Skip to main content
Back to Glossary

IT & Cloud

3-2-1 Backup Rule

Also called: 3-2-1 rule, backup strategy

A backup baseline: three copies of data, on two different media types, with one copy offsite — extended today to include one immutable or offline copy.

The rule survives because it addresses independent failure modes: hardware failure, site loss, and human error. Ransomware added a fourth, since modern attacks specifically hunt and encrypt reachable backups — which is why the current guidance adds immutability or a genuine air gap.

Backups also need to be proven. An untested backup is a hypothesis; a documented restore test with a measured completion time is a capability. Test restores on a schedule, not after an incident.

Related terms

RTO / RPO
Two recovery targets: RTO is how long a system may be down, RPO is how much recent data may be lost. Together they dictate what backup and failover design is required.
Cloud Migration
Moving applications, data, and infrastructure from on-premises servers to cloud platforms — by lift-and-shift, re-platforming, or replacement with SaaS.
Endpoint Security
Protection on the device itself that detects malicious behaviour, contains it, and preserves the forensic trail — going beyond signature-based antivirus.

More IT & Cloud terms

Support305 in the press

All press coverage

Need this specified correctly?

Our engineers will review your drawings or quote and tell you exactly where 3-2-1 Backup Rule belongs in the design.

Talk to an engineer