Controls / Backups
Administrator accounts (other than the backup administrator) cannot change or delete backups
What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: stop administrator accounts, other than the backup administrator, from changing or deleting backups.
In Australia
Maturity Level Two
Above the target when the underwriter picks Maturity Level One: shown as "above your target level", never a gap.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1705 Essential Eight, Maturity Level Two | Privileged user accounts (excluding backup administrator accounts) cannot access backups belonging to other user accounts. Required at Maturity Levels Two and Three of the Regular backups mitigation strategy (Appendices B and C); ISM control ISM-1705 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Permissions preventing privileged accounts other than backup administrators accessing other users' backups; List of backup administrator accounts |
| ISM-1707 Essential Eight, Maturity Level Two | Privileged user accounts (excluding backup administrator accounts) are prevented from modifying and deleting backups. Required at Maturity Levels Two and Three of the Regular backups mitigation strategy (Appendices B and C); ISM control ISM-1707 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Permissions preventing privileged accounts other than backup administrators modifying or deleting backups; Dated record of an assessor's attempt to defeat the setting, with the outcome |
In the United States
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 11.3 CIS Controls v8.1 | Protect Recovery Data Give recovery data protection equal to that of the original data, drawing on encryption or data separation as the requirements dictate. evidence an assessor asks for Backup encryption configuration showing the algorithm, key management arrangement and access restrictions on backup repositories; Access control list for backup storage and backup consoles, matched against the access list for the source data; Encryption settings for backup media and cloud backup storage, including tape encryption and key custody separate from backup operators; Data classification mapping showing backups of each sensitive data set protected at the same level as production; Access review of backup administrators and service accounts, with removals of staff who no longer need access |
In United Kingdom
No requirement in the core list for the United Kingdom covers this control; it is on the schedule as a condition beyond the core list.
Also cited: ISO/IEC 27001:2022 Annex A
A lens in any jurisdiction, never a gap on its own.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.13 ISO/IEC 27001:2022 (lens) | Information backup Backups of information, software and systems are to be kept and tested regularly as the agreed topic-specific backup policy requires. Purpose (stated in ISO/IEC 27002:2022): makes it possible to recover lost data or systems. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.13. evidence an assessor asks for Statement of Applicability entry for control A.8.13, showing inclusion or justified exclusion, implementation status and the risks it treats; The topic-specific backup policy and backup plans stating scope, extent, frequency and retention per system aligned with RPO; Backup job monitoring reports with evidence that failed jobs were investigated and rerun; Restore test records onto test systems, checked against the recovery time in the continuity plan; Evidence of off-site or geographically separate backup storage with suitable physical protection |
Questions
- What does the applicant report for this control?
- Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
- When is it due on the 90-day schedule?
- Day 30 by the default rule (backups), unless it is marked not sure (day 90). The underwriter or broker can move it.
- Does this page check the control?
- No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.