ISO 27001 Annex : A.12.3 Backup
![]() |
ISO 27001 Annex : A.12.3 Backup Its objective is to safeguard against data loss.
A.12.3.1 Information backup
Control- In accordance with the agreed backup policy copies of records, program and device images shall be collected and regularly tested
Implementation Guidance – The organization’s information, software, and systems backup requirements should be established with a backup policy. The policy of backup should define the requirements for retention and protection. There should be sufficient backup facilities to ensure that all important information and software can be recovered after a disaster or media failure.
Related Product : ISO 27001 Lead Auditor Training And Certification ISMS
The following things should be considered when designing a backup plan:
- Precise and full backup records should be prepared as well as recorded restoration procedures;
- The nature and frequency of the backup (e.g., full or differential backups) should reflect the company’s business requirements, security requirements for the information involved and criticality to the continued operation of the organization;
- Backups should be held at a remote location at a distance sufficient to prevent any damage at most locations due to a disaster;
- The appropriate level of physical and environmental protection should be given backup information (Refer clause 11) in accordance with the standards at the main site;
- The backup medium should be tested regularly to ensure that they can be used for emergency use if required; combined with the restore procedures test and controlled for the required restore time. The check should not be carried out with overwriting of the original medium if the backup or restore process fails and cause irreparable data damage or loss;
- Backups should be secured by encryption in cases where confidentiality is the concern.
“By failing to prepare, you are preparing to fail”
-Benjamin Franklin
Operating procedures should monitor backup performance and address planned backup failures to ensure that the backups are complete according to the backup policy.
Backup procedures should be reviewed on a regular basis for specific systems and facilities to ensure they meet the criteria of business continuity plans. In essential systems and facilities, all computer information, software, and data required to restore the entire network during the event of a disaster should be protected by backup arrangements.
The preservation period should be set, taking into account any conditions for permanent retention of archive copies.
Also Read : ISO 27001 Annex : A.12.2 Protection from Malware
A well-known ISO 27001 Lead Auditor and ISO 27001 Lead Implementer certificate that mainly covers information security clauses and their implementation, i.e., controls which should be implemented by the organization to preserve the CIA triad, Confidentiality, Integrity, and Availability to maintain their critical, sensitive information in a secure manner. Infosavvy, a Mumbai- based institute, provides multi-domain certifications and training, which include IRCA CQI ISO 27001:2013 Lead Auditor (LA) and ISO 27001 Lead Implementer (LI) (TÜV SÜD Certification). Infosavvy will help you to understand and recognize the full scope of your organization’s security checks to protect your organization’s activities and information equipment (assets) from attacks, and also to illustrate the backup policy to safeguard if data gets lost due to intentional or natural hazards We have trainers with extensive expertise and experience to ensure the efficient handling of the security of information. Consequently, the applicant will gain the necessary skills for the ISMS audit by using commonly agreed audit concepts, procedures and techniques.
Read More : https://info-savvy.com/iso-27001-annex-a-12-3-backup/
-------------------------------------------------------------------------------------------------------------------------------------
This Blog Article is posted by
Infosavvy, 2nd Floor, Sai Niketan, Chandavalkar Road Opp. Gora Gandhi Hotel, Above Jumbo King, beside Speakwell Institute, Borivali West, Mumbai, Maharashtra 400092
Contact us – www.info-savvy.com
Thanks for given detail information to me. keep posting like this. eascertification
ReplyDelete