Skip to content
arrow_back
search
Annex A 8.13 verified ISO/IEC 27001:2022

Backup and Recovery Procedures for Data

Keep and test backups of data and systems regularly as per backup policy.

record_voice_over

Plain language

This control is about making sure you have backup copies of your important data and systems, and also about testing these backups regularly. If you don't do this, you risk losing crucial information or systems, which can seriously disrupt your business operations.

Framework

ISO/IEC 27001:2022

Control effect

Proactive

ISO 27001 domain

Technological controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

12 Apr 2026

Maturity levels

N/A

Official control statement

Backup copies of information, software and systems shall be maintained and regularly tested in accordance with the agreed topic-specific policy on backup.
verified ISO/IEC 27001:2022 Annex A 8.13
priority_high

Why it matters

Without regular, tested backups, data loss from corruption or deletion could halt operations for days, risking financial and reputational damage.

settings

Operational notes

Regularly test backups by restoring a sample to verify integrity, and confirm all critical systems and data sets are included in backup schedules.

Mapping detail

Mapping

Direction

Controls