Cybersecurity controls protecting backup data are equivalent to or more rigorous than controls protecting source data
Context and Guidance: Ensure that the controls that are being used to protect backup data are at least equivalent to the controls that protect the source data. The organisation should select controls that are designed to meet cybersecurity requirements (ARCHITECTURE-1f). The organisation may require backup data to have more rigorous cybersecurity controls such as data integrity monitoring or using write once, read many (WORM) technology to prevent modification of data.
Related Practices • Input From: Implementing ARCHITECTURE-1g provides input that may be useful for implementing this practice. • Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: RESPONSE-4b, RESPONSE-4f, RESPONSE-4j, RESPONSE-4k.