Skip to main content
Category: Business Continuity

Data Backup Control (8.13)

Also known as: Information Backup, ISO 27001 Annex A 8.13, ISO 27002 Control 8.13, Control 8.13
Simply put

Data Backup Control (8.13) is an ISO/IEC 27001 reference control that requires an organization to create and test backup copies of its data, software, and systems so it can recover if information is lost, corrupted, or otherwise interrupted. The idea is that reliable, tested backups let the organization restore operations after an incident rather than losing critical information permanently. As an Annex A control, it is selected for implementation through the Statement of Applicability based on the organization's risk assessment.

Formal definition

Annex A control 8.13 (Information backup), referenced in the 2022 revision of ISO/IEC 27001 and elaborated in ISO/IEC 27002, is a corrective control that maintains risk by requiring documented policies and procedures for maintaining and testing backup copies of information, software, and systems to enable timely recovery from data and/or system loss, corruption, or interruption. Practitioners typically define backup scope, frequency, retention, and testing regimes aligned to business recovery requirements, and integrate these procedures into the broader ISMS. As a reference control, its applicability and design are determined via the Statement of Applicability informed by risk assessment, so specific parameters vary by organization and scope; the control addresses recoverability rather than guaranteeing prevention of data loss events themselves.

Why it matters

Data loss and corruption remain among the most disruptive events an organization can face, whether triggered by hardware failure, human error, malicious activity such as ransomware, or system interruption. Control 8.13 matters because it addresses recoverability directly: without reliable, tested backups, an organization may have no path to restore critical information after an incident, turning a recoverable disruption into a permanent loss. This is why the control is classified as corrective and framed around enabling timely recovery.

The emphasis on testing is a defining feature of this control. Backups that exist but have never been restored can create a false sense of security, since undetected corruption, incomplete coverage, or misconfigured procedures may only surface at the moment recovery is actually needed. By requiring organizations to maintain and test backup copies, Control 8.13 pushes teams to validate that their recovery capability works in practice, not just on paper.

It is important to note the boundaries of this control. As a reference control selected through the Statement of Applicability, its specific parameters, scope, frequency, retention, and testing regimes, vary by organization based on the risk assessment and business recovery requirements. The control addresses recoverability rather than preventing data loss events from occurring, so it complements rather than replaces preventive controls within the broader ISMS.

Who it's relevant to

Compliance and GRC Managers
Those responsible for the ISMS need to determine whether Control 8.13 is applicable through the Statement of Applicability and document how its scope, frequency, retention, and testing align with the organization's risk assessment. They ensure backup procedures are integrated into the wider management system and are evidenced for certification against ISO/IEC 27001.
IT and Infrastructure Teams
The teams that operate backup systems implement the day-to-day procedures for creating, storing, and restoring backups of data, software, and systems. Their responsibility includes executing the testing regimes that validate recoverability, since backups that are never restored may conceal gaps that only appear during an actual incident.
Auditors and Certification Bodies
Auditors assessing an ISMS against ISO/IEC 27001 review whether backup policies are documented, whether backups are actually maintained and tested, and whether the design reflects the organization's stated recovery requirements. Because parameters vary by scope, they typically evaluate the control against what the organization has defined rather than a single fixed benchmark.
Business Continuity and Recovery Stakeholders
Those accountable for continuity depend on tested backups to meet recovery objectives after data or system loss, corruption, or interruption. They help define the business recovery requirements that inform backup scope and frequency, ensuring the recovery capability supports operational needs.

Inside Data Backup Control (8.13)

Annex A Reference Control 8.13 (ISO/IEC 27001:2022)
Information Backup is a reference control listed in Annex A of ISO/IEC 27001:2022, where the Annex A controls were restructured into 93 controls across four themes. Control 8.13 falls under the technological controls theme and addresses the maintenance of backup copies of information, software, and systems.
Selection via Statement of Applicability
Like all Annex A controls, 8.13 is a reference control that is included or excluded through the Statement of Applicability, informed by the organization's risk assessment. Its applicability depends on the defined scope of the ISMS rather than being universally mandated in every implementation.
Backup Policy and Scope of Coverage
The control typically involves defining what information, software, and system images require backup, based on business and risk requirements. The specific coverage depends on scoping decisions and the results of the organization's risk assessment.
Restoration and Testing
The concept commonly encompasses not only taking backups but also periodically verifying that data can be restored, so that recovery objectives can be met. The frequency and method of testing typically vary by organizational scope and risk tolerance.
Relationship to Guidance in ISO/IEC 27002
While ISO/IEC 27001 Annex A names the control, more detailed implementation guidance for backup is provided in ISO/IEC 27002, which serves as a companion guidance standard rather than a certifiable requirement.

Common questions

Answers to the questions practitioners most commonly ask about Data Backup Control (8.13).

Is control 8.13 a mandatory backup requirement that every ISO 27001-certified organization must implement?
Not automatically. Control 8.13 is one of the reference controls in Annex A of ISO/IEC 27001:2022. Annex A controls are selected via the Statement of Applicability and informed by the organization's risk assessment, so their applicability depends on scope and risk. An organization could justify excluding a given Annex A control if it is not relevant to its defined ISMS, provided the exclusion is documented and defensible. The certifiable ISMS requirements themselves sit in clauses 4 through 10, not in Annex A.
Does having a backup control like 8.13 in place also satisfy the equivalent requirement in a SOC 2 examination?
Not directly. ISO 27001 and SOC 2 are distinct frameworks: Annex A controls such as 8.13 are not the same as the Trust Services Criteria used in a SOC 2 examination. Backup practices may be relevant to a SOC 2 engagement depending on the criteria in scope, but mapping between the two frameworks is partial. Satisfying an Annex A backup control does not automatically satisfy any SOC 2 criterion, and the evidence, testing, and reporting differ between an attestation examination and a certification against a management system standard.
How does an organization decide what backup frequency and retention to apply under control 8.13?
These parameters are typically driven by the organization's risk assessment, business requirements, and any applicable obligations rather than by a single prescribed value. In most implementations, backup scope, frequency, and retention are documented in a backup policy and aligned with recovery objectives defined by the organization. Because the appropriate settings depend on scope and risk, they vary between organizations and should be justified and recorded.
What evidence typically demonstrates that control 8.13 is operating as intended?
Depending on the auditor and scope, evidence commonly includes a documented backup policy, records or logs of backup jobs, configuration showing scope and schedule, and records of restoration or recovery tests. Auditors generally look for both the design of the control and evidence that it functions in practice, though the specific artifacts requested vary by certification body and engagement.
Should backup restoration be tested, and if so, how often?
Testing the ability to restore from backups is a common practice, since it confirms that backups are usable rather than merely created. The frequency of restoration testing typically depends on the organization's risk appetite, recovery objectives, and business context, so it varies between organizations. There is no single universally mandated interval; the chosen approach should be documented and consistent with the organization's stated requirements.
How does backup control 8.13 relate to information security incident management and continuity planning?
Backups often support recovery activities that are addressed under other Annex A controls and under continuity-related considerations, so 8.13 typically works alongside those areas rather than in isolation. In most engagements, backup controls are considered as one element of a broader set of resilience and recovery measures. The precise interfaces between these areas depend on how the organization structures its ISMS and its defined scope.

Common misconceptions

Control 8.13 is a mandatory control that every ISO 27001-certified organization must implement.
Annex A controls, including 8.13, are reference controls selected through the Statement of Applicability and informed by risk assessment. An organization may justify exclusion where it is not applicable to the defined ISMS scope. The certifiable requirements themselves reside in clauses 4 through 10.
Having backup controls documented under 8.13 satisfies backup-related expectations in a SOC 2 examination.
SOC 2 and ISO 27001 are distinct frameworks. SOC 2 is an attestation examination against the Trust Services Criteria, and mapping between the two is possible but only partial. Satisfying an ISO 27001 Annex A control does not automatically satisfy any SOC 2 criteria, and backup-related considerations in SOC 2 typically arise under scope-dependent categories such as Availability rather than being a direct equivalent.
Control number 8.13 refers to the same control across all versions of the standard.
The 8.13 numbering corresponds to the ISO/IEC 27001:2022 revision, which restructured Annex A into 93 controls across four themes. The 2013 edition used a different structure and numbering, so the version should always be specified when citing a control number.

Best practices

Document the decision to include or exclude control 8.13 in the Statement of Applicability, tying the rationale back to the results of your risk assessment and the defined ISMS scope.
Define backup coverage explicitly, identifying which information, software, and system images are in scope based on business and risk requirements rather than assuming a single default approach.
Establish and record a restoration testing routine so that backups are periodically verified as recoverable, and retain evidence of these tests for audit purposes.
Reference ISO/IEC 27002 for detailed implementation guidance on backup while treating ISO/IEC 27001 clauses 4 through 10 and Annex A as the certifiable and reference elements respectively.
Confirm you are working from the ISO/IEC 27001:2022 numbering when citing control 8.13, and avoid mixing it with the differently structured 2013 edition.
If you also pursue a SOC 2 report, treat backup evidence separately for each framework, since mapping between SOC 2 criteria and Annex A controls is partial and neither outcome automatically satisfies the other.