CYB-18 · Cyber security
Ransomware renders unprotected backups useless. Backups must be: immutable or air-gapped (the 3-2-1-1 rule: 3 copies, 2 media types, 1 offsite, 1 immutable), encrypted at rest, and tested via restoration exercises at minimum quarterly. The RTO and RPO must be defined and achievable.
Trigger
Backup only stored on same system as production data; no offsite/cloud backup; backup restoration not tested in last 6 months; no defined RTO/RPO; backups stored in same cloud tenant as primary systems (same ransomware blast radius)
Applicability gate
This is a readiness rule mapped to JS2 themes. Its presence in the library does not establish that JS2 applies directly to the firm.
Citation
This control maps to the public instruments below. The mapping does not establish entity applicability.
Remediation
Implement 3-2-1-1 backup strategy. Use a separate cloud backup account from production tenant. Enable immutability/WORM on backup storage. Conduct quarterly restoration tests and document results. Define RTO (<4 hours) and RPO (<24 hours) for critical systems.
Evidence required