# Backup and continuity policy

Source: https://aestech.com.au/policy-templates/#backup-and-continuity-policy
Markdown URL: https://aestech.com.au/policy-templates/backup-and-continuity-policy.md

Use for ISO 27001 A.5.29, A.5.30, A.8.13, A.8.14, SOC 2 Availability, and resilience controls.

Frameworks: ISO 27001, SOC 2

Use this as a starting point only. Adapt it to your real scope, systems, legal obligations, customer commitments and operating process.

```text
1. Purpose
This policy defines how critical systems and information are backed up, restored and kept available during disruption.

2. Requirements
- Critical systems must have defined recovery time objectives and recovery point objectives.
- Backups must be protected against unauthorised access and deletion.
- Backup coverage must be monitored.
- Restore tests must be performed at least annually for critical systems.
- Continuity plans must include security responsibilities during disruption.
- Failover or redundancy must match the availability commitment made to customers.

3. Evidence
Keep backup job reports, restore test records, recovery objectives, continuity exercises, failover tests, incident records and corrective actions.
```

Full template pack: https://aestech.com.au/policy-templates/policy-pack.md