Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Operations Manager

previous version on gdrive

N.4.05 Backup and restore

Control Overview

This control mandates that the organization establishes, implements, and maintains a comprehensive backup policy and restoration workflow to guarantee data availability and business continuity. To protect essential information assets from permanent loss due to ransomware, physical disasters, hardware failures, or human error, backups must be generated at defined intervals according to a formalized plan. Crucially, the control requires that these backups are regularly tested for validity and restorability, and that clear organizational responsibilities are assigned for their execution, monitoring, and validation.

note

Applicability Note: This control is fully applicable to the anDREa platform and serves as a foundational pillar for safeguarding customer environments, platform configurations, and corporate records.

Compliance & Strategic Approach

Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, translating the classical 3-2-1 backup strategy into a modern, cloud-native resiliency framework.

anDREa enforces systematic data retention and recovery pathways across all critical applications and databases. While operating within a public cloud environment shifts physical media rotation to the cloud provider, our architecture mirrors the 3-2-1 backup philosophy logically: we maintain three copies of critical data, distribute them across separate technical media structures, and enforce geo-redundancy (offsite replication across isolated Azure availability zones or regions).

Furthermore, recovery objectives are explicitly documented within our Baseline Recovery of myDRE Service framework. Responsibilities for executing and verifying backups are permanently assigned to technical owners, and backup integrity is validated through scheduled, periodic restoration drills to guarantee operational readiness during an emergency.


Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001A.08.13 - Information backupMandates that backup copies of information, software, and system images are taken and regularly tested in accordance with the agreed topic-specific policy.
Technical ArchitectureBackup myDRE Knowledge Base (KB)The engineering manual detailing exact snapshot cadences, retention windows, logical media separation, and replication schemas.
Continuity GovernanceBaseline Recovery of myDRE ServiceThe operational disaster recovery playbook defining specific Recovery Point Objective (RPO) and Recovery Time Objective (RTO) targets for core services.
Verification RecordsDisaster Recovery Plan, Testing Logs`Documented outcomes of formal restoration drills proving that system states and database records can be successfully compiled from backup snapshots.
Operational TrackingPeriodic Controls Security LogsRoutine tracking registers verifying daily backup success metrics, automated alert statuses, and active management review loops. (Periodic Security Controls)

Audit Summary

  • Compliance Status: Fully Compliant
  • Gaps Identified: None. Multi-zone logical 3-2-1 backup structures, documented RPO targets, and formalized restoration testing protocols are fully active, integrated into our periodic controls, and auditable.