Implement and Regularly Test Backup and Recovery Procedures
What this control requires
Establish backup policies requiring daily incremental and weekly full backups for critical systems. Encrypt all backups. Store backups offline and offsite. Test restoration monthly for critical systems. Maintain immutable backups to protect against ransomware. Document and enforce backup retention periods aligned with regulatory requirements.
Other DORA controls
DORA-A17-001-B - DORA Incident Classification and ManagementDORA-A5-001-B - Board ICT Risk AccountabilityDORA-GOV-001 - Maintain Board-Approved ICT Risk Management FrameworkDORA-GOV-002 - Designate Senior ICT Risk Function with Board-Level AccessDORA-GOV-003 - Implement Comprehensive ICT Risk Management FrameworkDORA-GOV-004 - Maintain Approved ICT Systems and Security Baseline StandardsDORA-ICT-001 - Conduct Annual ICT Asset Classification and Risk AssessmentDORA-ICT-002 - Deploy Multi-Layer ICT Protection and Prevention ControlsDORA-ICT-003 - Deploy 24/7 Security Monitoring and Threat DetectionDORA-ICT-004 - Maintain and Test Incident Response and Recovery PlansDORA-INC-001 - Establish DORA-Compliant ICT Incident Management ProcessDORA-INC-002 - Implement DORA Incident Classification and Severity Assessment