Skip to content
arrow_back
search
ISM-1515 policy ASD Information Security Manual (ISM)

Test Backup Restoration During Disaster Recovery

Backups should be restored regularly to ensure data can be retrieved in case of a disaster.

record_voice_over

Plain language

This control ensures that you regularly test your backup systems to make sure you can recover important data if something goes wrong, like a cyber attack or a natural disaster. It's crucial because if backups can't be restored when needed, you could lose critical business information, which could be devastating to your operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1, ML2, ML3

Official control statement

Restoration of data, applications and settings from backups to a common point in time is tested as part of disaster recovery exercises.
policy ASD Information Security Manual (ISM) ISM-1515
priority_high

Why it matters

Failure to test backup restoration can prevent recovery to a common point in time, causing data loss, prolonged outage, and reputational harm.

settings

Operational notes

During DR exercises, restore data, applications and settings to a common point in time and validate integrity, access and RTO/RPO results; record and fix gaps.

build

Implementation tips

  • IT team should schedule regular backup restoration exercises. They can start by selecting a non-critical system and restoring its data from backups in a test environment to check that everything works as expected.
  • System owners should document the restoration process. Note every step taken during the restoration exercise, from accessing backup files to completing the restoration, so that this process can be followed easily in the future.
  • Managers should allocate time and resources for these exercises. Ensure teams have necessary permissions and tools to execute the restoration without delays, prioritising it as part of risk management activities.
  • IT team should simulate varied disaster scenarios. By testing restoration under different circumstances, like server failures or network outages, they ensure backups work in all kinds of situations.
  • Staff training should include backup restoration protocols. Conduct hands-on workshops to familiarise relevant staff with the procedures for conducting restorations successfully.
fact_check

Audit / evidence tips

  • AskDocumentation of recent backup restoration tests. Review the documents for details about the date, systems involved, and outcomes of the restoration exercises GoodIncludes evidence that tests were performed regularly and successfully, with any issues noted and addressed
  • AskTo observe an actual backup restoration exercise GoodObservation shows a smooth process where the team follows documented steps without confusion
  • AskRecords of any restoration issues and how they were resolved GoodRecord will show timely resolutions and improvements made to prevent similar issues
  • AskFeedback from staff who participated in restoration tests GoodWould include positive feedback and suggestions for improvement, showing an engaged and informed staff
  • AskA list of systems included in tests GoodList shows comprehensive coverage and schedules that ensure all important systems are regularly tested
link

Cross-framework mappings

How ISM-1515 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

Control Notes Details
layers Partially meets (1) expand_less
Annex A 8.13 ISM-1515 requires testing restoration of data, applications and settings from backups to a common point in time specifically during disas...

E8

Control Notes Details
handshake Supports (1) expand_less
E8-RB-ML1.1 ISM-1515 requires organisations to test restoring from backups to a common point in time as part of disaster recovery exercises
extension Depends on (2) expand_less
E8-RB-ML1.2 ISM-1515 requires organisations to test restoring data, applications and settings from backups to a common point in time during disaster ...
E8-RB-ML1.3 ISM-1515 requires regular testing of restoring from backups to a common point in time as part of disaster recovery exercises
link Related (1) expand_less
E8-RB-ML1.4 E8-RB-ML1.4 requires organisations to test restoration of data, applications, and settings from backups to a common point in time as part...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

Mapping detail

Mapping

Direction

Controls