# Backup policy

Source: https://aestech.com.au/policy-templates/#backup-policy
Markdown URL: https://aestech.com.au/policy-templates/backup-policy.md

Use for ISO 27001 A.8.13, A.8.14, SOC 2 Availability, and PCI DSS requirement 12 resilience expectations.

Frameworks: ISO 27001, SOC 2

Use this as a starting point only. Adapt it to your real scope, systems, legal obligations, customer commitments and operating process.

```text
1. Purpose
This policy defines how company and customer data is backed up, protected, tested and restored so that information can be recovered after loss, corruption, ransomware or system failure.

2. Scope
This policy applies to all critical systems, production databases, configuration data, source code, and any information whose loss would materially affect the business or customers. It applies to backups stored on company infrastructure and with cloud or third-party providers.

3. Policy statements
- Each critical system must have a defined backup frequency aligned to its recovery point objective.
- Each critical system must have a defined recovery time objective.
- Backups must be encrypted at rest and in transit.
- At least one backup copy must be kept in a separate location or account from the primary system.
- Backups must be protected against unauthorised access, modification and deletion, including protection against ransomware such as immutable or write-once storage where available.
- Backup success and failure must be monitored, and failures must be investigated and resolved.
- Restore tests must be performed at least annually for each critical system, and results recorded.
- Backup retention must align with the data retention schedule and any regulatory requirements.

4. Roles and responsibilities
- The [IT Manager] owns the backup programme and approves backup configurations.
- System owners define recovery point and recovery time objectives for their systems.
- IT and system administrators configure, monitor and test backups.
- The [Security Lead] reviews backup protection controls and restore test results.

5. Procedures
- Maintain a backup register listing system, data, frequency, retention, location and owner.
- Configure automated backups for all in-scope systems.
- Monitor backup jobs daily and alert on failures.
- Perform and document a restore test for each critical system at least annually.
- Review backup encryption, access controls and immutability settings at least annually.

6. Evidence and records
Keep the backup register, backup job reports, restore test records, recovery objective definitions, encryption and access configuration, immutability settings and exception approvals.

7. Review cadence
This policy is reviewed at least annually and after major changes to systems, providers or recovery objectives.

Owner: [role]
Version: [x.y]   Approved by: [name/role]   Date: [date]
```

Full template pack: https://aestech.com.au/policy-templates/policy-pack.md