PR.DS-11:

Backups of data are created, protected, maintained, and tested

Implementation Examples

Ex1:

Continuously back up critical data in near-real-time, and back up other data frequently at agreed-upon schedules

Ex2:

Test backups and restores for all types of data sources at least annually

Ex3:

Securely store some backups offline and offsite so that an incident or disaster will not damage them

Ex4:

Enforce geographic separation and geolocation restrictions for data backup storage