Embed
Email

Data Backup and Restoration Procedure

Document Sample

Shared by: dfgh4bnmu
Categories
Tags
Stats
views:
4
posted:
10/19/2011
language:
English
pages:
4
Data Backup and Restoration Procedure ICTPR 2.2





Data Backup and Restoration

Procedure

ICTPR 2.2





Related Policy ICT Security Policy



Procedure Scope All data stores associated with ICT Services, Facilities

and Infrastructure maintained and operated by IT

Resources

Commencement Date May 2010



Review Date Review 1 – May 2011

Review 2 – May 2014

Organisational Unit Unit name: IT Resources – ICT Security Officer

responsible for day- Phone: +61 3 6226 6361

to-day operation of Fax: +61 3 6226 7171

the procedure Email: ICT.Security.Officer@utas.edu.au



PROCEDURE



1 Purpose



To minimise ICT Security and Business Continuity risks associated with data

loss by defining a sound backup regime for all centralised ICT data services.



2 Exceptions



There are no exceptions to this Procedure.



3 Definitions and Acronyms



Archive Move data to another medium (the backup media) for

long term storage. Archive is intended for the storage of

data that do not need to be kept immediately accessible,

but which may possibly be needed at some point in the

future.

Backup Copy data to another medium so that, if the active data

are lost, they can be recovered in a recent if not

completely current version. Backup is primarily intended

for disaster recovery.

Data Numerical represented in a form suitable for processing

by computer.

Data Custodian A nominated trustee of University of Tasmania data. A

data custodian holds responsibility for protecting the data

as defined by University of Tasmania Policies and

Procedures.



Data Custodians may be nominated by their role with the

University of Tasmania, or by their role in relation to an

ICT Service. A Data Custodian will typically have

responsibility for the management of a location of shared

information, a database, or an application referencing a

1

Data Backup and Restoration Procedure ICTPR 2.2







database distinct from the role of a systems administrator.



Data Custodians may include but are not restricted to:



 Application Managers

 Data Managers

 Business Systems Owners

Information Processed, stored, or transmitted data such that the data

holds a meaning or can be interpreted.

ICT Officer The University of Tasmania staff authorised by the

Faculty, School and/or Director, IT Resources to maintain

and/or administer ICT Services, Facilities Infrastructure,

user level accounts and passwords.

Restore The recovery of point-in-time copies of active data.



4 Links to Related Forms, Records and Electronic Databases



ICT Security Policy



5 Detailed Steps, Procedures and Actions



Procedure (including key steps) Responsibility

1.

The frequency and extent of backups must be in Data Custodian

accordance with the importance of the information.



The Data Custodian will determine the importance of

the data via risk assessment and notify IT Resources

of the required backup frequency.

2.

The backup and recovery process for each system ICT Officer

must be documented, and reviewed at least Data Custodian

annually.

3.

Physical access controls must be implemented to ICT Officer

protect physical backup media. ICT Security Officer



When backup media is stored onsite (within IT

Resources locations) physical access controls must

meet those defined in the ICT Physical Security

Procedure.



Offsite backup storage locations must meet or

exceed the physical access controls of the source

location.



Backup media must be protected in accordance with

the highest sensitivity level of information stored.

4.

Backup operations must include verification ICT Officer

processes to ensure the integrity of the operation.

5.

Backups must be periodically tested, at least ICT Officer



2

Data Backup and Restoration Procedure ICTPR 2.2





annually, to ensure that they are recoverable.

6.

Procedures between IT Resources and any offsite ICT Security Officer

backup storage vendor must be reviewed at least Director, IT Resources

annually.

7.

Tape drives, cleaning tapes and other backup media ICT Officer

must be maintained according to manufacturer’s

recommendations.

8.

Backup tapes and other backup media must have at ICT Officer

a minimum the following identifying criteria:

 System name;

 Creation date;

 Backup set name, and;

 Data Custodian contact information.



6 Key Words



 Backup

 Recovery

 ICT

 Security



7 Supporting Guidelines, Flow-charts, Check-lists, etc



Nil



RESPONSIBILITIES



Implementation ICT Security Officer

ICT Officer

Compliance ICT Security Officer

ICT Officer

Development/Review Director, IT Resources

ICT Security Officer

Interpretation and ICT Security Officer

Advice



WHO SHOULD KNOW THIS PROCEDURE?



 ICT Officer



EFFECTIVENESS OF THIS PROCEDURE



 Measured reduction in data loss

 Improved Disaster Recovery operations

 Improved management of backup media

 Improved security of backup media









3

Data Backup and Restoration Procedure ICTPR 2.2









PROCEDURE HISTORY



Revision Ref. No. Version 1



Approved or Approved

Rescinded

Policy Maker (Title) Director, IT Resources



Policy Maker (signed)

(Signature)

Date 13 May 2010









4



Related docs
Other docs by dfgh4bnmu
By registering with docstoc.com you agree to our
privacy policy

You are almost ready to download!

You are almost ready to download!