ISO 27001A.8 — Information backup
A.8.13
Information backup
ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026
Objective
Maintain backup copies of information, software, and systems and test them regularly according to an agreed backup policy.
Points of focus
- Backup scope and schedule
- Encryption and access to backups
- Retention aligned to requirements
- Periodic restore tests
Implementation notes
Automate backups for datastores and critical config. Encrypt and restrict restore roles. Run quarterly restore tests into isolated accounts. Document RPO/RTO targets. Assign a named owner in the SoA, tie operating evidence to backup policy, and sample the control during internal audit before Stage 2 fieldwork.
Audit tip: Show last successful restore test with ticket evidence, not only green backup checkmarks.
Evidence auditors typically request:
- Backup policy
- Backup job success dashboards
- Encrypted backup configuration
- Restore test records with dates
Common gaps
- Backups unencrypted
- Never restored
- Backups in same account without immutability
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.8.13 | This control |
| SOC 2 | A1.2, CC7.5 | Related SOC 2 themes (A1.2, CC7.5) — map in your crosswalk; not identical requirements. |
| GDPR | Article 32 | Related GDPR themes (Article 32) — map in your crosswalk; not identical requirements. |
| HIPAA | §164.308(a)(7) | Related HIPAA themes (§164.308(a)(7)) — map in your crosswalk; not identical requirements. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.8.13)
Frequently Asked Questions
They help availability; backups address corruption and deletion scenarios.
Privileged, logged roles — dual control for large customer restores if risk warrants.
Backups must still honor deletion timelines or document residual retention windows.
Even without owned data centers, information backup still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.
Start with backup policy, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.