ISO 27001 and backup testing.
Regular backup tests are part of control A.8.13 in ISO/IEC 27001. RestoreTrust helps you run these tests and record the results for your ISMS.
ISO/IEC 27001:2022 describes an information security management system, or ISMS. Annex A includes control A.8.13 on information backup: backup copies of information, software, and systems should be maintained and tested regularly in line with a defined backup policy.
Tests that follow your backup policy
A.8.13 calls for regular testing but does not prescribe the same interval for every organisation. Your backup policy should define what you back up and how you test recovery. With RestoreTrust, you can turn your requirements for database backups into test plans and your own check criteria.
Include the results in your ISMS
Your risk treatment determines which Annex A controls you need. Record your selection and the reasons for it in the Statement of Applicability. Documented test runs from RestoreTrust help you assess how your backup controls are working and prepare evidence for audits.
An overview of ISO/IEC 27001 (ISO)
Control A.8.13 in the standards comparison (Alcumus ISOQAR, PDF, p. 24)
How RestoreTrust helps
- Recurring tests based on your backup policy
- Your own checks on restored data
- Documented test runs for reviews and audits
How to put the tests into practice
- Define test coverage based on your risks and goals
- Place controls in your Statement of Applicability
- Assess results and track improvements
Part of your ISMS
RestoreTrust helps you put backup tests into practice and document them. These controls form part of your ISMS. Together with risk management, other security measures, and regular reviews, they help you prepare for your certification audit.