|
Purpose:
The
purpose of this policy is to define the need for performing
periodic computer system backups to ensure that mission
critical administrative applications, data and archives are
adequately preserved and protected against data loss and
destruction.
Applicability:
Dedicated
Server only
Background:
Data
can be destroyed by system malfunction or accidental or
intentional means. Adequate backups will allow data to be
readily recovered as necessary. The ongoing availability of
data is critical to the operation of the company or
individually. In order, to minimize any potential loss or
corruption of this data. Responsibility for providing and
operating administrative applications needs to ensure that
data is adequately backed up by establishing and following
an appropriate system backup procedure.
THREAT SCENARIO:
The following typical threat is assumed for
a data backup policy as part of minimal baseline protection:
-
Demagnetization
of magnetic data media due to ageing or unsuitable
environmental conditions (temperature, air moisture)
-
Interference
of magnetic data media by extraneous magnetic fields
-
Inadvertent
deletion or overwriting of files
-
Technical
failure of storage device (head crash)
-
Faulty
data media
-
Uncontrolled
changes in stored data (loss of integrity)
-
Deliberate
deletion of files with computer-viruses etc
Policy:
Computer
systems that create or update mission critical data on a
daily basis need to be backed up on a daily basis to
minimize the exposure to loss of mission critical data. The
unit responsible for providing and operating such systems
must conduct a systematic and detailed investigation of all
the influencing factors leading to the compilation of a Minimal
Data Backup Policy.
MINIMAL DATA BACKUP POLICY:
The minimal data backup policy stipulates
the following:
-
Software:
All software, whether purchased or created personally,
is to be protected by at least one full backup.
-
System
data: System
data are to be backed up with at least one generation
per month.
-
Application
data: All
application data are to be protected by means of daily
full backup.
-
Storage:
All backups are to be stored in the network access
storage server.
Guidelines
RETENTION:
Backup retention will be available for 7 days, the system will automatic
overwrite the backup after 7 days.
PERSON-IN-CHARGE:
Each data backup process should have at least one primary
person-in-charge and one substitute. Data backup is a
critical security measure thus the relevant
persons-in-charge should be committed in writing to
adherence to the specific data backup (if established) or
minimal data back up policies and procedures.
TRAINING:
All persons-in-charge of data backup should receive adequate training on
the data backup process, data restoration process, retention
and storage. Regular refresher, motivation campaigns and
adherence checking on data backup must be conducted.
DOCUMENTATION:
Documentation is necessary for orderly and efficient data backup and
restoration. Once
the backup is in process, a log file will be sent via e-mail
to the person-in-charge, whereby to notify the status of the
backup. If,
there is an error from the log file, the person-in-charge
will check the on backup set.
This is to ensure that the person-in-charge is able
to monitor the whole process of the backup, where an
immediate action could be taken when any problems occurs.
RESTORATION OF DATA: The restoration of
data using data backups must be tested at irregular
intervals, at least after every modification to the data
backup procedure. It must at least once be proven that
complete data restoration is possible (e.g. all data
contained in a server must be installed on an alternative
server using substitute reading equipment to the data backup
writing equipment). This ensures reliable testing as to
whether:
-
Data
restoration is possible
-
The
data backup procedure is practicable
-
There
is sufficient documentation of the data backup, thus
allowing a substitute to carry out the data restoration
if necessary
-
The
time required for the data restoration meets the
availability requirements
This
restoration of data service is provided ONCE a month at no
additional charge. Should
any further request for additional restore service is
required; RM 250 will be charged for each service.
Unutilized restore services provided free are not
able to carry forward.
RECOVERY
SOLUTION FROM THE BACKUP SOLUTION: There is a need of approximately 4 hours to recover back the system
when the system is crash or problem with the hard disk.
BACKUP
COVER: The backups are on the operating system; web application and database
with log files of each.
BACKUP
TYPE:
The implementation of the backup is on a full backup system instead of
incremental backup.
FREQUENCY
OF BACKUP:
A weekly
basis backup is on for the operating system.
In daily basis will be performing to backup the web
application and database.
SIZE
OF BACKUP:
The size of backup are depends on the plan that been
subscribed, the details as following:
|
PLAN
|
SIZE OF BACKUP SPACE
|
|
RM
200
per month
|
2GB
|
|
RM
500
per month
|
5GB
|
|
RM
800
per month
|
10GB
|
|
RM
1,200
per month
|
20GB
|
DURATION
OF THE BACKUP:
It is
dependent on the total size of files or folders that
required to be backup. As an example, 15GB backup will
required an estimated time of 180 minutes.
BACKUP
PROCEDURE:
There is
a need of the users’ login in order the backup process
could be done.
|