Backup
A backup is a copy of computer data stored separately from the original so it can be used to restore information if the original is lost or corrupted. Keeping backups in a separate location helps protect against data loss from events such as hardware failure, accidental deletion, or other incidents. In compliance contexts, backups are one of the controls organizations use to support the recoverability and availability of their data.
A backup is a copy of data taken and stored in a location separate from the source system so that the original can be restored following a data loss or corruption event. In SOC 2 examinations, backup controls are typically evaluated where relevant to the selected Trust Services Criteria, most commonly the Availability category and, depending on scope, the Common Criteria (Security), with the auditor assessing the suitability of design (Type I) and, over a defined review period, the operating effectiveness (Type II) of those controls. In an ISO/IEC 27001 ISMS, backup is addressed as a reference control in Annex A and is selected via the Statement of Applicability based on the organization's risk assessment; the specific control designation and grouping depend on the standard edition (for example, the 2013 and 2022 revisions differ in Annex A structure). The presence of backup controls attests only to the copying and recovery capabilities within the defined scope and does not by itself guarantee successful restoration, freedom from data loss, or resilience of systems not covered by the assessment.
Why it matters
Backups are one of the foundational controls organizations rely on to support the recoverability and availability of their data. When original data is lost or corrupted, whether through hardware failure, accidental deletion, or other incidents, a copy stored in a separate location provides a path to restore that information. Without a reliable backup, an otherwise recoverable event can escalate into permanent data loss, making backups a routine focus of both SOC 2 examinations and ISO/IEC 27001 ISMS assessments.
In a SOC 2 context, backup controls are typically evaluated where relevant to the selected Trust Services Criteria, most commonly the Availability category and, depending on scope, the Common Criteria (Security). The distinction between a Type I and Type II report matters here: a Type I assesses only the suitability of the design of backup controls at a point in time, while a Type II assesses both design and operating effectiveness over a defined review period. This means a Type II can provide evidence that backups were actually taken and functioned as intended across the period covered, rather than simply being described on paper.
It is important to recognize the limits of what backup controls attest to. The presence of backup controls attests only to the copying and recovery capabilities within the defined scope of the assessment. It does not by itself guarantee successful restoration, freedom from data loss, or resilience of systems that fall outside the assessed scope. Organizations that treat a passing report or certificate as a guarantee of recoverability misread what these controls demonstrate.
Who it's relevant to
Inside Backup
Common questions
Answers to the questions practitioners most commonly ask about Backup.