Cyber Insurance Subjectivity Tracker

Controls / Backups

Backups of data, applications and settings run on a schedule set by how critical each system is, and can be restored to a common point in time

What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: back up data, applications and settings on a schedule, so they can be restored to one point in time.

In Australia

Maturity Level One

ClauseThe held text, and the evidence an assessor asks for
ISM-1511
Essential Eight, Maturity Level One

Backups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements. Required at Maturity Levels One, Two and Three of the Regular backups mitigation strategy (Appendices A, B and C); ISM control ISM-1511 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Backup policy setting frequency and retention by business criticality and continuity requirements; Backup job reports matching the policy

ISM-1810
Essential Eight, Maturity Level One

Backups of data, applications and settings are synchronised to enable restoration to a common point in time. Required at Maturity Levels One, Two and Three of the Regular backups mitigation strategy (Appendices A, B and C); ISM control ISM-1810 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Backup schedule showing data, applications and settings synchronised to a common point in time; Restore point catalogue

In the United States

ClauseThe held text, and the evidence an assessor asks for
CIS 11.1
CIS Controls v8.1
Establish and Maintain a Data Recovery Process

Set up and keep a process for recovering data that defines what recovery covers, the order of recovery priorities, and how backup data is kept secure. Revisit the documentation each year, or sooner when a major change in the enterprise could affect this Safeguard.

evidence an assessor asks for Data recovery process document defining recovery scope, recovery priority order and how backup data is secured, with version history; Record of the annual review of the recovery documentation, including changes triggered by major enterprise changes; Recovery priority list mapping business services and their systems to RTO and RPO targets, approved by the service owners; Backup security section of the recovery process covering encryption, access restriction and separation of backup credentials; Change records for major enterprise changes, such as new systems or a data centre move, showing the recovery documentation updated

CIS 11.2
CIS Controls v8.1
Perform Automated Backups

Back up in-scope enterprise assets automatically, at least weekly, with frequency set by how sensitive the data is.

The requirement's own words: at least weekly

evidence an assessor asks for Backup job schedule configuration showing automated backups at least weekly, with frequency mapped to data sensitivity; Backup job success and failure reports for the last 90 days, with failed jobs re-run or remediated; Data classification to backup frequency matrix, such as daily for sensitive databases and weekly for general file shares; Backup coverage report comparing protected systems in the backup tool with the asset inventory; Alerting configuration that notifies the backup team of failed or skipped jobs, with sample alert tickets

PR.DS-11
NIST CSF 2.0

Backups of data are created, protected, maintained, and tested. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

evidence an assessor asks for Backup policy with frequency and retention; Backup integrity test reports; Immutable backup configuration evidence; Restoration test records with success criteria; Backup access control and audit logs

HIPAA Security Rule, when it applies

HIPAA covered entities (health plans, health care clearinghouses, health care providers that transmit health information electronically) and their business associates.

ClauseThe held text, and the evidence an assessor asks for
164.308(a)(7)(ii)(A)
HIPAA Security Rule (add-on)
Data Backup Plan (Required)

Establish procedures to create and maintain retrievable exact copies of ePHI. NIST recommends offline or immutable backups, encryption, and regular restoration testing.

evidence an assessor asks for Backup policy and schedule; Backup completion logs; Restoration test results; Immutable or offline backup evidence

In United Kingdom

No requirement in the core list for the United Kingdom covers this control; it is on the schedule as a condition beyond the core list.

Also cited: ISO/IEC 27001:2022 Annex A

A lens in any jurisdiction, never a gap on its own.

ClauseThe held text, and the evidence an assessor asks for
A.8.13
ISO/IEC 27001:2022 (lens)
Information backup

Backups of information, software and systems are to be kept and tested regularly as the agreed topic-specific backup policy requires. Purpose (stated in ISO/IEC 27002:2022): makes it possible to recover lost data or systems. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.13.

evidence an assessor asks for Statement of Applicability entry for control A.8.13, showing inclusion or justified exclusion, implementation status and the risks it treats; The topic-specific backup policy and backup plans stating scope, extent, frequency and retention per system aligned with RPO; Backup job monitoring reports with evidence that failed jobs were investigated and rerun; Restore test records onto test systems, checked against the recovery time in the continuity plan; Evidence of off-site or geographically separate backup storage with suitable physical protection

Questions

What does the applicant report for this control?
Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
When is it due on the 90-day schedule?
Day 30 by the default rule (backups), unless it is marked not sure (day 90). The underwriter or broker can move it.
Does this page check the control?
No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.

Put this control on a schedule