It’s important from a backup perspective that it’s point in time as well, otherwise as soon as you get ransomware that encrypts your file you now have replicated those changes everywhere.
[1] https://www.backblaze.com/blog/the-3-2-1-backup-strategy/
Given the peeks that amazon has provided into the scale of S3, I don't know if you CAN 'back it up'.
Allegedly, compliance mode is unalterable by any account period, I guess the equivalent of the immutable attribute without an overriding account. I'm not immediately familiar with any literature on attacks on this feature, but I've also not searched hard; however, I know from my clients that it's an accepted form of WORM, and that cloud storages like S3 are considered in the same vein as tape when immutability is in play.
I suppose it will be a case in the future that proves the efficacy of AWS/Azure/s3 providers, but for now, a lot of regulatory policies for 3-2-1 allow for such storage to fulfill the "2" part of the 3-2-1 rule.
A slightly larger company also used tapes, and stored them at an undisclosed (to me) offsite location.
A much larger company kept it all in datacenters, but the "offline" backups were disconnected from the WAN when they weren't actively being used.
Depending on how much data you're backing up, sneakernet works.
When I was still in the office, my company had me rotate a set of backup hard drives between the office lockup and a strongbox in my house. The notion was that it was unlikely that both the office building and my house 12 miles away would both burn down at the same time.
Of course, now I'm working from home, so all of the eggs are in one basket again.
1) That nobody in our company actually knew where they were physically stored (insider risk?), but
2) That we had assurance that the physical storage was far enough away that a physical disaster in our area wouldn't also touch where the offline storage was located.
There's a concomitant jump in RTO if that's what you do this, but hopefully that's well understood among the stakeholders.
The drives are encrypted (Truecrypt) since they will be outside my physical control. The ones at the office I am prepared to abandon should I get fired/laid-off.
Imagine if you had a document that stored useful information. You had this document automatically replicated to another system in a different time zone every time there was a change.
You think you're doing great, if there is an outage in the one system you just get your important document from the other system.
Then one day someone accidentally copies and pastes the wrong data into the file. Now what do you do? If you goto your replicated copy it also has the bad data.
The answer is you should have had backups too. so you could go back an hour,a day or a week or even much longer. Depending on how much data you have, how often it changes, how important it is, and how quickly someone would notice bad data.
In short, if anything that happens to the files is immediately copied to the "backup" then you don't actually have a chance to recover from any software problems. Whereas, if you make a copy of the data every night and keep the last 30 copies you can find an issue like this and go back in time to retrieve the files from before it started.
A backup can be a 1:1 copy but it should be set up such that something going wrong with the primary (e.g. cryptolocker malware), can't affect it (since "something went wrong with the primary" is what the backup is intended to resolve).
To do that you could take the backup offline or use features like filesystem snapshots to ensure that changes can be rolled back.
If you `sudo rm -rf / --no-preserve-root` your drive, replication deletes everything, while backups let you restore to the last time you took a backup.
Backups are WRITE ONCE. They persist if the original is deleted or modified.
Separate infrastructure and geographical distribution are orthogonal.
Replication usually involves storage that is powered up and connected somehow to the same systems as the main storage; and any data that's corrupted on the main storage would propagate to the replicated storage.