N.4.05 Backup and restore
Control Overview
This control mandates that the organization establishes, implements, and maintains a comprehensive backup policy and restoration workflow to guarantee data availability and business continuity. To protect essential information assets from permanent loss due to ransomware, physical disasters, hardware failures, or human error, backups must be generated at defined intervals according to a formalized plan. Crucially, the control requires that these backups are regularly tested for validity and restorability, and that clear organizational responsibilities are assigned for their execution, monitoring, and validation.
Applicability Note: This control is fully applicable to the anDREa platform and serves as a foundational pillar for safeguarding customer environments, platform configurations, and corporate records.
Compliance & Strategic Approach
Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, translating the classical 3-2-1 backup strategy into a modern, cloud-native resiliency framework.
anDREa enforces systematic data retention and recovery pathways across all critical applications and databases. While operating within a public cloud environment shifts physical media rotation to the cloud provider, our architecture mirrors the 3-2-1 backup philosophy logically: we maintain three copies of critical data, distribute them across separate technical media structures, and enforce geo-redundancy (offsite replication across isolated Azure availability zones or regions).
Furthermore, recovery objectives are explicitly documented within our Baseline Recovery of myDRE Service framework. Responsibilities for executing and verifying backups are permanently assigned to technical owners, and backup integrity is validated through scheduled, periodic restoration drills to guarantee operational readiness during an emergency.
Control Mappings & Evidence
| Framework / Document Reference | Element & Identifier | Description / Relationship to NIS 2 |
|---|---|---|
| ISO/IEC 27001 | A.08.13 - Information backup | Mandates that backup copies of information, software, and system images are taken and regularly tested in accordance with the agreed topic-specific policy. |
| Technical Architecture | Backup myDRE Knowledge Base (KB) | The engineering manual detailing exact snapshot cadences, retention windows, logical media separation, and replication schemas. |
| Continuity Governance | Baseline Recovery of myDRE Service | The operational disaster recovery playbook defining specific Recovery Point Objective (RPO) and Recovery Time Objective (RTO) targets for core services. |
| Verification Records | Disaster Recovery Plan, Testing Logs` | Documented outcomes of formal restoration drills proving that system states and database records can be successfully compiled from backup snapshots. |
| Operational Tracking | Periodic Controls Security Logs | Routine tracking registers verifying daily backup success metrics, automated alert statuses, and active management review loops. (Periodic Security Controls) |
Audit Summary
- Compliance Status: Fully Compliant
- Gaps Identified: None. Multi-zone logical 3-2-1 backup structures, documented RPO targets, and formalized restoration testing protocols are fully active, integrated into our periodic controls, and auditable.