Defining a backup policy for your service
A useful backup policy starts with the data you need to recover and the loss your business can tolerate. Specify both the recovery point objective, meaning acceptable data loss, and the recovery time objective, meaning the target time to restore service.
Document the policy
- List applications, databases, configuration, secrets and other data that must be recoverable.
- Set backup frequency, retention and destination, including a copy separated from the production failure domain.
- Assign responsibility for checking backup results and responding to failures.
- Plan regular restoration tests and record the actual recovery steps and outcomes.
Backup service is included only where agreed for your configuration. Ask us to confirm coverage and charges rather than assuming every disk or application is protected. Keep recovery credentials accessible to authorised staff even when the production system is unavailable.
Further reading: CISA: backup and recovery guidance