compliance, assessment and managed security. We help growing companies implement and certify ISO 27001:2022, and stay secure afterward.


Continue the toolkit

How we can help

Working toward this?

If a certification or a customer's security questionnaire is what brought you here, tell us where you are. We'll give you an honest read on the work and the timeline, with no obligation.

What happens next

  1. Tell us the trigger

    A questionnaire, an audit date or an investor ask. The short form or a call both work.

  2. A practitioner replies

    A senior practitioner, not a bot, within four business hours.

  3. You get a scoped next step

    An honest view of what the work involves. No pressure, no theatre.