Backup and disaster recovery: the clause the question tests
Whether the customer's data can be recovered, how recent the copy is and how fast it comes back.
How the customer usually asks it
example"How often are backups taken, and when was a restore last tested?"
Anchor clauses
7 frameworks| Framework | Anchor clause |
|---|---|
| ISO/IEC 27001:2022 | 8.13 Information backup |
| SOC 2 (Trust Services Criteria) | A1.2 Environmental protections, data backups, and recovery infrastructure support availability |
| SIG (Shared Assessments) | domain K Business Resiliency |
| CSA Cloud Controls Matrix v4.0.1 | BCR-08 Backup |
| NIST Cybersecurity Framework 2.0 | PR.DS-11 Backups of data are created, protected, maintained, and tested |
| NIST SP 800-53 Rev 5 | CP-9 System backup |
| HIPAA Security Rule (45 CFR 164) | 164.308(a)(7)(ii)(A) Data Backup Plan (Required) |
Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.
Evidence expected
The backup schedule and retention, where backups are held and how they are protected, and the record of the last restore test with its result.
The clauses, with what an assessor asks for
ISO 27001 8.13 Information backupMaintain and regularly test backups of information, software and systems per the backup policy.
Where answers usually fall short: Infrequent restore testing; Missing retention documentation
Source: ISO/IEC 27001:2022
SOC 2 A1.2 Environmental protections, data backups, and recovery infrastructure support availabilityNamed, not quoted: the criteria text is not held in full here.
Where answers usually fall short: Backups configured with failures reported and never investigated, so gaps in the backup set are unknown; Backups reachable using production credentials, so a single compromise destroys both
Source: SOC 2 (Trust Services Criteria)
SIG domain K Business ResiliencyWhat it asks for, in one line (the standard's own text is not quoted here):
Maintain business continuity and disaster recovery programs including business impact analysis, recovery objectives, plans, periodic testing, and dependencies on third party providers.
Where answers usually fall short: RTO and RPO not validated against tested recovery; Critical supplier failover untested
Source: SIG (Shared Assessments)
CSA CCM BCR-08 BackupWhat it asks for, in one line (the standard's own text is not quoted here):
Back up cloud-held data on a defined cycle, protect the confidentiality and integrity of the backups, and prove by restore testing that the data can actually be recovered.
Where answers usually fall short: Backups running successfully but never restore tested; Backups readable by the same credentials that could destroy production
Source: CSA Cloud Controls Matrix v4.0.1
NIST CSF PR.DS-11 Backups of data are created, protected, maintained, and testedBackups of data are created, protected, maintained, and tested.
Where answers usually fall short: Restoration tests narrow in scope; Immutability not configured on all critical systems
Source: NIST Cybersecurity Framework 2.0
SP 800-53 CP-9 System backupRequires backups of user-level information, system-level information and system documentation including security and privacy documentation, each at an organization-defined frequency, and requires the confidentiality, integrity and availability of the backup information itself to be protected.
Where answers usually fall short: Documentation and configuration backed up nowhere, only application data; Backups unencrypted or reachable with the same credentials as production, so ransomware takes both
Source: NIST SP 800-53 Rev 5
HIPAA 164.308(a)(7)(ii)(A) Data Backup Plan (Required)Establish procedures to create and maintain retrievable exact copies of ePHI. NIST recommends offline or immutable backups, encryption, and regular restoration testing.
Where answers usually fall short: Backups exist but never restored; No air-gapped or immutable copy for ransomware
Source: HIPAA Security Rule (45 CFR 164)