Security Questionnaire Mapper
Incident and continuity ยท question family

Backup and disaster recovery: the clause the question tests

Whether the customer's data can be recovered, how recent the copy is and how fast it comes back.

How the customer usually asks it

example

"How often are backups taken, and when was a restore last tested?"

Read this question

Anchor clauses

7 frameworks
FrameworkAnchor clause
ISO/IEC 27001:20228.13 Information backup
SOC 2 (Trust Services Criteria)A1.2 Environmental protections, data backups, and recovery infrastructure support availability
SIG (Shared Assessments)domain K Business Resiliency
CSA Cloud Controls Matrix v4.0.1BCR-08 Backup
NIST Cybersecurity Framework 2.0PR.DS-11 Backups of data are created, protected, maintained, and tested
NIST SP 800-53 Rev 5CP-9 System backup
HIPAA Security Rule (45 CFR 164)164.308(a)(7)(ii)(A) Data Backup Plan (Required)

Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.

Evidence expected

The backup schedule and retention, where backups are held and how they are protected, and the record of the last restore test with its result.

The clauses, with what an assessor asks for

ISO 27001 8.13 Information backup

Maintain and regularly test backups of information, software and systems per the backup policy.

Evidence an assessor expects: Backup policy; Backup schedule; Backup test reports; Retention records; Access logs
Where answers usually fall short: Infrequent restore testing; Missing retention documentation
Source: ISO/IEC 27001:2022
SOC 2 A1.2 Environmental protections, data backups, and recovery infrastructure support availability

Named, not quoted: the criteria text is not held in full here.

Evidence an assessor expects: Evidence of environmental protections at the facilities in scope, covering fire detection and suppression, power continuity, cooling and water detection, with testing and maintenance records; The backup configuration showing scope, frequency and retention against the recovery point objective; Evidence of protection of backup data, including encryption, access restriction and an immutable or offline copy; Evidence of the recovery infrastructure, including alternative processing capability and its readiness; Evidence these are authorised, approved, maintained and monitored, including who approved the design
Where answers usually fall short: Backups configured with failures reported and never investigated, so gaps in the backup set are unknown; Backups reachable using production credentials, so a single compromise destroys both
Source: SOC 2 (Trust Services Criteria)
SIG domain K Business Resiliency

What it asks for, in one line (the standard's own text is not quoted here):

Maintain business continuity and disaster recovery programs including business impact analysis, recovery objectives, plans, periodic testing, and dependencies on third party providers.

Evidence an assessor expects: Business impact analysis with RTO and RPO; Approved BCP and DR plans; Annual test reports; Supplier dependency map
Where answers usually fall short: RTO and RPO not validated against tested recovery; Critical supplier failover untested
Source: SIG (Shared Assessments)
CSA CCM BCR-08 Backup

What it asks for, in one line (the standard's own text is not quoted here):

Back up cloud-held data on a defined cycle, protect the confidentiality and integrity of the backups, and prove by restore testing that the data can actually be recovered.

Evidence an assessor expects: Backup schedules and job success records; Backup encryption and access control configuration; Restore test results with date, scope and outcome; Retention settings matched to the recovery point objective
Where answers usually fall short: Backups running successfully but never restore tested; Backups readable by the same credentials that could destroy production
Source: CSA Cloud Controls Matrix v4.0.1
NIST CSF PR.DS-11 Backups of data are created, protected, maintained, and tested

Backups of data are created, protected, maintained, and tested.

Evidence an assessor expects: Backup policy with frequency and retention; Backup integrity test reports; Immutable backup configuration evidence; Restoration test records with success criteria; Backup access control and audit logs
Where answers usually fall short: Restoration tests narrow in scope; Immutability not configured on all critical systems
Source: NIST Cybersecurity Framework 2.0
SP 800-53 CP-9 System backup

Requires backups of user-level information, system-level information and system documentation including security and privacy documentation, each at an organization-defined frequency, and requires the confidentiality, integrity and availability of the backup information itself to be protected.

Evidence an assessor expects: Backup schedule and success reports covering user-level, system-level and documentation backups; Encryption and access control configuration protecting backup data; Restore test records proving backups are usable; Defined backup frequencies and evidence they are met
Where answers usually fall short: Documentation and configuration backed up nowhere, only application data; Backups unencrypted or reachable with the same credentials as production, so ransomware takes both
Source: NIST SP 800-53 Rev 5
HIPAA 164.308(a)(7)(ii)(A) Data Backup Plan (Required)

Establish procedures to create and maintain retrievable exact copies of ePHI. NIST recommends offline or immutable backups, encryption, and regular restoration testing.

Evidence an assessor expects: Backup policy and schedule; Backup completion logs; Restoration test results; Immutable or offline backup evidence
Where answers usually fall short: Backups exist but never restored; No air-gapped or immutable copy for ransomware
Source: HIPAA Security Rule (45 CFR 164)

Other families in incident and continuity