View a markdown version of this page

Cross-account and Region data protection with AWS Backup and AWS Organizations - Data Protection Reference Architectures with AWS Backup

Cross-account and Region data protection with AWS Backup and AWS Organizations

This reference architecture shows how to implement a consistent backup strategy through multiple AWS accounts and Regions, and copy backups between them through an automated, policy-driven approach.

Architecture diagram showing cross-account and Region data protection with AWS Backup and AWS Organizations.
  1. Use AWS CloudFormation StackSets to create AWS Backup resources such as an IAM role, backup vault, AWS KMS key, and access policies.

  2. Create a backup policy. Define the frequency, retention, lifecycle, backup copy settings, and resource assignment tag values. Then attach the policy to a target.

  3. StackSets and backup policies support both organizational units (OUs) or specific AWS accounts as targets.

  4. Use Service Control Policies (SCPs) to protect your AWS Backup resources from unwanted modification, deletion, or use.

  5. After configuration and attachment to a target, AWS Backup creates a backup plan in all member accounts that belong to the OU.

  6. Based on the plan schedule, backup jobs run and recovery points appear in the backup vault.

  7. For cross-account backup copies, use a customer-managed AWS KMS key on the originating resource and source backup vault. Then provide the necessary permissions to the key and target vault.

  8. Cross-Region backups can occur within the same account or to a different account in a single step. The backup policy defines the vault name and destination account.

  9. Forward backup events through an https://docs.aws.amazon.com/eventbridge/latest/userguide/eb-what-is.html rule to a central custom event bus for centralized monitoring. Then trigger email notifications by using Amazon SNS.

  10. Monitor cross-account and Region activities through the AWS Backup console in the AWS Organizations management account.

Further reading

For additional information, refer to

Diagram history

To be notified about updates to this reference architecture diagram, subscribe to the RSS feed.

ChangeDescriptionDate

Initial publication

Reference architecture diagram first published.

July 29, 2022

Initial publication

Reference architecture diagram first published.

July 29, 2022

Initial publication

Reference architecture diagram first published.

July 29, 2022

Initial publication

Reference architecture diagrams first published.

July 29, 2022

Note

To subscribe to RSS updates, you must have an RSS plugin enabled for the browser you are using.