Skip to main content
Category: Business Continuity

Backup

Also known as: Data Backup, Data Backup Copy
Simply put

A backup is a copy of computer data stored separately from the original so it can be used to restore information if the original is lost or corrupted. Keeping backups in a separate location helps protect against data loss from events such as hardware failure, accidental deletion, or other incidents. In compliance contexts, backups are one of the controls organizations use to support the recoverability and availability of their data.

Formal definition

A backup is a copy of data taken and stored in a location separate from the source system so that the original can be restored following a data loss or corruption event. In SOC 2 examinations, backup controls are typically evaluated where relevant to the selected Trust Services Criteria, most commonly the Availability category and, depending on scope, the Common Criteria (Security), with the auditor assessing the suitability of design (Type I) and, over a defined review period, the operating effectiveness (Type II) of those controls. In an ISO/IEC 27001 ISMS, backup is addressed as a reference control in Annex A and is selected via the Statement of Applicability based on the organization's risk assessment; the specific control designation and grouping depend on the standard edition (for example, the 2013 and 2022 revisions differ in Annex A structure). The presence of backup controls attests only to the copying and recovery capabilities within the defined scope and does not by itself guarantee successful restoration, freedom from data loss, or resilience of systems not covered by the assessment.

Why it matters

Backups are one of the foundational controls organizations rely on to support the recoverability and availability of their data. When original data is lost or corrupted, whether through hardware failure, accidental deletion, or other incidents, a copy stored in a separate location provides a path to restore that information. Without a reliable backup, an otherwise recoverable event can escalate into permanent data loss, making backups a routine focus of both SOC 2 examinations and ISO/IEC 27001 ISMS assessments.

In a SOC 2 context, backup controls are typically evaluated where relevant to the selected Trust Services Criteria, most commonly the Availability category and, depending on scope, the Common Criteria (Security). The distinction between a Type I and Type II report matters here: a Type I assesses only the suitability of the design of backup controls at a point in time, while a Type II assesses both design and operating effectiveness over a defined review period. This means a Type II can provide evidence that backups were actually taken and functioned as intended across the period covered, rather than simply being described on paper.

It is important to recognize the limits of what backup controls attest to. The presence of backup controls attests only to the copying and recovery capabilities within the defined scope of the assessment. It does not by itself guarantee successful restoration, freedom from data loss, or resilience of systems that fall outside the assessed scope. Organizations that treat a passing report or certificate as a guarantee of recoverability misread what these controls demonstrate.

Who it's relevant to

Compliance and GRC Managers
Those managing a SOC 2 examination or an ISO 27001 ISMS need to understand where backup controls fit within their chosen scope, for SOC 2, typically the Availability category and, depending on scope, the Common Criteria; for ISO 27001, as an Annex A reference control selected via the Statement of Applicability. They should be prepared to demonstrate that these controls exist and, for a Type II report, that they operated effectively over the review period.
Auditors and Certification Bodies
SOC 2 auditors assess the suitability of design and, over a defined period, the operating effectiveness of backup controls relative to the selected Trust Services Criteria. Assessors working against ISO 27001 evaluate backup as a reference control informed by the organization's risk assessment, confirming the applicable control designation against the relevant standard edition.
Security Engineers and IT Operations
Those responsible for implementing backups design and maintain the process of copying data to a separate location and restoring it after a loss or corruption event. Because the presence of backup controls does not by itself guarantee successful restoration, they carry the practical responsibility of ensuring the copies are recoverable within the systems covered by the assessment.

Inside Backup

Backup Copies
Duplicate copies of data, systems, or configurations retained so that information can be restored following loss, corruption, or a disruptive event. The scope of what is backed up depends on the organization's risk assessment and the boundaries of the systems under examination or certification.
Backup Frequency and Retention
The schedule on which backups are taken and the length of time copies are kept. These parameters typically vary based on data criticality, recovery objectives, and scoping decisions rather than any single mandated interval.
Backup Storage and Protection
The location and safeguards applied to backup media, which in most implementations include offsite or geographically separated storage and encryption of backup data at rest to preserve confidentiality and integrity.
Restoration and Testing
Procedures for recovering data from backups and periodic testing to confirm that copies are usable and complete. Evidence of restoration testing is commonly reviewed to demonstrate that a control operates effectively over time.
Relevance to SOC 2
Backup practices commonly support the Availability category of the Trust Services Criteria and may relate to the Security Common Criteria. Availability is an optional category selected based on scope, so backup controls are examined only where they fall within the criteria and period covered by the report.
Relevance to ISO 27001
Backup is addressed among the Annex A reference controls, which are selected via the Statement of Applicability and informed by the organization's risk assessment. Whether and how a backup control applies depends on the defined scope of the ISMS and the Annex A version referenced.

Common questions

Answers to the questions practitioners most commonly ask about Backup.

Does having backups satisfy the SOC 2 Availability criteria on its own?
Not by itself. Backups are one component that can support the Availability category of the Trust Services Criteria, but Availability is an optional category selected based on scope, and it typically encompasses more than backup activities. A SOC 2 report attests only to the controls and period actually covered, so demonstrating a backup process does not on its own establish that Availability commitments are met. The specific controls examined and their sufficiency depend on the auditor, scope, and applicable criteria.
Is a specific backup control mandatory under ISO 27001?
ISO 27001's certifiable requirements are in clauses 4 through 10, while backup-related measures appear among the Annex A reference controls. Annex A controls are not universally mandatory; they are selected via the Statement of Applicability and informed by the organization's risk assessment. In most implementations backup is addressed because it is relevant to typical risks, but whether and how it applies depends on scope and the risk decisions documented for the ISMS.
How is backup typically evidenced in a SOC 2 Type II examination?
In most Type II engagements, the auditor evaluates both the design and the operating effectiveness of backup-related controls over the defined review period, so evidence generally spans that period rather than a single point in time. In a Type I examination, by contrast, the focus is typically on the suitability of design at a point in time. The exact evidence expected varies by auditor and scope.
How does backup relate to the Statement of Applicability under ISO 27001?
Where backup is treated as a relevant Annex A reference control, its inclusion or exclusion is typically recorded in the Statement of Applicability, with justification informed by the risk assessment. The SoA documents which reference controls apply to the defined ISMS scope, so backup's treatment there depends on the organization's scoping and risk decisions rather than a fixed rule.
Can one backup approach serve both a SOC 2 report and an ISO 27001 certification?
Backup practices can often be mapped to relevant expectations across both frameworks, but the mapping is partial and satisfying one framework does not automatically satisfy the other. A SOC 2 report is an attestation examination performed by a licensed CPA firm, while ISO 27001 is a certification issued by an accredited certification body against a management system standard. Backup evidence and control expectations should be evaluated separately against each framework's applicable criteria and scope.
What are the boundaries of what backup controls demonstrate in a compliance context?
Backup controls address only the specific objectives within scope, and their assessment reflects only the controls and, for SOC 2, the period covered. A SOC 2 report does not guarantee freedom from breaches or data loss, and an ISO 27001 certificate covers only the defined scope of the ISMS. Depending on scope, backup may intersect with other categories or controls, but its inclusion and depth of assessment vary by auditor, certification body, and applicable criteria.

Common misconceptions

Passing a SOC 2 examination or achieving ISO 27001 certification proves that backups will always successfully restore data.
A SOC 2 report attests only to the controls and period covered and does not guarantee freedom from data loss or breaches, and an ISO 27001 certificate covers only the defined scope of the ISMS. Neither outcome guarantees that every backup will restore successfully outside what the assessment examined.
Backup controls are mandatory in exactly the same way under both SOC 2 and ISO 27001.
Under SOC 2, backup typically relates to the Availability category, which is optional and selected based on scope. Under ISO 27001, backup is an Annex A reference control selected via the Statement of Applicability and informed by risk assessment. Whether a specific backup control applies depends on scope, criteria, and the applicable framework rather than a universal rule.
Having backup software configured is sufficient evidence of an effective backup control.
Design alone is not the same as operating effectiveness. A SOC 2 Type I assesses suitability of design at a point in time, whereas a Type II assesses both design and operating effectiveness over a defined review period, which typically means auditors look for evidence such as restoration testing across that period rather than configuration alone.

Best practices

Align backup frequency, retention, and recovery objectives with your risk assessment and the criticality of the data, rather than applying a single fixed schedule across all systems.
Periodically test restoration from backups and retain evidence of those tests, since operating effectiveness over a review period is what a SOC 2 Type II examination typically evaluates.
Protect backup copies with appropriate safeguards such as encryption at rest and geographically separated or offsite storage, depending on scope and risk.
Document backup controls within the relevant framework artifacts, for example the Statement of Applicability for ISO 27001 where the control has been selected as applicable.
Define the scope of what is backed up explicitly, recognizing that a SOC 2 report and an ISO 27001 certificate cover only the controls, criteria, or ISMS boundaries in scope.
Avoid assuming that satisfying backup requirements under one framework automatically satisfies the other, as mapping between SOC 2 and ISO 27001 is partial.