Glossary

    Backup Security

    Data Protection

    Backup Security ensures that your AWS backups are protected, immutable, and recoverable - even if your primary account is compromised by ransomware or insider threats.

    AWS Backup Features

    • Backup Vault Lock: WORM (write-once-read-many) protection; once locked, backup retention cannot be shortened or deleted, even by root
    • Cross-Account Backup: copy backups to a separate, restricted AWS account
    • Cross-Region Backup: replicate backups to another AWS region for disaster recovery
    • Encryption: all backups encrypted with KMS keys
    • Access Policies: IAM policies and backup vault access policies control who can manage backups

    Best Practices

    • 3-2-1 Rule:3 copies, 2 different storage types, 1 off-site (cross-account or cross-region)
    • Enable Backup Vault Lock in compliance mode for immutable backups
    • Use a dedicated backup account with restricted access
    • Regularly test restores: untested backups are not backups
    • Monitor with Config Rules to ensure all critical resources are backed up

    Related AWS Services

    Related Content

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.