A.8.13 Technological
Information backup
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (12)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CP-10mostlyaligns with — Both controls emphasize testing restoration procedures and verifying that backups can actually be used to reconstitute systems within required recovery timeframes.
- CP-9mostlyaligns with — Both controls require organizations to establish and execute systematic backup processes that ensure essential data and software can be recovered after incidents or failures.
- AU-11partialaligns with — Both controls address determining and enforcing retention periods for critical information, including the secure disposal of backup media once retention requirements expire.
- CP-2partialaligns with — The ISO control's requirement to align backup scope, frequency, and retention with business continuity objectives directly supports the contingency planning process.
- CP-4partialaligns with — Both controls require periodic testing of backup and recovery capabilities to confirm they satisfy incident response and business continuity objectives.
- SC-28partialaligns with — The ISO control's guidance to encrypt backups when confidentiality risks are identified complements the NIST requirement to protect information at rest.
Aligned NIST CSF 2.0 outcomes (11)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.DS-11fullcovers — The ISO control's comprehensive requirements for creating, protecting, testing, and maintaining backups directly implement the CSF outcome of ensuring data backups exist and remain reliable for recovery.
- ID.RA-04mostlyaligns with — Backup planning that incorporates recovery point objectives, criticality, and business continuity needs aligns with the CSF outcome of identifying potential impacts and likelihoods to inform risk response.
- PR.IR-03mostlyaligns with — The control's emphasis on tested restoration procedures and meeting business continuity recovery time objectives aligns with the CSF outcome of implementing mechanisms to achieve resilience in adverse situations.
- GV.PO-01partialaligns with — Establishing a topic-specific backup policy based on organizational data retention and security requirements aligns with the CSF outcome of creating policy grounded in organizational context and strategy.
- ID.IM-04partialaligns with — Regular testing of backup and restoration procedures against incident response and business continuity plans aligns with the CSF outcome of maintaining and updating such plans based on operational execution.
- PR.PS-04partialaligns with — Operational monitoring of backup execution and addressing failures aligns with the CSF outcome of generating log records to support continuous monitoring of security-relevant activities.
Related OWASP ASVS 5.0 requirements (6)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- V13.1.4partialaligns with — The ISO requirement to establish a documented backup policy and schedule for rotating critical secrets aligns with the ASVS mandate to document and rotate secrets essential to application security.
- V13.3.4partialaligns with — Requiring that backup secrets expire and are rotated according to documented policy mirrors the ASVS expectation that secrets are configured to expire and rotate on a defined schedule.
- V14.2.7partialaligns with — Defining retention periods and automated deletion of backup data once it expires directly supports the ASVS requirement that sensitive information be subject to data-retention classification and automatic removal of outdated data.
- V16.2.3partialaligns with — Ensuring backups are stored only in approved, documented locations and services corresponds to the ASVS rule that logs and related artifacts are stored or transmitted only to documented destinations.
Related weaknesses / CWE (8)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-530mostlyprevents — The backup control explicitly requires protecting backup confidentiality and integrity, directly addressing exposure risks.
- CWE-200partialmitigates — Encrypting backups and storing them off-site with physical and environmental controls reduces the chance that an attacker who compromises the primary site can read or exfiltrate the sensitive data.
- CWE-770partialmitigates — Defining retention periods and deletion schedules for backup copies prevents indefinite accumulation of data on storage media without corresponding resource-management controls.
- CWE-284nonenone — Requiring documented restoration procedures and access controls on backup media limits who can restore or access copies, thereby reducing unauthorized data exposure or tampering.
- CWE-312nonemitigates — Mandating encryption of backups according to confidentiality risks directly counters the storage of sensitive information in cleartext on backup media.
- CWE-400nonenone — Monitoring backup execution and addressing failures prevents uncontrolled resource consumption or incomplete backups that could leave systems without recoverable data after an incident.
- CWE-664nonenone — Backups preserve resources but do not govern their full lifetime control.
Mitigated MITRE ATT&CK techniques (4)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1485mostlymitigates — Regular, tested backups stored off-site allow the organization to restore data after deliberate destruction, limiting the impact of mass deletion attacks.
- T1486mostlymitigates — Encrypted, geographically separated backups enable recovery of files encrypted by ransomware, reducing the attacker’s leverage from data encryption.
- T1490mostlymitigates — Documented and periodically validated restoration procedures let the organization rebuild systems even if volume shadow copies or recovery partitions are wiped.
- T1561partialmitigates — Secure, remote backups provide an authoritative copy that survives disk-wiping attacks, allowing the organization to reconstitute wiped volumes.
Prevented OWASP Web Top 10 (2025) risks (3)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A04partialprevents — Requiring encryption of backups when confidentiality risks are identified directly counters exposure of sensitive data that would otherwise result from weak or absent cryptographic controls.
- A08partialmitigates — Encrypting backups and storing them off-site with appropriate physical protection reduces the chance that tampered or corrupted data will be restored after an integrity failure.
- A09partialmitigates — Regular testing of backup media and restoration procedures, plus monitoring for backup failures, provides the evidence and alerting needed to detect when data loss or corruption has occurred.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.