Skip to content

Data Recovery

What is Data Recovery?

The process of restoring data that has been lost, corrupted, accidentally deleted, or otherwise made inaccessible from backup copies.

Information Security

What the standards actually require on data recovery

Requirements naming data recovery across 6 standards, quoted from the control text.

CIS Controls v82 controls

Test backup recovery quarterly, or more frequently, for a sampling of in-scope enterprise assets.

CIS-11.5 · Test Data Recovery

Data recovery capability. The company should maintain backups and a data recovery capability for critical shipboard data and system configurations.

BIMCO-10.4 · Data recovery capability

Destroy renders target data recovery infeasible and the media unable to be reused. Methods include disintegration, pulverization, melting, incineration, and shredding to particle sizes appropriate for the media.

MS-DESTROY-1 · Destroy as Highest Sanitization Level

Where practical, cryptographic equipment, applications and libraries provide a means of data recovery to allow for circumstances where the encryption key is unavailable due to loss, damage or failure.

ISM-0455 · Where practical, cryptographic equipment, applications and libraries provide a means of da

Perform periodic data recovery tests against backups to verify the backup configuration and the availability of backup data meet the defined recovery time and recovery point objectives.

ASBv3-BR-4 · Regularly test backup

Apply the three NIST SP 800-88 Rev 1 sanitization method categories per Chapter 2 (Background) Section 2.5. Clear (Section 2.5.1): applies logical techniques to sanitize data in all user-addressable storage locations for protection against simple non-invasive...

NISTSP88-2 · Sanitization Method Categories: Clear, Purge, Destroy

Questions people ask about data recovery

What is Data Recovery?
The process of restoring data that has been lost, corrupted, accidentally deleted, or otherwise made inaccessible from backup copies.
Why is Data Recovery important for compliance?
Data Recovery is a key concept in Information Security. Understanding data recovery helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Data Recovery?
Data Recovery appears in the requirement text of CIS Controls v8, BIMCO Cyber Security, NIST SP 800-88 Rev 1, Australian Information Security Manual, Azure Security Benchmark. Across these standards we have identified 8 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Data Recovery?
Explore our compliance framework pages to see how data recovery applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Data Recovery applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.