Backups are formally required to be stored in a location that cannot be modified or deleted by attackers
Among A.5.1's topic-specific policies, Sekit's Immutable and offsite backups policy requires at least one backup copy that attackers cannot alter or delete.
The immutable-backup policy facet requires at least one copy to sit offsite or in storage attackers cannot alter, directly addressing A.8.13's expectation that ransomware cannot destroy every copy.