You are using an unsupported browser. Please update your browser to the latest version on or before July 31, 2020.
You are viewing the article in preview mode. It is not live at the moment.
Backup & Restore Policy
print icon

Purpose

  • To provide secure storage for data assets critical to the workflow of SSMC business.
  • To provide a consistent framework to apply to the backup process.
  • To prevent loss of data in the case of accidental deletion / corruption of data, system failure, or disaster.
  • To permit timely restoration of archived data in the event of a disaster or system failure.

Policy Statement

  • All necessary software and data shall be backed up regularly to ensure that each application and its data can be recovered in the event of systems failure, loss of Service, or loss/corruption of data. Records and information shall be protected from loss, destruction, tampering.
  • This policy applies to all critical data stored on IT systems. The policy covers guidelines on, type of data to be backed up, frequency of backups, storage of backups, retention of backups, and restoration procedures.

Responsibilities

SSMC Staff

  • Ensure their critical files are stored in the user drive on OneDrive, allocated/ authorized to you.

Line Managers and Head of Departments

  • Ensure that the department critical files are stored in the respective department folder in OneDrive. Inform IT department with any critical data folders maintained outside the fileserver to schedule a manual/automated backup job for that.

IT Team

  • System Administrator: ensure the backup jobs and schedule is running as per plan, restore and test the backup copies regularly with the test and validation from the application team, Monitor the backup environment and reporting metrics, manage, and resolve any backup exceptions.
  • IT Infrastructure Manager: ensure compliance with backup storage, plan and security.
  • IT Applications Manager: It is the responsibility of the IT applications manager to identify all critical data systems and provide clear guidelines to system administrators to back up the application and their respective databases.
  • IT Director: Will be responsible for ensuring compliance with this policy and ensure all IT systems are backed up as per the best IT practices.

Procedure

This policy applies to all Servers and computing devices owned by SSMC.

  • Specific locations will be automatically backed up (e.g., File Server etc...)
  • Any location outside of the automated backup locations will be added on a per request basis upon approval from the IT Director.

Backups are NOT meant for the following purposes:

  • Maintaining a versioned history of data
  • Personal data such as photos, videos, music, and personal e-mail accounts, etc.
  • Programs (i.e., applications) of any type (personal or officially supported) like MS Office.

SSMC IT to ensure that the Data Backup and Recovery policy adheres to the following conditions for purposes of complying with the mandated organizational security requirements set forth and approved by management:

  • Backup Environments and identification of critical data:

A critical component of any data backup and recovery policy is to properly identify all environments and the associated data that required backup procedures. While critical environments, such as those relating to production, development, and staging require backups, it is also the platforms and the supporting systems within these environments that are to be identified, with applicable backup procedures in place.

The SSMC IT applications manager and SSMC IT infrastructure manager must identify what data is most critical to the organization. This can be done through a formal data classification process or through an informal review of information assets. Regardless of the method, critical data should be identified so that it can be given the highest priority during the backup process.

  • Data to be Backed Up:

This would include, but not limited to, the following IT systems, Platforms, and its supporting systems:

* Network devices backups, such as configuration file, rule sets, and other critical data.
  • Primary Backup Storage: The primary backup storage will store data as per data classification and the backup policy. Data will be transferred to secondary storage if it’s more than the approved period. All critical services/system data will be stored in primary storage for faster recovery to reduce the services/system outage.
  • Backup Retention

When determining the time required for backup retention, the organization must determine what number of stored copies of backup-up data is sufficient to effectively mitigate risk while preserving required data. The organization has determined that the following will meet all requirements:

Full Backups must be maintained for 3 months.

Backup Exceptions

  • Any exceptions to the types of backups and the default backup scheduling are to be approved by IT Managers or IT Director, with a valid and justified reason. Additionally, such exceptions – which are ultimately changes to the backup process – are to be submitted with a backup request form, reviewed, and approved by respective line manager or IT Director. Furthermore, changes to any of the tools and utilities used for the backup process also require the use of a documented change request, initiated by select personnel only and approved by the IT Director.
  • The backup platform is a critical component of the organization’s information technology infrastructure, thus great care and due diligence must be enacted when involving changes to its process.

Backup Reporting Metrics

Backup reporting activities, for all types of backups (i.e., Full, Differential, Incremental, etc.) are to be monitored on a regular basis to ensure the success of the backup process itself. Specifically, all backups conducted are to generate reporting metrics for which the system administrator and the IT Infrastructure are to review in a timely manner. Such reporting metrics include, but are not limited to, the following:

  • E-mails confirming the status and final result – such as success or failure – of the backup.
  • Reports generated confirming the status and final result – such as success or failure – of the backup.
  • Portals for which the system administrator can log into to review and confirming the status and result – such as success or failure – of the backup.
  • Backups that are successful are to be recorded as such, yet backup failure exceptions are to be handled immediately, with all appropriate steps undertaken for ensuring the timely backup of such data.

Backup Requests and Retrieval/ Restore

  • Backups are to be available in a timely manner for any such requests for restoration.
  • Such requests require completing the Backup & Restore Request form along with all applicable information as necessary.
  • The Backup and Restore request form or email is to be approved by the authored IT Manager or IT Director.
  • As for the restore process, it is to be conducted by the IT system administrator who coordinates with the requestor to test for ensuring a complete restoration was achieved, along with conducting any user-acceptance and system testing.

Backup Recovery Abilities

  • On a regular basis, such as quarterly, and no less than twice a year, IT system administrators are to examine, and report on the ability to effectively restore and recover data especially for those critical servers.
  • This required examining the facility for which data is being stored for ensuring its overall safety and security. Furthermore, all backup mediums, such as tapes, disks, and other supporting hardware and software utilities, are to be examined for ensuring proper function. Such information and all relevant findings are to be reported upstream to IT Director, with recommendations for improving upon or correcting any issues or concerns.

Appendices

Back and restore request form attached

Information Technology End user Policy attached

Conditional Clause

References

Joint Commission International: Joint Commission International Accreditation for Hospitals Sixth Edition, USA: Joint Commission Resources; 2017. MOI

Abbreviations and Definitions

  1. SSMC: Smart Salem Medical Center
  2. IT: Information technology
  3. FTP: File Transfer Protocol
  4. DNS: Domain Name Server
  5. USB: Universal Serial Bus
  6. Backup: To have a redundant copy of the data to a second location, solely for the purpose of safe keeping of that data.
  7. Full Back up: A backup that makes a complete copy of the data available on a system.
  8. Restoration: Also called “recovery.” The process of restoring the data from its backup-up state to its normal state so that it can be used and accessed in a regular manner.
  9. Primary Storage: is the main storage where all active data is stored. It’s the main data store for all IT Services/System running in the clinics and HQ.
  10. Archive: The saving of old or unused files onto offline mass storage media for the purpose of releasing on-line storage room.
Feedback
0 out of 0 found this helpful

scroll to top icon