Private Pierce

3-2-1 Backups and Border Crossings: Copy Separation and Cloud Exposure

The 3-2-1 model separates copies by count, media type, and storage location. Recovery testing adds a different check, while isolated or cloud-held copies retain technical limits that do not answer border-specific legal questions.

Not legal advice. This page is research, not compliance guidance.

What does the 3-2-1 model separate?

The 3-2-1 rule keeps the original plus two backups, keeps the copies on at least two different types of media, and stores one copy outside the data center; an isolated recovery-data instance is a separate safeguard.

The model separates three properties that can otherwise be collapsed into one checklist. Copy count is the original plus two backups. Media diversity places the copies on at least two different types of media. Storage separation keeps one copy outside the data center.

The separation matters because copies on the same media share the same risks, while copies stored together may all be destroyed by a calamity such as fire. More copies do not create media or location diversity when they remain exposed to the same failure.

CIS also calls for an isolated instance of recovery data. Its example implementations include version-controlled backup destinations through offline, cloud, or off-site systems or services. Isolation is a distinct control; no listed destination is described here as immune to access, compromise, or loss.

  • Copy count: the original plus two backups.
  • Media diversity: copies on at least two different types of media.
  • Storage separation: one copy outside the data center.
  • Recovery isolation: an isolated recovery-data instance, with offline, cloud, or off-site destinations given as examples.
Conceptual backup topology with separated copies and media, a restore-test loop, a cloud-copy path and a border-access limits boundary, with no quantities or outcomes.Conceptual backup topology with separated copies and media, a restore-test loop, a cloud-copy path and a border-access limits boundary, with no quantities or outcomes.

Figure 1. Copies, media, separation, restore testing, cloud copies and border access form distinct parts of the backup topology.

Source: none (concept)

What does recovery testing establish?

CIS Safeguard 11.5 calls for testing backup recovery quarterly, or more frequently, for a sampling of in-scope enterprise assets.

Recovery testing asks a different question from backup possession: whether a sampled recovery can be performed. CIS Safeguard 11.5 sets a quarterly-or-more-frequent cadence for testing a sampling of in-scope enterprise assets.

The sampling and enterprise qualifiers remain attached to that cadence. The safeguard does not become a universal schedule for every backup simply because it is cited on a general reference page.

A copy-count rule and a recovery test therefore describe different controls. One separates copies; the other tests recovery for a defined sample and scope.

  • Cadence: quarterly, or more frequently.
  • Test: backup recovery.
  • Scope: a sampling of in-scope enterprise assets.
  • Boundary: the cited enterprise safeguard is not presented as a universal schedule.

What exposure remains for cloud-held copies at a border?

Adversaries may access data from cloud storage and may obtain and abuse leaked credentials to reach cloud-storage objects; these technical access paths do not establish a border-search or compelled-access rule.

MITRE ATT&CK T1530 identifies technical access to cloud-stored data as an exposure. It says adversaries may obtain and abuse leaked credentials from source repositories, logs, or other means to access cloud-storage objects.

Cloud is also one of the example destinations CIS gives for version-controlled backups, alongside offline and off-site systems or services. That example does not establish a provider-specific encryption configuration, access promise, or protection from legal process.

The sources on this page supply no border-search or compelled-access rule. This page confines its answer to the technical cloud-access surface.

  • Technical exposure: adversaries may access data from cloud storage.
  • Credential path: leaked credentials from repositories, logs, or other means may be abused to access cloud-storage objects.
  • Recovery example: CIS includes cloud among possible version-controlled backup destinations.
  • Not established here: a cloud provider's backup configuration or a border-search or compelled-access legal rule.

What does copy separation fail to guarantee?

Copies on the same media share the same risks, copies stored together may all be destroyed by a calamity such as fire, and adversaries may access cloud storage; separation does not guarantee immunity from compromise, access, loss, or legal process.

Copy count cannot substitute for separation. When copies remain on the same media, they share the same risks. When copies remain in one place, a calamity such as fire may destroy all of them.

Cloud placement changes the destination without eliminating technical access paths. MITRE ATT&CK T1530 says adversaries may access cloud-stored data, including by obtaining and abusing leaked credentials from source repositories, logs, or other means.

An isolated, offline, cloud, or off-site copy is therefore not described here as immune to compromise, access, loss, or legal process. The supported conclusion is narrower: copy and destination separation address shared failure modes, while recovery testing checks whether a sampled restoration can be performed.

For the separate topic of name-resolution filtering boundaries, see DNS-Level Filtering.

  • Same-media limit: copies share the same risks.
  • Co-location limit: one calamity may destroy all copies stored together.
  • Cloud limit: adversaries may access cloud data, including through abused leaked credentials.
  • No immunity claim: isolation or destination choice does not establish freedom from compromise, access, loss, or legal process.