Free policy template ISO 27001

Backup, Business Continuity & Disaster Recovery Policy

Backup schedules, recovery objectives (RTO/RPO), and how you keep critical services available through disruption.

Download the Markdown

Free and ungated, no email required. The full template is below and in the download. Authored in Keel's own words and mapped to ISO 27001 by clause; replace the {{PLACEHOLDER}} tokens with your details.

How to use it

  1. Download the template. Grab the Markdown file, or copy the full text from this page.
  2. Fill in the placeholders. Replace every {{PLACEHOLDER}} token (company name, owner, approver, dates, version) with your details.
  3. Tailor it to how you operate. Adjust the statements so they describe what your organization actually does. A policy you do not follow is worse than none.
  4. Approve and publish. Have an accountable owner approve it, set an effective date and a review date, and share it where staff can find it.
  5. Keep it current. Review on the schedule you set (or when things change), and keep evidence that it is followed. In Keel this is tracked for you.

Related

Backup, Business Continuity & Disaster Recovery

Organization: {{COMPANY_LEGAL_NAME}} Document owner: {{POLICY_OWNER_ROLE}} Approved by: {{APPROVER_NAME}}, {{APPROVER_TITLE}} Version: {{VERSION}} · Effective: {{EFFECTIVE_DATE}} · Next review: {{REVIEW_DATE}} Classification: Internal


1. Purpose

This policy makes sure {{COMPANY_LEGAL_NAME}} can restore critical {{DATA_TYPES}} and services within agreed recovery-time and data-loss targets after a disruption, for workloads running in {{CRITICAL_SYSTEMS}} and subject to {{GEO_SCOPE}} requirements.

2. Scope

This policy covers production databases, file stores, configuration repositories, and the essential SaaS services that support {{CRITICAL_SYSTEMS}} and handle {{DATA_TYPES}}. It applies to the {{LOCATION}} workforce, and only managed {{DEVICE_TYPES}} may perform backup or restore actions.

3. Policy statements

3.1 Backup strategy and frequency

Critical production {{DATA_TYPES}} are backed up in full daily and kept online for at least 30 days. Infrastructure-as-code and configuration are snapshotted before each major change to {{CRITICAL_SYSTEMS}}. Backup jobs alert on failure so misses are caught quickly.

3.2 Storage and encryption

Backups are stored in a separate region or provider while honoring any {{GEO_SCOPE}} residency constraints. Data is encrypted at rest with managed keys, restore permissions follow least privilege, and every restore is logged. Only authorized staff on managed {{DEVICE_TYPES}} may initiate a restore into {{CRITICAL_SYSTEMS}}.

3.3 Recovery testing and targets

We test restores quarterly and record the actual recovery-time and data-loss figures for key systems in {{CRITICAL_SYSTEMS}}. Results are compared to targets, and the strategy is adjusted whenever a target is missed. Test plans, results, and any remediation are kept, and failed tests are tracked to closure.

3.4 Business continuity

A concise continuity playbook covers loss of workspace, loss of key staff, and SaaS outages for the {{LOCATION}} team. It is reviewed annually or after significant operational change, and critical scenarios are exercised in a tabletop at least once a year with outcomes recorded.

3.5 Disaster recovery activation

Clear thresholds define when disaster recovery is triggered. An incident commander authorizes activation and coordinates restoration of {{CRITICAL_SYSTEMS}} services. Activation decisions, timelines, and handoffs are documented, and a current contact list for critical vendors and providers is maintained.

3.6 Compliance measurement

The program is healthy when backups succeed at least 95 percent of the time and the most recent quarterly restore test is documented and within target. Larger teams (over {{EMPLOYEE_COUNT}} people) widen sampling across systems in {{CRITICAL_SYSTEMS}}.

3.7 Continual improvement

Findings from recovery exercises and advances in technology feed back into the backup and continuity strategy, reflecting {{INDUSTRY}} expectations and any change to {{GEO_SCOPE}} obligations.

4. Roles and responsibilities

Role Responsibility
Executive sponsor Accountable for the program; approves this policy
{{POLICY_OWNER_ROLE}} Maintains this policy and its procedures
Incident commander Authorizes disaster-recovery activation and coordinates restoration
All personnel Follow recovery procedures; report issues promptly

5. Compliance and exceptions

Missed backups or failed restore tests are escalated to leadership for immediate remediation. Any system excluded from backup requires documented justification and an alternative safeguard (such as rebuild automation), including any effect on {{DATA_TYPES}} residency in {{GEO_SCOPE}}. Exceptions require documented risk acceptance by {{APPROVER_TITLE}} and are time-limited and reviewed.

6. Review

This policy is reviewed at least annually and when significant change occurs.


Aligned to ISO/IEC 27001:2022. {{COMPANY_LEGAL_NAME}} is not affiliated with or endorsed by the relevant standards body; full standard text is copyrighted and is not reproduced here.

This template is authored by Keel in its own words. Clause references to ISO 27001 are factual identifiers; Keel is not affiliated with or endorsed by the standards bodies named. It is a starting point, not legal advice, review and adapt it for your organization.

Manage this policy in Keel

Keel ships this template in-product, fills the placeholders, maps it to your controls, and tracks approvals and reviews, so the policy stays live evidence, not a file in a drive. Start free.

Start free Browse all templates