Incremental or differential backup
None of the held texts sets a fixed period on this consumer; every row below reads no period set by the text. Paste one job that feeds this consumer, for example incremental_backup_hourly, weekly, and the register reads its period against the clocks below, names the gap in hours, and carries the question for its owner.
Matched on the job name or the consumer column by these words: incremental, differential, incr backup, diff backup, log backup, transaction log backup, incremental. A backup, replication, feed or return job in this class is expected to name a fallback; a blank one is a finding.
The clock each rule sets
| Regime | Clock | Clause |
|---|---|---|
| ISO 27001 | no clock | ISO 27001 8.13 Information backup |
| SP 800-53 | no clock | SP 800-53 CP-9 System backupa defined frequency |
| DORA | no clock | DORA Art. 12 Backup policies and procedures, restoration and recovery |
| HIPAA | no clock | HIPAA 164.308(a)(7)(ii)(A) Data Backup Plan (Required) |
Questions this page answers
How often does ISO/IEC 27001:2022 require incremental or differential backup?
The held text of ISO 27001 8.13 (Information backup) sets no fixed period: no period set by the text. Maintain and regularly test backups of information, software and systems per the backup policy.
How often does NIST SP 800-53 Rev 5 require incremental or differential backup?
The held text of SP 800-53 CP-9 (System backup) sets no fixed period: a defined frequency. Requires backups of user-level information, system-level information and system documentation including security and privacy documentation, each at an organization-defined frequency, and requires the confidentiality, integrity and availability of the backup information itself to be protected.
How often does DORA (Regulation (EU) 2022/2554) require incremental or differential backup?
The held text of DORA Art. 12 (Backup policies and procedures, restoration and recovery) sets no fixed period: no period set by the text. Financial entities shall develop and document backup policies and procedures, and restoration and recovery procedures and methods, ensuring backups can be restored with minimal disruption, with backup systems physically and logically segregated from the source system.
How often does HIPAA Security Rule require incremental or differential backup?
The held text of HIPAA 164.308(a)(7)(ii)(A) (Data Backup Plan (Required)) sets no fixed period: no period set by the text. Establish procedures to create and maintain retrievable exact copies of ePHI. NIST recommends offline or immutable backups, encryption, and regular restoration testing.
What does the register ask the owner of a incremental or differential backup job?
Which full backup does this chain depend on, and is the chain tested end to end?
The clauses in full
Maintain and regularly test backups of information, software and systems per the backup policy.
Guidance beside it, ISO 27002 8.13: Requires backup copies of information, software and systems to be maintained and regularly tested, in line with the agreed topic specific policy on backup. Supporting SME guidance treats regular creation of backups together with tested recovery as the substance of the control, not the copy on its own.
What an assessor asks to see: backup_policy; backup_schedule; backup_test_reports; retention_records. Where it usually falls short: infrequent restore testing
Requires backups of user-level information, system-level information and system documentation including security and privacy documentation, each at an organization-defined frequency, and requires the confidentiality, integrity and availability of the backup information itself to be protected.
What an assessor asks to see: Backup schedule and success reports covering user-level, system-level and documentation backups; Encryption and access control configuration protecting backup data; Restore test records proving backups are usable; Defined backup frequencies and evidence they are met. Where it usually falls short: Documentation and configuration backed up nowhere, only application data
Financial entities shall develop and document backup policies and procedures, and restoration and recovery procedures and methods, ensuring backups can be restored with minimal disruption, with backup systems physically and logically segregated from the source system.
What an assessor asks to see: Backup and restoration policies/procedures; Evidence of segregated backups and restoration tests. Where it usually falls short: No tested backups
Establish procedures to create and maintain retrievable exact copies of ePHI. NIST recommends offline or immutable backups, encryption, and regular restoration testing.
What an assessor asks to see: Backup policy and schedule; Backup completion logs; Restoration test results; Immutable or offline backup evidence. Where it usually falls short: Backups exist but never restored
Requirement text quoted from the standards themselves, published at compliance.theartofservice.com, the same publisher as this register, read against the held text of each standard: our statement of each clause, not the instrument verbatim. Run this job through the register