GlossaryCompliance operations

Backup

Short answer

A backup is a copy of data and systems kept separately so they can be restored after a failure, an error or an attack. Against ransomware, backups only help if at least one copy is offline or immutable and restores are tested regularly.

The 3 2 1 rule

The classic rule is to keep three copies of the data, on two different types of storage, with one copy off site. Because attackers now target backups first, it is often extended: one copy offline or immutable (it cannot be changed or deleted, even by an administrator), and zero errors when restores are tested.

What to back up

Servers and databases, but also SaaS data. Microsoft 365, Google Workspace and most SaaS providers work under a shared responsibility model: they keep the service running, but recovering data deleted by mistake or by an attacker is often limited and is largely the customer's responsibility.

How often and how fast

Backup frequency should follow the RPO defined in the business continuity plan, and the restore process must meet the RTO. A backup that has never been restored is an assumption, not a guarantee.

Protecting the backups

Backups should be encrypted, stored with separate credentials protected by MFA, and monitored for unusual deletions. During a ransomware attack, they are often the difference between recovering in days and paying a ransom.

Where it shows up in compliance

ISO 27001 requires backups to be made and tested according to a backup policy (Annex A 8.13). The ENS, NIS2 and DORA also require backup and recovery measures.

Related terms

Keep reading on this topic

Running security as a repeatable process: policy management, risk registers, evidence upkeep, supplier assessment and audit readiness between cycles.

Go to the topic hub