View a markdown version of this page

Creating immutable backups with AWS Backup Vault Lock - Data Protection Reference Architectures with AWS Backup

Creating immutable backups with AWS Backup Vault Lock

This architecture details the key steps involved in setting up a central immutable backup data bunker that follows the principle of least privilege in a multi-account AWS Organization.

Architecture diagram showing how to create immutable backups with AWS Backup Vault Lock.
  1. Create a resource policy that limits CopyFromBackupVault to the Backup Data Bunker Account. Apply it to the AWS Backup vaults in each member account. Create a customer-managed KMS key for each vault.

  2. Set up a Backup Data Bunker account, create an AWS Backup Vault, and apply Vault Lock. Create a resource policy that limits CopyIntoBackupVault actions from specific OUs or accounts.

  3. Create a customer-managed KMS key in a separate Key Vault account and share it with the Central Vault Account. Implement additional security controls, including MFA on critical KMS API calls.

  4. Create a Service Control Policy that restricts access to appropriate IAM roles for backup operations into the Backup Data Bunker account.

  5. Create an AWS Backup policy with a copy operation into the Backup Data Bunker account. Apply it to the member accounts.

  6. Restrict access to the Backup Data Bunker account to specific users through AWS SSO and MFA, following a Break Glass workflow.

  7. The authenticated user receives AWS STS temporary credentials through federation. These credentials provide specific access to the Backup Data Bunker.

  8. Create audit reporting by using AWS Backup Audit Manager (BAM).

  9. Create an organizational CloudTrail for recording and monitoring policy changes and Central Backup Vault access patterns.

Further reading

For additional information, refer to

Diagram history

To be notified about updates to this reference architecture diagram, subscribe to the RSS feed.

ChangeDescriptionDate

Initial publication

Reference architecture diagram first published.

July 29, 2022

Initial publication

Reference architecture diagram first published.

July 29, 2022

Initial publication

Reference architecture diagram first published.

July 29, 2022

Initial publication

Reference architecture diagrams first published.

July 29, 2022

Note

To subscribe to RSS updates, you must have an RSS plugin enabled for the browser you are using.