← AWS projects

AWS · Backup Design

AWS Backup Vault Lock & Recovery Copies

Protect AWS recovery points from deletion or account compromise with centralized backup policy, immutable vault controls, independent copies, and regular restore testing.

PlatformAWS
DomainResilience
LevelIntermediate
Last reviewed2026-09-19
Use whenProtect recovery points from privileged deletion and keep independent recovery copies for operational, security, or regional failure scenarios.
Key decisionChoose governance versus compliance mode deliberately
Primary servicesAWS Backup · AWS Backup Vault Lock · AWS Organizations
Cost focusBackup storage and retention
On this page

Building blocks

AWS BackupAWS Backup Vault LockAWS OrganizationsAWS KMSCross-Region copyCross-account copy

Design goal

Keep recoverable copies available even when production credentials, accounts, or a Region are affected, while making retention and restore responsibilities explicit.

Success criteria

  • Centralize backup policy
  • Use Vault Lock where immutability is required
  • Separate recovery copies by account or Region
  • Test restore and access procedures

Architecture

Apply AWS Backup plans to supported resources, store recovery points in encrypted vaults, use Vault Lock for governance or compliance immutability, and create supported cross-account or cross-Region copies when required.

Architecture flow

  • AWS workloads
  • Backup plan
  • Primary vault
  • Vault Lock
  • Recovery copy vault
  • Restore test
AWS WorkloadsBackup PlanLocked VaultRecovery CopyRestore Test
AWS Workloads
Backup Plan
Locked Vault
Recovery Copy
Restore Test

Architecture decisions

Decision

Choose governance versus compliance mode deliberately

Why

Governance mode can be changed by sufficiently privileged users, while compliance mode becomes immutable after its grace period and requires careful retention planning.

Trade-off

Compliance mode provides stronger immutability but removes operational flexibility after the grace period; governance mode is easier to change but relies more heavily on privileged-access controls.

Decision

Use independent copies for broader failure isolation

Why

Cross-account or cross-Region copies can reduce dependence on the production account or Region, subject to feature support for the protected resource.

Trade-off

Cross-account or cross-Region copies improve isolation but add storage, transfer, key-management, and restore-access complexity.

Security

Protect the control and data paths deliberately. Use dedicated backup roles, KMS controls, AWS Organizations policies where appropriate, and destination-vault permissions that prevent workload administrators from deleting independent recovery copies.

Availability

Design for the failure domain that must be survived. Backup copies should be placed across the account or regional failure boundaries that the recovery requirement is intended to survive.

Disaster recovery

Treat regional recovery as a separate operating state. AWS Backup provides recovery data protection; application failover orchestration and service-specific replication may still be required for low RTO/RPO workloads.

Cost drivers

  • Backup storage and retention
  • Cross-Region data transfer and copy storage
  • Cross-account recovery design
  • KMS usage
  • Restore testing frequency

Design assumptions

  • Resource types support the selected AWS Backup copy and retention features
  • Compliance-mode retention is approved before the grace period expires

Implementation plan

  1. Define recovery tiers, backup frequency, retention, and copy requirements before creating policies.
  2. Create encrypted backup vaults with administration separated from workload operators where the recovery model requires it.
  3. Configure Vault Lock retention bounds and move to the intended governance or compliance mode only after the policy has been tested.
  4. Create cross-account or cross-Region copies only where the required failure scope justifies the additional storage and transfer cost.
  5. Centralize failed-job alerts, vault activity, and compliance reporting, then schedule representative restore tests.

Validate the design

  • Confirm Vault Lock state and retention bounds match the approved policy.
  • Attempt a controlled prohibited deletion or retention change and confirm the vault blocks it as expected.
  • Restore a representative workload from the independent copy and verify the recovered data is usable.
  • Simulate loss of the primary account or Region and confirm the recovery team can still access the intended copy.

Architecture basis

Continue a learning path