Resources / Free policy templates
Free Backup and Recovery Policy Template (Word)
The complete template is below — read every word before you download. Editable Word version, no email required. Satisfies: ISO/IEC 27001:2022, ISO/IEC 27001:2022 Annex A 8.13 (Information backup).
Download the Word template (.docx) — free
Get new templates and guides by email
An occasional email when we publish a new free template, guide, or dataset. Unsubscribe any time.
[Organization Name]
Backup and Recovery Policy
ISO/IEC 27001:2022 — ISO/IEC 27001:2022 Annex A 8.13 (Information backup)
This policy defines how [Organization Name] creates, protects, stores, and restores backup copies of its information and systems. It addresses ISO/IEC 27001:2022 Annex A control 8.13 (Information backup) and sets requirements for backup scope, frequency, retention, storage, encryption, and restoration testing. Every bracketed placeholder must be customized to your organization before the policy is adopted.
1. Purpose
The purpose of this policy is to ensure that [Organization Name] can recover its information, software, and systems after accidental deletion, data corruption, hardware or platform failure, malicious encryption, or site loss. It sets minimum requirements for creating backup copies, protecting them, and proving by testing that they restore. This policy addresses ISO/IEC 27001:2022 Annex A control 8.13 (Information backup) and supports controls 8.14 (Redundancy of information processing facilities), 5.29 (Information security during disruption), and 5.30 (ICT readiness for business continuity). Annex A is a reference set of controls; which of these apply to [Organization Name], and the specific values recorded in this policy, are determined by its risk assessment and Statement of Applicability rather than by the standard itself.
2. Scope
This policy applies to all information systems, applications, databases, virtual machines, and configuration data owned or operated by [Organization Name], whether hosted on premises, in [Cloud Provider], or by a third party. It applies to everyone who administers, configures, monitors, or restores backups. Where a supplier backs up data on [Organization Name]'s behalf, equivalent requirements must appear in the contract, and evidence of the supplier's restoration testing must be requested [annually].
3. Backup Scope and Exclusions
[IT Manager] maintains a backup register listing every in-scope system, the data it holds, the backup method, and the storage locations used. Systems in scope include [Production Databases], [File Storage], [Email and Collaboration Platform], [Source Code Repositories], [Identity and Directory Services], and infrastructure configuration. Out of scope are [development and sandbox environments holding no production data], [ephemeral build agents], and [local workstation storage outside synchronized folders]. Every exclusion requires a written justification in the register, approved by [Role or Title].
4. Backup Frequency, Retention, and Recovery Objectives
Each in-scope system is assigned a recovery point objective (RPO) and a recovery time objective (RTO) by its [System Owner] and recorded in the backup register. Where no system-specific value is documented, the default RPO is [4 hours] and the default RTO is [24 hours]. Default schedules are [hourly] incremental backups, [daily] full backups retained [30 days], [weekly] backups retained [13 weeks], and [monthly] backups retained [12 months]. Retention periods must not be shorter than those required by [Data Retention Policy] or by applicable legal, regulatory, or contractual obligations.
5. Storage Locations, Offsite Copies, and Immutability
Backup copies must not depend on the availability or credentials of the system they protect. [Organization Name] retains at least [three] copies across at least [two] storage platforms, with at least [one] copy offsite or in a separate cloud region ([Secondary Region]). At least one retained copy must be immutable for [14 days] using object lock, write-once media, or an equivalent control that prevents deletion or alteration by any account, including backup administrators. Physical media must be stored, transported, and disposed of under [Media Handling Policy].
6. Encryption and Access Control
All backup data must be encrypted in transit and at rest using [AES-256] or another algorithm approved in [Cryptography Policy], consistent with ISO/IEC 27001:2022 Annex A control 8.24 (Use of cryptography). Encryption keys must be held in [Key Management System], must be recoverable independently of the systems being backed up, and must never be stored with the backups they protect. Access to backup repositories, consoles, and restore functions is limited to [Backup Administrators], requires multi-factor authentication, is logged, and is reviewed [quarterly].
7. Restoration Testing and Monitoring
A backup that has never been restored is not a verified backup. [Backup Administrator] tests restoration of each in-scope system at least [quarterly]; each system classified [Critical] undergoes a full restoration into an isolated environment at least [annually]. Each test record must state the system, the backup copy used, the restore method, the time taken to reach a usable state, whether the documented RTO was met, integrity checks performed, and corrective actions. Test records are retained [24 months]. Backup jobs are monitored [daily]; failed or incomplete jobs are raised and tracked under [Incident Response Policy] and remediated within [2 business days].
8. Roles and Responsibilities
[IT Manager] owns this policy, maintains the backup register, and is accountable for backup coverage. [Backup Administrator] configures and monitors backup jobs, performs and documents restoration tests, and resolves failures. [System Owners] set the RPO, RTO, and retention values for their systems and confirm the integrity of restored data during tests. [Information Security Officer] reviews test results, encryption and access controls, and approved exceptions. [Senior Management] approves this policy and allocates the resources needed to meet the recovery objectives it records.
9. Enforcement, Exceptions, and Review
Failure to comply may result in disciplinary action up to and including termination under [Organization Name]'s [HR or Sanctions Policy]. Supplier noncompliance is addressed through the applicable contract.
Exceptions must be requested in writing, risk-assessed, approved by [Role or Title], and recorded in the exception register maintained by [IT Manager], with a compensating control, an expiry date, and a cross-reference to the affected entry in the backup register.
This policy and the backup register are reviewed at least [annually], after significant changes to systems or hosting, and after any incident in which a restoration failed or a recovery objective was missed. Version History: [Version] | [Date] | [Author] | [Summary of Changes] | [Approved By]
How to customize this template
- Replace every [bracketed placeholder] with your organization's real values, then search the document for "[" to confirm none remain before you distribute it.
- Build the backup register referenced in Section 3 first. The frequencies, retention periods, RPOs, and RTOs in Section 4 are defaults that hold only until each system owner records its own.
- Set the numbers in Sections 4, 5, and 7 to what your tooling actually does today, then close the gaps you find. A documented [4 hour] RPO you cannot meet is worse than an honest [24 hour] one.
- Confirm that at least one backup copy is genuinely immutable and cannot be deleted using production or backup-administrator credentials, then record how you verified it.
- Put the restoration tests in Section 7 on a calendar with named owners, and keep the completed test records — a backup that has never been restored is not a verified backup.
- Have [IT Manager] and the approving authority sign the policy, record the effective date and version, and cross-reference your incident response, data retention, and cryptography policies by their real document names.
One honest caveat, as with everything we publish: no template, free or paid, makes an organization certified or compliant on its own. The document describes the practice; you still operate it.
This is one document — the toolkit is the whole set
This free template is drafted to the same standard as our paid toolkits. If you need the complete, cross-referenced documentation set rather than one policy:
- ISO 27001 Policy Pack — Core —
$59$29.50 - ISO 27001 Complete Toolkit —
$99$49.50 - ISO 27001 + SOC 2 Dual Toolkit —
$149$74.50
