Backup and Recovery
Backup and recovery refers to two related activities: copying important data to a separate, secure location on a regular schedule, and later restoring that data when the original is lost or damaged. It helps an organization respond to events such as human error, system failure, natural disasters, or cyber incidents like ransomware. In short, backup creates the protective copies, and recovery uses them to return data to a usable state.
Backup and recovery is a paired set of data-protection processes. Backup is the scheduled duplication of critical data to a secure, independent storage location, producing copies that are isolated from the production environment. Recovery is the restoration of that data to a production or usable state following data loss arising from causes such as human error, system failure, natural disaster, or cyberattack. The two functions are distinct but complementary: backup establishes the copies, while recovery is the operation that returns data from those copies. In a GRC context, backup and recovery typically operates as a preventive and corrective control supporting availability and resilience objectives. This entry does not cover implementation specifics, tooling selection, or related but separate disciplines such as disaster recovery planning, business continuity, or defined recovery objectives (e.g., RPO/RTO), which are not addressed in the evidence provided.
Why it matters
Data is central to most organizational operations, and its loss can disrupt service delivery, impair decision-making, and undermine obligations to customers, regulators, and other stakeholders. Backup and recovery addresses a range of loss scenarios that organizations commonly face, including human error, system failure, natural disasters, and cyber incidents such as ransomware. Without reliable copies stored independently of the production environment, an organization may have no practical means of returning affected data to a usable state after such an event.
Within a governance, risk, and compliance context, backup and recovery typically functions as both a preventive and a corrective control supporting availability and resilience objectives. It contributes to an organization's ability to withstand and respond to disruptive events, and it is often examined as part of broader risk assessment and control evaluation activities. The presence of tested backups can materially affect the severity of an incident's consequences, because recovery capability determines whether lost or damaged data can be restored.
It is worth noting that maintaining backups is not by itself a guarantee of recoverability; the ability to restore data depends on the integrity and accessibility of the copies at the time they are needed. This entry does not address defined recovery objectives, disaster recovery planning, or business continuity, which are related but distinct disciplines with their own requirements and considerations.
Who it's relevant to
Inside Backup and Recovery
Common questions
Answers to the questions practitioners most commonly ask about Backup and Recovery.
