Data Backup Control (8.13)
Data Backup Control (8.13) is an ISO/IEC 27001 reference control that requires an organization to create and test backup copies of its data, software, and systems so it can recover if information is lost, corrupted, or otherwise interrupted. The idea is that reliable, tested backups let the organization restore operations after an incident rather than losing critical information permanently. As an Annex A control, it is selected for implementation through the Statement of Applicability based on the organization's risk assessment.
Annex A control 8.13 (Information backup), referenced in the 2022 revision of ISO/IEC 27001 and elaborated in ISO/IEC 27002, is a corrective control that maintains risk by requiring documented policies and procedures for maintaining and testing backup copies of information, software, and systems to enable timely recovery from data and/or system loss, corruption, or interruption. Practitioners typically define backup scope, frequency, retention, and testing regimes aligned to business recovery requirements, and integrate these procedures into the broader ISMS. As a reference control, its applicability and design are determined via the Statement of Applicability informed by risk assessment, so specific parameters vary by organization and scope; the control addresses recoverability rather than guaranteeing prevention of data loss events themselves.
Why it matters
Data loss and corruption remain among the most disruptive events an organization can face, whether triggered by hardware failure, human error, malicious activity such as ransomware, or system interruption. Control 8.13 matters because it addresses recoverability directly: without reliable, tested backups, an organization may have no path to restore critical information after an incident, turning a recoverable disruption into a permanent loss. This is why the control is classified as corrective and framed around enabling timely recovery.
The emphasis on testing is a defining feature of this control. Backups that exist but have never been restored can create a false sense of security, since undetected corruption, incomplete coverage, or misconfigured procedures may only surface at the moment recovery is actually needed. By requiring organizations to maintain and test backup copies, Control 8.13 pushes teams to validate that their recovery capability works in practice, not just on paper.
It is important to note the boundaries of this control. As a reference control selected through the Statement of Applicability, its specific parameters, scope, frequency, retention, and testing regimes, vary by organization based on the risk assessment and business recovery requirements. The control addresses recoverability rather than preventing data loss events from occurring, so it complements rather than replaces preventive controls within the broader ISMS.
Who it's relevant to
Inside Data Backup Control (8.13)
Common questions
Answers to the questions practitioners most commonly ask about Data Backup Control (8.13).