The purpose of this policy is to ensure that critical systems, configurations, source code, and data can be restored in the event of hardware failure, software corruption, accidental deletion, cyber incidents, or other operational disruptions.
This policy applies to all infrastructure assets including:
The maximum acceptable amount of data loss shall not exceed:
24 hours
Critical systems shall be restored within:
24 hours
Critical assets shall be backed up daily.
Important assets shall be backed up weekly.
Recoverable assets may be rebuilt manually and do not require scheduled backups.
Examples include:
Frequency:
Daily at 02:00
Retention:
30 Days
Frequency:
Every Sunday
Retention:
12 Weeks
Frequency:
First Day of Each Month
Retention:
12 Months
Backup files shall be stored on the designated backup repository.
Backup access shall be restricted to authorized administrators.
Backup restorations shall be tested monthly.
A backup shall not be considered valid until a successful restoration test has been completed.
System Administrators are responsible for:
This policy shall be reviewed annually or following significant infrastructure changes.