Does your organization maintain offline and offsite backups that would remain unaffected by incidents or disasters impacting your primary systems?
Explanation
Offline backups (disconnected from networks) and offsite backups (stored in a different physical location) provide critical protection against ransomware, malware, physical disasters, and other threats that could compromise your primary systems and connected backup solutions. These backups serve as your last line of defense when all other recovery options fail.
Evidence could include documentation of your backup strategy showing offline/offsite components, backup schedules and rotation policies, contracts with offsite storage providers, or photographs of physical media in secure offsite locations with appropriate handling procedures.
Implementation Example
Securely store some backups offline and offsite so that an incident or disaster will not damage them
ID: PR.DS-11.236
Context
- Function
- PR: PROTECT
- Category
- PR.DS: Data Security
- Sub-Category
- Backups of data are created, protected, maintained, and tested
Related questions
- Does your organization implement cryptographic controls (encryption, digital signatures, hashing) to protect the confidentiality and integrity of stored data across all relevant storage systems?
- Is full disk encryption implemented on all user endpoints (laptops, desktops, mobile devices) that store company data?
- Does your organization validate digital signatures to verify the integrity and authenticity of software before installation or use?
- Does your organization have a policy and technical controls to restrict the use of removable media devices?
- Does your organization physically secure all removable media containing unencrypted sensitive information?
- Does your organization implement cryptographic controls to protect the confidentiality and integrity of network communications?

