Backup Policy

Backup Policy

Backup Policy

Backup policies specify scope, frequency, retention, storage location including offsite and offline copies, encryption, and testing procedures. Immutable backups cannot be altered or deleted during a retention period.

Ransomware resilience depends on backups the attacker cannot reach.

Alternative Names:

Backup Strategy, Data Backup Policy

Why it Matters?

Ransomware changed backup requirements substantially, because attackers now target backup systems specifically before deploying encryption. Backups accessible from the production network provide no protection against that scenario, which is why offline or immutable copies have become the standard. Backup retention also interacts with legal holds and deletion commitments, since data deleted from production may persist in backup sets for months.

Frequently Confused with

Related terms

Frequently asked questions

Why do backups need to be offline or immutable?

Why do backups need to be offline or immutable?

Because ransomware attackers target backup systems before deploying encryption, and backups reachable from production provide no protection.

How do backups interact with deletion commitments?

How do backups interact with deletion commitments?

Data deleted from production may persist in backup sets for months, which deletion commitments must address explicitly.