Controls / Backups
Backups are kept in a secure and resilient way (an isolated, offline or unchangeable copy), and ordinary staff accounts cannot change or delete them
What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: keep a backup copy that is offline, separate or cannot be changed, and that ordinary staff accounts cannot delete.
In Australia
Maturity Level One
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1811 Essential Eight, Maturity Level One | Backups of data, applications and settings are retained in a secure and resilient manner. Required at Maturity Levels One, Two and Three of the Regular backups mitigation strategy (Appendices A, B and C); ISM control ISM-1811 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Evidence backups are stored securely and resiliently (offline, immutable or separate copies); Storage configuration |
| ISM-1812 Essential Eight, Maturity Level One | Unprivileged user accounts cannot access backups belonging to other user accounts. Required at Maturity Levels One, Two and Three of the Regular backups mitigation strategy (Appendices A, B and C); ISM control ISM-1812 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Backup repository permissions showing unprivileged accounts cannot reach other users' backups; Dated record of an assessor's attempt to defeat the setting, with the outcome |
| ISM-1814 Essential Eight, Maturity Level One | Unprivileged user accounts are prevented from modifying and deleting backups. Required at Maturity Levels One, Two and Three of the Regular backups mitigation strategy (Appendices A, B and C); ISM control ISM-1814 in ASD's Essential Eight to ISM mapping (December 2023). The Maturity Level Three table words it: "Unprivileged accounts are prevented from modifying and deleting backups." evidence an assessor asks for Permissions preventing unprivileged accounts modifying or deleting backups; Dated record of an assessor's attempt to defeat the setting, with the outcome |
PCI DSS v4.0.1, when it applies
Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PCI DSS 9.4.1.1 PCI DSS v4.0.1 (add-on) | Secure storage location for offline backups Offline media backups that contain cardholder data must be kept in a secure location. The guidance describes off-site storage, for instance at a commercial storage provider or an alternate or backup site, as good practice, and notes that backups in a non-secured facility could be lost, stolen or copied. Applicability: entities keeping offline backups with cardholder data. Customized approach objective: unauthorized personnel cannot reach offline backups by unauthorized personnel. evidence an assessor asks for Backup media storage procedure naming the secure storage location; Contract and security description for any commercial off-site storage vendor; Tape or disk check-in and check-out logs at the storage site; Access list for the backup storage room or vault |
In the United States
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 11.3 CIS Controls v8.1 | Protect Recovery Data Give recovery data protection equal to that of the original data, drawing on encryption or data separation as the requirements dictate. evidence an assessor asks for Backup encryption configuration showing the algorithm, key management arrangement and access restrictions on backup repositories; Access control list for backup storage and backup consoles, matched against the access list for the source data; Encryption settings for backup media and cloud backup storage, including tape encryption and key custody separate from backup operators; Data classification mapping showing backups of each sensitive data set protected at the same level as production; Access review of backup administrators and service accounts, with removals of staff who no longer need access |
| CIS 11.4 CIS Controls v8.1 | Establish and Maintain an Isolated Instance of Recovery Data Set up and keep a copy of recovery data that is isolated, for example by version-controlling backup targets held off site, in the cloud or offline, whether as systems or as services. evidence an assessor asks for Architecture or configuration record of the isolated backup copy: offline, immutable, air-gapped or versioned off-site or cloud target; Report confirming the isolated copy is current, with its retention and immutability settings and the date of the last successful write; Immutability or object lock configuration on the isolated backup target, with retention period and who can change it; Network and identity separation record showing the isolated copy is not reachable with production domain credentials; Off-site or offline media rotation log with dates, media IDs and custody signatures |
| PR.DS-11 NIST CSF 2.0 | Backups of data are created, protected, maintained, and tested. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect. evidence an assessor asks for Backup policy with frequency and retention; Backup integrity test reports; Immutable backup configuration evidence; Restoration test records with success criteria; Backup access control and audit logs |
PCI DSS v4.0.1, when it applies
Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PCI DSS 9.4.1.1 PCI DSS v4.0.1 (add-on) | Secure storage location for offline backups Offline media backups that contain cardholder data must be kept in a secure location. The guidance describes off-site storage, for instance at a commercial storage provider or an alternate or backup site, as good practice, and notes that backups in a non-secured facility could be lost, stolen or copied. Applicability: entities keeping offline backups with cardholder data. Customized approach objective: unauthorized personnel cannot reach offline backups by unauthorized personnel. evidence an assessor asks for Backup media storage procedure naming the secure storage location; Contract and security description for any commercial off-site storage vendor; Tape or disk check-in and check-out logs at the storage site; Access list for the backup storage room or vault |
In United Kingdom
No requirement in the core list for the United Kingdom covers this control; it is on the schedule as a condition beyond the core list.
PCI DSS v4.0.1, when it applies
Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PCI DSS 9.4.1.1 PCI DSS v4.0.1 (add-on) | Secure storage location for offline backups Offline media backups that contain cardholder data must be kept in a secure location. The guidance describes off-site storage, for instance at a commercial storage provider or an alternate or backup site, as good practice, and notes that backups in a non-secured facility could be lost, stolen or copied. Applicability: entities keeping offline backups with cardholder data. Customized approach objective: unauthorized personnel cannot reach offline backups by unauthorized personnel. evidence an assessor asks for Backup media storage procedure naming the secure storage location; Contract and security description for any commercial off-site storage vendor; Tape or disk check-in and check-out logs at the storage site; Access list for the backup storage room or vault |
Also cited: ISO/IEC 27001:2022 Annex A
A lens in any jurisdiction, never a gap on its own.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.13 ISO/IEC 27001:2022 (lens) | Information backup Backups of information, software and systems are to be kept and tested regularly as the agreed topic-specific backup policy requires. Purpose (stated in ISO/IEC 27002:2022): makes it possible to recover lost data or systems. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.13. evidence an assessor asks for Statement of Applicability entry for control A.8.13, showing inclusion or justified exclusion, implementation status and the risks it treats; The topic-specific backup policy and backup plans stating scope, extent, frequency and retention per system aligned with RPO; Backup job monitoring reports with evidence that failed jobs were investigated and rerun; Restore test records onto test systems, checked against the recovery time in the continuity plan; Evidence of off-site or geographically separate backup storage with suitable physical protection |
Questions
- What does the applicant report for this control?
- Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
- When is it due on the 90-day schedule?
- Day 30 by the default rule (backups), unless it is marked not sure (day 90). The underwriter or broker can move it.
- Does this page check the control?
- No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.