Business continuity and backup: who owns it on each service model
Keeping the service available and your data recoverable. The provider keeps the platform up; a copy of your data you can restore is usually yours to arrange and to test.
The split by service model
| Service model | Owner | Why, and the clause |
|---|---|---|
| Infrastructure as a service | yours | Backups of your machines and volumes are yours to schedule, protect and test a restore of; the provider keeps the hardware redundant, not your data. ISO/IEC 27017 12.3.1 |
| Platform as a service | shared | The provider keeps the service available and may keep its own backups; whether you rely on those, keep your own copy and test the restore is yours to decide and prove. ISO/IEC 27017 12.3.1 |
| Software as a service | shared | The provider keeps the service available and may keep its own backups; whether you rely on those, keep your own copy and test the restore is yours to decide and prove. ISO/IEC 27017 12.3.1 |
| Serverless functions and event services | shared | The provider keeps the service available and may keep its own backups; whether you rely on those, keep your own copy and test the restore is yours to decide and prove. ISO/IEC 27017 12.3.1 |
| Hosted AI models and AI platforms | shared | The provider keeps the service available and may keep its own backups; whether you rely on those, keep your own copy and test the restore is yours to decide and prove. ISO/IEC 27017 12.3.1 |
Services that move the line
- Backup service: yours A backup service does what you configure: what is copied, how often, how long it is kept and whether a restore has been tested are yours.
The clauses each framework attaches
6 quoted| Framework | Clause |
|---|---|
| Cloud Controls Matrix v4.0.1 | CCM-BCR-08 Backup |
| ISO/IEC 27017:2015 | ISO/IEC 27017 12.3.1 Information backup |
| SOC 2 Trust Services Criteria | SOC 2 A1.2 Environmental protections, data backups, and recovery infrastructure support availability |
| ISO/IEC 27001:2022 Annex A | ISO/IEC 27001 8.13 Information backup |
| CMMC 2.0 | CMMC MP.L2-3.8.9 Protect Backups |
| C5 cloud criteria catalogue | C5-OPS-06 Data Backup and Recovery - Concept |
CCM-BCR-08 BackupBack up cloud-held data on a defined cycle, protect the confidentiality and integrity of the backups, and prove by restore testing that the data can actually be recovered.
- Backup schedules and job success records
- Backup encryption and access control configuration
- Restore test results with date, scope and outcome
- Retention settings matched to the recovery point objective
- Backups running successfully but never restore tested
- Backups readable by the same credentials that could destroy production
- Restore tested for one system and the result generalised to all
ISO/IEC 27017 12.3.1 Information backupThe provider should specify the backup capabilities it offers, including scope, frequency, retention, protection of the backups and how the customer may restore, and should state what it does not back up. The customer should decide which of its cloud-hosted information needs backup, whether to rely on the provider's backups or keep its own, and should test that restoration works.
- Provider backup specification for the service
- Customer backup decision and arrangements per cloud service
- Restore test records
- Customer assumes the provider backs up its data when the service only replicates it
- Backups held only inside the same cloud account they protect
SOC 2 A1.2 Environmental protections, data backups, and recovery infrastructure support availabilityAuthorizes, designs, develops or acquires, implements, operates, approves, maintains, and monitors environmental protections, software, data back-up processes, and recovery infrastructure to meet its objectives
- Evidence of environmental protections at the facilities in scope, covering fire detection and suppression, power continuity, cooling and water detection, with testing and maintenance records
- The backup configuration showing scope, frequency and retention against the recovery point objective
- Evidence of protection of backup data, including encryption, access restriction and an immutable or offline copy
- Evidence of the recovery infrastructure, including alternative processing capability and its readiness
- Evidence these are authorised, approved, maintained and monitored, including who approved the design
- Backups configured with failures reported and never investigated, so gaps in the backup set are unknown
- Backups reachable using production credentials, so a single compromise destroys both
- Environmental protections at the primary site only, with the recovery site unassessed
- Reliance on a cloud provider's environmental controls with no review of their assurance report or of the complementary controls it assumes
ISO/IEC 27001 8.13 Information backupMaintain and regularly test backups of information, software and systems per the backup policy.
- Backup policy
- Backup schedule
- Backup test reports
- Retention records
- Access logs
- infrequent restore testing
- missing retention documentation
- undefined backup responsibilities
- inconsistent backup verification
CMMC MP.L2-3.8.9 Protect Backups Level 2Protect the confidentiality of backup copies of CUI at the locations where those backups are stored.
- Backup inventory identifying which backups contain CUI
- Protection applied at backup storage locations, encryption or physical control
- Access controls and records for backup storage
- Production data protected while backups are not
- Offsite and cloud backup locations unassessed
- Backup encryption keys stored alongside the backups
C5-OPS-06 Data Backup and Recovery - ConceptDocument and communicate backup and recovery policies fixing backup scope, frequency and retention against contractual and internal RTO and RPO targets, requiring state of the art encryption of backups, restricting restores to authorised persons and mandating recovery testing.
- Backup policy stating retention per data class alongside the agreed RTO and RPO
- Encryption standard and key handling rules applied to backup sets
- Authorisation matrix naming who may trigger a restore
- Mapping of customer contract terms onto the internal backup schedule
- Retention in the policy shorter than the periods promised to customers in contract
- Policy silent on where backup encryption keys are held and who controls them
- Restore authority expressed as a role that no longer exists in the organisation
- Policy scoped to databases while configuration, secrets and infrastructure state are omitted