ISO 27001 Backup Policy Beginner’s Guide

Home / ISO 27001 Templates / ISO 27001 Backup Policy Beginner’s Guide

In this article we lay bare the ISO 27001 Backup Policy. Exposing the insider trade secrets, giving you the templates that will save you hours of your life and showing you exactly what you need to do to satisfy it for ISO 27001 certification. We show you exactly what changed in the ISO 27001:2022 update. I am Stuart Barker the ISO 27001 Ninja and this is the ISO 27001 Backup Policy.

What is a backup policy?

A backup policy is designed to protect you from the loss of data or the corruption of data due to malware and ransomeware.

It sets out the organisations approach to backups and ensures that adequate processes and procedures are in place as well as regular testing of the backup so that we can be sure that when the time comes and if we need it, we can recover it.

What is a data backup

Data backup is the process of taking an exact copy of the data at a point in time so that if you need to restore it you can restore it and return to it as it was at that point in time.

Define Backup

The backup should be defined. We want to know what we are backing up and how often. Backup is not just of data files but consider the backup of system configuration files, virtual machines, databases, websites, photographs – in fact anything that you rely on or would harm you if you no longer had it. When deciding how often to backup it is a question of how much update and changes can you accept to loose? If you only back up once a week then you potentially have a week of data that will be missing and may need recreating. Can you accept loosing a weeks worth of data? Based on circumstance, but the more often you can backup, the better.

Backup and restoration

It is important to have documented processes and procedures for backing up and restoring data. Having documented processes enables us to ensure the control is in place and effective. We want and need the knowledge to be written down so that if when the time comes, if the person that normally performs the backup and restoration is not available we can still recover.

Encrypted backup

Should backup be encrypted? Yes. Most definitely. Backup is one of the weakest areas for security control. It maybe that it is held on removable media, offsite, in a remote location. There are many variables that can present a risk to backup. To mitigate that risk we want to encrypt our backup so that if the backup is compromised it is to all intents and purposes, worthless.

Backup policy

The purpose of the backup policy is to protect against loss of data. Information is backed up securely in line with the data retention requirements, business requirements and legal and all legal and regulation legislation requirements including but not limited to the GDPR and Data Protection Act 2018. Backup and restoration procedures are documented, in place and maintained. Backups are encrypted using vendor built in encryption.

In the process documents and in the processes we ensure that the backups are tested regularly to ensure they are effective.

What ever you do, back up your data

I think it’s fair to say that data is our most important asset.

Let’s be honest we have so much of it. In our personal lives we’re creating data daily in photographs and posts and emails and then in business we have all that valuable customer data, intellectual property coma even the emails and communications that we send.

Every piece of data that we have has a value.

The question that we always ask ourselves is – what if I lost this data?

It doesn’t really become a problem until the fateful day comes when you do lose the data and suddenly your entire world collapses.

I’ve been in information security now for over 20 years and with all the changes that have come there are still only a handful of things that we recommend that people do, not matter what. Pretty near the top of that list is ensuring that we back up our data.

Information security is about the confidentiality, integrity, and availability of data. That third tenant availability is so often overlooked.

Nearly all the information security standards from ISO 27001 to SOC 2 will have a requirement for backing up data and ensuring the security of that backup.

So, my top tips when it comes to backing up data are

  • Have a back up policy
  • Identify the information that is the most important to you
  • Ensure that that data is adequately backed up

There are things that you can do that will help you to identify what kind of a backup you should be doing around that data. A great tip is to conduct a business impact analysis. This will identify the key systems and key data for your organisation, and it will include working out what is the longest time that you can go without data and what is the last recovery point in terms of time that you can afford to lose.

If you’re only backing up once a week then you have to consider that potentially you will lose up to six days’ worth of information. If you’re backing up every day then you’re going to potentially lose up to 23 hours of new data.

ISO 27001 Backup Policy Template

ISO 27001 Backup Policy Template

How to write a backup policy

You could always write your own backup policy. Give yourself about 4 hours and follow these simple steps.

Time needed: 4 hours

How to write a backup policy

  1. Create your version control and document mark-up

    ISO 27001 documents require version control of the author, the change, the date and the version as well as document mark up such as document classification.

  2. Write the document purpose

    Write the purpose of the document. The purpose of this policy is to protect against loss of data.

  3. Write the scope of the policy

    Company owned, managed and controlled information and systems that form part of systems and applications deemed in scope by the ISO 27001 scope statement including:
    • Servers
    • Databases
    • Code Repositories
    • Test Environments
    • Development Environments
    Out of scope for back up:
    • Desktop
    • Laptop
    • Mobile Device

  4. Write the principle on which the policy is based

    Information is backed up securely in line with the data retention requirements, business requirements and legal and all legal and regulation legislation requirements including but not limited to the GDPR and Data Protection Act 2018.

  5. Write the content for the required sections

    Backup Restoration Procedures
    Backup Security
    Backup Schedule
    Backup Testing and Verification
    Policy Compliance
    Compliance Measurement
    Continual Improvement

Backup FAQ

How often should I perform a backup?

As often is required. The requirement is based on the risk associated with the loss of the data. To understand this structurally you would perform a business impact assessment and record what is the maximum amount of data you are prepared to loose. Factors such as costs, losses, effort to recreate data come in to play. For most people a daily backup would suffice.

How long should I keep backups?

For as long as is necessary. You define this based on the usefulness of the data and legal and regulatory factors. Having a set of back ups that cover the last 12 months for most people would suffice.

What is the best strategy for a backup?

Usually having a daily backup, the last 7 days backed up, the last month backed up and the last year backed up in a rolling backup strategy.

Should I encrypt backups?