Cloud Shared Responsibility Mapper
Control area

Business continuity and backup: who owns it on each service model

Keeping the service available and your data recoverable. The provider keeps the platform up; a copy of your data you can restore is usually yours to arrange and to test.

The split by service model

Service modelOwnerWhy, and the clause
Infrastructure as a serviceyoursBackups of your machines and volumes are yours to schedule, protect and test a restore of; the provider keeps the hardware redundant, not your data. ISO/IEC 27017 12.3.1
Platform as a servicesharedThe provider keeps the service available and may keep its own backups; whether you rely on those, keep your own copy and test the restore is yours to decide and prove. ISO/IEC 27017 12.3.1
Software as a servicesharedThe provider keeps the service available and may keep its own backups; whether you rely on those, keep your own copy and test the restore is yours to decide and prove. ISO/IEC 27017 12.3.1
Serverless functions and event servicessharedThe provider keeps the service available and may keep its own backups; whether you rely on those, keep your own copy and test the restore is yours to decide and prove. ISO/IEC 27017 12.3.1
Hosted AI models and AI platformssharedThe provider keeps the service available and may keep its own backups; whether you rely on those, keep your own copy and test the restore is yours to decide and prove. ISO/IEC 27017 12.3.1

Services that move the line

The clauses each framework attaches

6 quoted
FrameworkClause
Cloud Controls Matrix v4.0.1CCM-BCR-08 Backup
ISO/IEC 27017:2015ISO/IEC 27017 12.3.1 Information backup
SOC 2 Trust Services CriteriaSOC 2 A1.2 Environmental protections, data backups, and recovery infrastructure support availability
ISO/IEC 27001:2022 Annex AISO/IEC 27001 8.13 Information backup
CMMC 2.0CMMC MP.L2-3.8.9 Protect Backups
C5 cloud criteria catalogueC5-OPS-06 Data Backup and Recovery - Concept
CCM-BCR-08 Backup

Back up cloud-held data on a defined cycle, protect the confidentiality and integrity of the backups, and prove by restore testing that the data can actually be recovered.

What an assessor asks to see:
  • Backup schedules and job success records
  • Backup encryption and access control configuration
  • Restore test results with date, scope and outcome
  • Retention settings matched to the recovery point objective
Where it usually falls short:
  • Backups running successfully but never restore tested
  • Backups readable by the same credentials that could destroy production
  • Restore tested for one system and the result generalised to all
Source: Cloud Controls Matrix v4.0.1
ISO/IEC 27017 12.3.1 Information backup

The provider should specify the backup capabilities it offers, including scope, frequency, retention, protection of the backups and how the customer may restore, and should state what it does not back up. The customer should decide which of its cloud-hosted information needs backup, whether to rely on the provider's backups or keep its own, and should test that restoration works.

What an assessor asks to see:
  • Provider backup specification for the service
  • Customer backup decision and arrangements per cloud service
  • Restore test records
Where it usually falls short:
  • Customer assumes the provider backs up its data when the service only replicates it
  • Backups held only inside the same cloud account they protect
Source: ISO/IEC 27017:2015
SOC 2 A1.2 Environmental protections, data backups, and recovery infrastructure support availability

Authorizes, designs, develops or acquires, implements, operates, approves, maintains, and monitors environmental protections, software, data back-up processes, and recovery infrastructure to meet its objectives

What an assessor asks to see:
  • Evidence of environmental protections at the facilities in scope, covering fire detection and suppression, power continuity, cooling and water detection, with testing and maintenance records
  • The backup configuration showing scope, frequency and retention against the recovery point objective
  • Evidence of protection of backup data, including encryption, access restriction and an immutable or offline copy
  • Evidence of the recovery infrastructure, including alternative processing capability and its readiness
  • Evidence these are authorised, approved, maintained and monitored, including who approved the design
Where it usually falls short:
  • Backups configured with failures reported and never investigated, so gaps in the backup set are unknown
  • Backups reachable using production credentials, so a single compromise destroys both
  • Environmental protections at the primary site only, with the recovery site unassessed
  • Reliance on a cloud provider's environmental controls with no review of their assurance report or of the complementary controls it assumes
Source: SOC 2 Trust Services Criteria
ISO/IEC 27001 8.13 Information backup

Maintain and regularly test backups of information, software and systems per the backup policy.

What an assessor asks to see:
  • Backup policy
  • Backup schedule
  • Backup test reports
  • Retention records
  • Access logs
Where it usually falls short:
  • infrequent restore testing
  • missing retention documentation
  • undefined backup responsibilities
  • inconsistent backup verification
Source: ISO/IEC 27001:2022 Annex A
CMMC MP.L2-3.8.9 Protect Backups Level 2

Protect the confidentiality of backup copies of CUI at the locations where those backups are stored.

What an assessor asks to see:
  • Backup inventory identifying which backups contain CUI
  • Protection applied at backup storage locations, encryption or physical control
  • Access controls and records for backup storage
Where it usually falls short:
  • Production data protected while backups are not
  • Offsite and cloud backup locations unassessed
  • Backup encryption keys stored alongside the backups
Source: CMMC 2.0
C5-OPS-06 Data Backup and Recovery - Concept

Document and communicate backup and recovery policies fixing backup scope, frequency and retention against contractual and internal RTO and RPO targets, requiring state of the art encryption of backups, restricting restores to authorised persons and mandating recovery testing.

What an assessor asks to see:
  • Backup policy stating retention per data class alongside the agreed RTO and RPO
  • Encryption standard and key handling rules applied to backup sets
  • Authorisation matrix naming who may trigger a restore
  • Mapping of customer contract terms onto the internal backup schedule
Where it usually falls short:
  • Retention in the policy shorter than the periods promised to customers in contract
  • Policy silent on where backup encryption keys are held and who controls them
  • Restore authority expressed as a role that no longer exists in the organisation
  • Policy scoped to databases while configuration, secrets and infrastructure state are omitted
Source: C5 cloud criteria catalogue