A.8.13 Information Backup
Control Objective
Backup copies of information, software and systems shall be maintained and regularly tested in accordance with the agreed topic-specific policy on backup.
Policy Statement
anDREa ensures corporate continuity and platform resilience by maintaining a comprehensive data backup framework. Backup copies of critical systems, software configurations, and operational information are automatically generated, continuously monitored, and regularly tested to guarantee rapid restorability in the event of equipment failure, data corruption, or a major security incident.
Backup Framework & Strategy
Our resilience strategy balances automated execution with strict verification tracking across all cloud assets:
- SaaS Environment Mapping: A complete ledger of the primary Software-as-a-Service (SaaS) utilities utilized across anDREa operations, alongside their respective provider backup retention schemes, is maintained within the Record of Processing Activities (ROPA).
- Platform Architecture and Fabric: Backup scheduling, technical dependencies, retention windows, and replication regions required to bring the myDRE ecosystem back online following an outage are governed under the Baseline Recovery of myDRE Service blueprint.
- Verification & Logging: The success or failure of automated backup sequences is reviewed systematically. Successful executions, log anomalies, and manual test validations are recorded within our internal ticketing ecosystem.
- Incident Alignment: The execution of bare-metal or point-in-time recoveries during an active operational crisis is integrated into the master Disaster Recovery Plan.
Monitoring & Testing Protocols
Backups are subject to multi-layered quality control checks to confirm availability and prevent data silent-corruption:
- Periodic Controls Security: Dedicated administrative tickets are systematically generated to verify backup health, snapshot integrity, and automated alert routing configuration (see: Periodic Security Controls).
- Overview Security Checks: A centralized dashboard utilized by the Security Team to audit execution continuity and track historical trends across all retention pools (see: Retention Periods).