Cyber Resilience

← ISO 27001 Annex A

A.8.13 Technological

Information backup

AttributesCorrectiveI·ARecoverContinuityProtection

Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?

The implementation guidance for this control is published in ISO/IEC 27002:2022 and is not reproduced here. The structured attributes and the cross-walk rationales below are derived facts and our own AI-authored analysis.

Mapped NIST 800-53 r5 controls (18)

Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Aligned NIST CSF 2.0 outcomes (20)

NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related OWASP ASVS 5.0 requirements (6)

Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related weaknesses / CWE (5)

Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Mitigated MITRE ATT&CK techniques (345)

Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

T1001←MT1001.002←MT1001.003←MT1003→MT1003.002→MT1003.003←M →MT1003.004→MT1003.005→MT1003.006→MT1003.007→MT1003.008→MT1005→MT1006←M →MT1014←MT1025→MT1027.001←MT1027.002←MT1027.006←M →MT1027.007←MT1027.008←MT1027.009←MT1027.011←MT1027.012→MT1027.014←MT1027.016←PT1027.017→MT1036←MT1036.003←MT1036.005←MT1036.007→MT1036.008←M →MT1036.009←MT1039→MT1040→MT1047←MT1055←MT1055.001←MT1055.002←MT1055.003←MT1055.004←MT1055.005←MT1055.008←MT1055.009←MT1055.011←MT1055.012←MT1055.013←M →MT1055.014←MT1055.015←MT1056→MT1070←M →PT1070.003←MT1070.004→MT1070.005→MT1070.006←MT1070.007→PT1070.008→PT1070.010←MT1071.004←MT1074→MT1074.001→MT1074.002←M →MT1078←PT1078.004←M →PT1090.002←MT1090.003←MT1098.005←MT1113→MT1114→MT1114.001→MT1114.002→MT1114.003→MT1119→MT1123→MT1127←MT1127.002→MT1133←MT1134.004←MT1137.001→PT1197→MT1205.002→MT1207←M →MT1211←PT1213→MT1213.001→MT1213.002→MT1213.003→MT1213.004→MT1213.005→MT1213.006→PT1218←MT1218.001→MT1218.005←M →MT1218.007←M →MT1218.011←MT1218.012→MT1218.013←MT1218.014←P →MT1218.015→MT1221←MT1222←PT1222.001←PT1222.002←MT1480.001←MT1484←MT1484.002←MT1485←M →MT1485.001←M →MT1486←M →MT1489←P →MT1490→MT1491→MT1491.001→MT1491.002→MT1495←M →MT1496→MT1496.001→MT1496.002→PT1496.003→MT1496.004→PT1497.002←PT1498←P →MT1498.001←P →MT1498.002→MT1499←M →MT1499.001→MT1499.002→MT1499.003→MT1499.004←P →MT1518.002←MT1528→MT1529←M →MT1530←M →MT1531←M →MT1535←MT1537←M →PT1539←F →MT1542←M →MT1542.001→MT1542.002←M →MT1542.003←M →MT1542.004→MT1542.005→MT1546.012←PT1548.006←MT1550←MT1550.001←FT1550.002←FT1550.003←FT1550.004←FT1552→MT1552.001←PT1552.004→PT1552.005→MT1552.006→MT1552.008→MT1553.002←PT1553.003←MT1553.004←PT1553.005←MT1553.006←MT1555→MT1555.001→MT1555.003→PT1555.004→PT1555.005→MT1555.006→MT1556.001→MT1556.004→MT1556.005→MT1556.006←FT1556.007←MT1556.009←MT1557→MT1557.001→MT1557.003→MT1557.004→MT1558.001→MT1558.002→MT1558.005→MT1560→MT1560.001→MT1560.002→MT1560.003→MT1561→MT1561.001→MT1561.002←M →MT1564→MT1564.005→MT1564.009→MT1564.014→MT1565→MT1565.001→MT1565.002←P →MT1565.003→PT1571←MT1572←MT1574←M →MT1574.001←MT1574.004←M →MT1574.006→MT1574.008→MT1574.009→MT1574.013←M →MT1574.014→MT1578←M →MT1578.001←MT1578.002←M →MT1578.003←M →MT1578.004←M →MT1578.005←MT1599←MT1599.001←PT1600←PT1600.001←PT1601→MT1601.001←P →PT1601.002←MT1602.002→MT1606←M →MT1606.002→MT1610←PT1612←MT1620←MT1621←PT1622←MT1647←P →MT1649→PT1653←PT1657←M →MT1665←PT1666←MT1667→MT1677←PT1679→MT1684→MT1684.001→MT1685←MT1685.001←M →MT1685.002→MT1685.003←MT1685.004←MT1685.005←M →MT1685.006←M →MT1686←MT1687←PT1688←M →MT1690←M
Why these map — AI rationale (under review)

Prevented OWASP Web Top 10 (2025) risks (2)

OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.