ISO 27001 Annex A 8.13 is a documented process for maintaining backup copies of information and systems. Organisations must integrate these procedures into daily operational tools like SharePoint. This ensures data availability after technical failures. It mandates regular testing within your internal document management systems.
Table of contents
Key Takeaways
- Maintain Backup Procedures: Keep clear, written rules for creating and managing regular backup copies of company data and systems.
- Ensure Data Availability: Store extra copies of essential files so your business can recover quickly after hardware failures or system crashes.
- Integrate Daily Work Tools: Connect backup rules directly into your regular document storage systems to protect files automatically.
- Test Backups Regularly: Run periodic recovery tests to prove that saved files open correctly and restore without data loss.
- Secure Backup Storage: Encrypt all backup files and store copies off-site or in secure cloud locations to prevent theft.
- Define Retention Timelines: Set clear rules for how long your team keeps old backup files to meet business and legal needs.
- Monitor Backup Logs: Check system logs daily to spot failed backups immediately and resolve technical errors fast.
How to implement ISO 27001 Annex A 8.13
- Draft a Clear Backup Policy: Write a standard policy that sets clear rules for how often to copy company data and systems.
- Set Recovery Goals: Define exact timelines for how long to keep files and how fast teams must restore data after an outage.
- Set Up Automated Tasks: Use work tracking tools to schedule regular checks and reminders for backup checks.
- Log Weekly Success Rates: Require IT staff to log backup results each week to spot failed tasks early.
- Run Bi-Annual Restore Tests: Perform a full data recovery test every six months to verify that saved files work properly.
- Document Test Results: Keep detailed records of each restore test to show audit proof that recovery steps work.
- Report to Management: Share regular backup health reports with leaders during monthly team meetings.
- Protect Off-Site Backups: Store extra backup copies in a separate, secure location to protect against site disasters.
How to audit ISO 27001 Annex A 8.13
- Audit Policy Alignment: Check the written backup policy to ensure it sets clear schedules, keep times, and strong file encryption rules.
- Verify Recovery Targets: Check recovery time and data loss limits to make sure they match business needs.
- Inspect Automated Scheduling: Check automated task lists and schedules to confirm backup jobs run on time.
- Sample Weekly Backup Logs: Review recent backup logs to ensure all jobs finished and staff fixed any errors quickly.
- Inspect Restore Test Evidence: Review notes from the last six month recovery test to prove files restored without errors.
- Review Remediation Records: Check issue logs to confirm staff logged, tracked, and fixed any backup test failures.
- Verify Management Oversight: Check monthly meeting notes to confirm leaders regularly review backup status reports.
- Assess Off-Site Controls: Ensure extra backup copies sit in a separate, locked location with rules that stop ransomware from editing files.
- Check Access Permissions: Verify that only approved IT staff have key access to open or edit backup files.
- Confirm Incident Response Links: Ensure teams know how to report and handle backup failures during a real system crash.
Audit Evidence Checklist
- Backup Policy Document: Show a current written backup policy with a clear file history to prove periodic team reviews.
- Restore Test Logs: Provide completed support tickets that record the date, method, and results of your recovery tests.
- Management Meeting Minutes: Supply notes from monthly leader meetings that show routine reviews of backup health reports.
- Technical Setup Guides: Share internal documentation that outlines your standard backup setup rules and safety settings.
- Off-Site Vendor Reports: Present service reports from external cloud or storage providers to prove secondary copy safety.
- Staff Training Records: Keep proof that technical teams completed lessons on managing and testing backup systems safely.
- Incident Tracking Logs: Maintain records of past backup job errors to show how quickly staff resolved technical failures.
What to Teach Employees
- Save to Approved Locations: Teach staff to store work files in core company folders so automated tools back up their work.
- Avoid Local Storage: Explain why saving files only to local computer desktops leaves data unprotected if hardware breaks.
- Know Recovery Rules: Ensure teams understand backup schedules so they know how much work can be restored after errors.
- Report Backup Warnings: Train workers to alert IT right away if backup software displays error alerts or sync failures.
- Understand Ransomware Risks: Show staff how isolated extra file copies act as a top defense against malware attacks.
- Use File History Features: Teach employees how to restore older file versions or deleted items using built-in tool settings.
- Protect Remote Laptops: Remind off-site workers to connect to secure company networks so scheduled backups finish on time.
- Check Active Folder Syncs: Show staff how to verify that key folders sync to cloud storage without stopping.
- Lock Physical Files: Train workers to store paper records in locked cabinets so physical backups stay safe from damage.
Common Implementation Challenges
- Automated Complacency: Caused by relying only on software dashboards without checking manual restore logs. Fix this by keeping clear logs of routine recovery tests in work tracking tools.
- No Management Review: Caused by backup failures that never get reported to leaders. Fix this by adding regular backup status updates to monthly management meeting notes.
- Stale Policies: Caused by backup rules that staff write once and never update. Fix this by reviewing and signing backup policies at least once a year.
- Untested Secondary Copies: Caused by keeping extra off-site backups without testing if they actually open. Fix this by running full restore tests on off-site copies twice a year.
- Missing Scope Controls: Caused by leaving new company devices or cloud folders out of the main backup plan. Fix this by running monthly checks to ensure backup software covers all active systems.
- Unresolved Backup Errors: Caused by technical teams ignoring daily alert warnings. Fix this by setting up automatic tasks that assign every failed job to an IT staff member for quick fixes.
How to Measure Effectiveness (KPIs)
- Backup Success Rate: Measures the percentage of planned backup tasks that finish with zero errors to ensure full system protection.
- Restore Success Rate: Tracks how often file recovery tests restore data completely without missing or damaged records.
- Mean Time to Restore: Measures the average time IT teams need to fully recover lost files or systems after an outage.
- Backup Coverage Rate: Tracks the percentage of company laptops, servers, and cloud databases enrolled in active backup plans.
- Data Loss Target Match: Measures how closely backup schedules match target recovery times so teams avoid losing important work.
- Unbacked Data Incidents: Counts the total times lost files could not be restored due to missing or failed backup setups.
- Failed Backup Resolution Speed: Tracks how fast technical teams investigate, fix, and re-run failed backup jobs.
- Off-Site Sync Compliance: Measures the percentage of secondary off-site backup copies that update on time without errors.
Related ISO 27001 Controls
ISO 27001 Annex A 8.13 connects to several core organisational requirements.
- ISO 27001 Annex A 5.30 manages ICT readiness for business continuity.
- ISO 27001 Annex A 8.15 covers logging activities. All these dependencies must link within your central SharePoint library.
ISO 27001:2022 Attributes
| ISO 27001:2013 Control | ISO 27001:2022 Control | Nature of Change |
|---|---|---|
| A.12.3.1 Information backup | A.8.13 Information backup | Renumbered. Requirement remains to maintain and test backup copies. |


