Backup Policy. Document Title: No. Pages 5. Document Type: Policy. Scope: OCIO, Operations Branch

Size: px
Start display at page:

Download "Backup Policy. Document Title: No. Pages 5. Document Type: Policy. Scope: OCIO, Operations Branch"

Transcription

1 Document Title: Backup Policy Document Type: Policy No. Pages 5 Scope: OCIO, Operations Branch Trim Number: DOC02866/2007 Revision: 3 Treasury Board Approval: TBM Date Implemented: 2011/03/08 Approval Date: Review Date: 2013/05/26 Lead Branch - Name: Randy Mouland, Executive Director Operations Chief Information Office: Jean Tilley, Chief Information Officer (A) Treasury Board Approval: Secretary (yyyy-mm-dd) (yyyy-mm-dd) (yyyy-mm-dd) Authority Name Authority Name Authority Name

2 Table of Contents 1.0 Introduction Purpose Scope Definitions Backup Retention Scheduling Exceptions Security Off-Site Storage Supporting Documentation Disposal Testing Approval Process Change Policy References... 5 Backup Policy Page 2 of 5

3 1.0 Introduction Today, governments face an ever expanding set of information protection challenges and regulatory information retention requirements. The availability of information is crucial to the business of government. Likewise, recovering this information in a timely manner after a data loss event is essential. 2.0 Purpose The purpose of this policy is to establish the Office of the Chief Information Officer s (OCIO) timeline and approach for the backup of client data to enable recovery should it be required. 3.0 Scope This policy covers backup and recovery services provided by the OCIO to departments and public bodies to which it supplies these services. 4.0 Definitions Backup: A copy or snapshot in time of electronic data created to facilitate recovery for business continuity or disaster recovery purposes. Client: Departments and public bodies to which the OCIO provides backup and recovery services. 5.0 Backup OCIO has a standard approach for its backup services while, at the same time, offering a measure of operational flexibility. 5.1 Retention Data written to backup media is preserved indefinitely as long as the original data used to make the backup remains on the source system. Data which is not deleted by clients is backed up indefinitely by the OCIO. The standard backup retention period for data which was replaced or removed at its source (e.g. electronic records deleted by clients) is 30 calendar days from the date of the change. In cases where the backup methodology employed uses a retention window rather than the default period of 30 calendar days, retention will be set as low as possible, while maintaining a minimum of 30 calendar days from the date of the change. In such cases, the exception(s) will be documented by the OCIO. Backup Policy Page 3 of 5

4 Government of Newfoundland and Labrador Office of the Chief Information Officer If a client can demonstrate a requirement for an exception to the thirty calendar day retention period, a request may be made to the OCIO (refer to Section 5.3). 5.2 Scheduling The standard backup schedule as defined by the OCIO is daily, seven days a week unless otherwise agreed upon as per Section Exceptions If an exception to the OCIO s standard backup process is required for reasons such as Access to Information requests or legal discovery requirements, the supporting documentation and authorization from the Deputy Minister or equivalent of the requesting department or public body is required. 5.4 Security Access to backup media, devices or backup systems software is restricted to authorized staff. Requests for physical or system access by unauthorized staff must be directed to the Executive Director, Operations Branch, OCIO. 5.5 Off-Site Storage Copies of backups will be stored in a safe location, physically distant from the data processing center to facilitate disaster recovery efforts. 5.6 Supporting Documentation Documentation regarding the build and recovery of the implemented backup solution must be maintained in locations that allow for access during disaster recovery efforts. Tape and other backup media must be clearly labelled or bar coded to reflect the data written to the media and the date which the backup action occurred. 5.7 Disposal Backup media must be physically destroyed in a secure manner that renders the stored data irretrievable. Media destruction shall be conducted by authorized staff or by an approved designate. All requests for destruction require a Disposal Certificate upon completion declaring that the data has been securely destroyed. 5.8 Testing The OCIO is responsible for periodic testing of its backup and recovery services. Client involvement is required to test and confirm successful recovery of information for which they are responsible. Backup Policy Page 4 of 5

5 Government of Newfoundland and Labrador Office of the Chief Information Officer 6.0 Approval Process Treasury Board Office of the Chief Information Officer - Executive Director - Operations Branch Office of the Chief Information Officer Chief Information Officer 7.0 Change Policy This policy will be changed as necessary in order to appropriately reflect current software and hardware standards. Reviews will take place on a biennial basis. Substantial changes will be made available to employees at the earliest possible convenience. 8.0 References N/A Backup Policy Page 5 of 5

Trim DOC6883/2008 Revision 03 Treasury Board Approval Not required for Guidelines. Mark Coffey

Trim DOC6883/2008 Revision 03 Treasury Board Approval Not required for Guidelines. Mark Coffey Document Title: Video Conference Guidelines Document Type: Guideline No. Of Pages 6 Scope: Government of Newfoundland and Labrador Trim DOC6883/2008 Revision 03 Treasury Board Approval Not required for

More information

E-Mail Policy. Government of Newfoundland and Labrador (GNL)

E-Mail Policy. Government of Newfoundland and Labrador (GNL) Document Title: E-Mail Policy Document Type: Policy No. Of Pages 6 Scope: Government of Newfoundland and Labrador (GNL) Trim # DOC15481/2009 Revision ( # ) 26 Treasury Board Approval ( # ) TBM2009-298

More information

GUIDELINE RECORDS AND INFORMATION INVENTORY

GUIDELINE RECORDS AND INFORMATION INVENTORY Government of Newfoundland and Labrador Office of the Chief Information Officer Information Management Branch GUIDELINE RECORDS AND INFORMATION INVENTORY Guideline (Definition): OCIO Guidelines derive

More information

GUIDELINE INFORMATION MANAGEMENT (IM) PERFORMANCE MEASUREMENT

GUIDELINE INFORMATION MANAGEMENT (IM) PERFORMANCE MEASUREMENT Government of Newfoundland and Labrador Office of the Chief Information Officer Information Management Branch GUIDELINE INFORMATION MANAGEMENT (IM) PERFORMANCE MEASUREMENT Guideline (Definition): OCIO

More information

Identify and Protect Your Vital Records

Identify and Protect Your Vital Records Identify and Protect Your Vital Records INTRODUCTION The Federal Emergency Management Agency s Federal Preparedness Circular 65 states The protection and ready availability of electronic and hardcopy documents,

More information

This policy is not designed to use systems backup for the following purposes:

This policy is not designed to use systems backup for the following purposes: Number: AC IT POL 003 Subject: Backup and Restore Policy 1. PURPOSE The backup and restore policy establishes the need and rules for performing periodic system backup to permit timely restoration of Africa

More information

Information Management and Protection Policy

Information Management and Protection Policy Document Title: Information Management and Protection Policy Document Type: Policy No. Of Pages (11) Scope: Government of Newfoundland and Labrador and Public Bodies supported by the Office of the Chief

More information

State of Michigan Records Management Services. Frequently Asked Questions About E mail Retention

State of Michigan Records Management Services. Frequently Asked Questions About E mail Retention State of Michigan Records Management Services Frequently Asked Questions About E mail Retention It is essential that government agencies manage their electronic mail (e mail) appropriately. Like all other

More information

Education and Workforce Development Cabinet POLICY/PROCEDURE. Policy Number: EDU-06 Effective Date: April 15, 2006 Revision Date: December 20, 2012

Education and Workforce Development Cabinet POLICY/PROCEDURE. Policy Number: EDU-06 Effective Date: April 15, 2006 Revision Date: December 20, 2012 Education and Workforce Development Cabinet POLICY/PROCEDURE Policy Number: EDU-06 Effective Date: April 15, 2006 Revision Date: December 20, 2012 Subject: Backup Procedures Tower and Server Farms Policy:

More information

CITY OF ELK GROVE CITY COUNCIL STAFF REPORT

CITY OF ELK GROVE CITY COUNCIL STAFF REPORT CITY OF ELK GROVE CITY COUNCIL STAFF REPORT AGENDA ITEM NO. 8.4 AGENDA TITLE: Adopt resolution establishing policy for the retention of electronic mail records and call recordings maintained by IT Services

More information

B. Preservation is not limited to simply avoiding affirmative acts of destruction because day-to-day operations routinely alter or destroy evidence.

B. Preservation is not limited to simply avoiding affirmative acts of destruction because day-to-day operations routinely alter or destroy evidence. This is a sample approach to developing a sound document collection process, referenced at Section II(7)(vi) of the Guidelines on Best Practices for Litigating Cases Before the Court of Chancery. It should

More information

HOW TO DEVELOP A RECORDS PROCEDURES MANUAL. New York State Unified Court System Division of Court Operations Office of Records Management

HOW TO DEVELOP A RECORDS PROCEDURES MANUAL. New York State Unified Court System Division of Court Operations Office of Records Management HOW TO DEVELOP A RECORDS PROCEDURES MANUAL New York State Unified Court System Division of Court Operations Office of Records Management June 2003 HOW TO DEVELOP A RECORDS PROCEDURES MANUAL PURPOSE OF

More information

INTERNATIONAL SOS. Data Retention, Archiving and Destruction Policy. Version 1.07

INTERNATIONAL SOS. Data Retention, Archiving and Destruction Policy. Version 1.07 INTERNATIONAL SOS Data Retention, Archiving and Destruction Policy Document Owner: LCIS Division Document Manager: Group General Counsel Effective: January 2009 Revised: 2015 All copyright in these materials

More information

Version: 1.5 2014 Page 1 of 5

Version: 1.5 2014 Page 1 of 5 Version: 1.5 2014 Page 1 of 5 1.0 Overview A backup policy is similar to an insurance policy it provides the last line of defense against data loss and is sometimes the only way to recover from a hardware

More information

Electronic Data Retention and Preservation Policy 1

Electronic Data Retention and Preservation Policy 1 1 Purpose and Scope The purpose of this policy is to: Identify the types of College-related electronic information, including the location of the information; Identify what departments or individuals are

More information

Technical Competency Framework for Information Management (IM)

Technical Competency Framework for Information Management (IM) Technical Competency Framework for Information Management (IM) Office of the Chief Information Officer (OCIO) June 15, 2009 Table of contents IM Competency Framework...1 Competency 1: Information Management

More information

Strategy for Email Management in Canadian Jurisdictions

Strategy for Email Management in Canadian Jurisdictions Strategy for Email Management in Canadian Jurisdictions Email is a fundamental part of doing business today, and the management of email has become a critical issue across all jurisdictions. All governments

More information

HIPAA Security Matrix

HIPAA Security Matrix HIPAA Matrix Hardware : 164.308(a)(1) Management Process =Required, =Addressable Risk Analysis The Covered Entity (CE) can store its Risk Analysis document encrypted and offsite using EVault managed software

More information

INFORMATION GOVERNANCE POLICY: DATA BACKUP, RESTORE & FILE STORAGE HANDLING

INFORMATION GOVERNANCE POLICY: DATA BACKUP, RESTORE & FILE STORAGE HANDLING INFORMATION GOVERNANCE POLICY: DATA BACKUP, RESTORE & FILE STORAGE HANDLING Original Approved by: Policy and Procedure Ratification Sub-group on 23 October 2007 Version 2.2 Approved by : Information Governance

More information

July 30, 2009. Internal Audit Report 2009-08 Information Technology Business Continuity Plan Information Technology Department

July 30, 2009. Internal Audit Report 2009-08 Information Technology Business Continuity Plan Information Technology Department Internal Audit Report 2009-08 Introduction. The Municipality depends heavily on technology and automated information systems, and their disruption for even a few days could have a severe impact on critical

More information

Economic Realities in the Management of Public Records. George Bakolia Senior Deputy State Chief Information Officer November 4, 2011

Economic Realities in the Management of Public Records. George Bakolia Senior Deputy State Chief Information Officer November 4, 2011 Economic Realities in the Management of Public Records George Bakolia Senior Deputy State Chief Information Officer November 4, 2011 Outline Statutory and other requirements Hidden vs. direct costs Records

More information

How To Manage Records In A Cloud

How To Manage Records In A Cloud Retention & Disposition of Records Residing in a Public Cloud: A Risk Management Approach Patricia C. Franks, PhD, IGP, CA, CRM International Symposium October 17, 2014 to mitigate risk Not all information

More information

RECORDS MANAGEMENT POLICY

RECORDS MANAGEMENT POLICY RECORDS MANAGEMENT POLICY PURPOSE The purpose of this policy is to: Assist departments in effective utilization of space and efficient information retrieval; Establish guidelines for disposal of records;

More information

BEST PRACTICES FOR MANAGEMENT OF LOTUS NOTES EMAIL RECORDS September 4, 2003

BEST PRACTICES FOR MANAGEMENT OF LOTUS NOTES EMAIL RECORDS September 4, 2003 BEST PRACTICES FOR MANAGEMENT OF LOTUS NOTES EMAIL RECORDS September 4, 2003 All information in a Lotus Notes email system workspace is a record. Following are best practices for managing those records:

More information

Records Management Policy

Records Management Policy Records Management Policy Responsible Officer Chief Operating Officer Approved by Vice-Chancellor Approved and commenced April, 2014 Review by April, 2017 Relevant Legislation, Ordinance, Rule and/or Governance

More information

HIPAA CRITICAL AREAS TECHNICAL SECURITY FOCUS FOR CLOUD DEPLOYMENT

HIPAA CRITICAL AREAS TECHNICAL SECURITY FOCUS FOR CLOUD DEPLOYMENT HIPAA CRITICAL AREAS TECHNICAL SECURITY FOCUS FOR CLOUD DEPLOYMENT A Review List This paper was put together with Security in mind, ISO, and HIPAA, for guidance as you move into a cloud deployment Dr.

More information

CITY OF ANDERSON ELECTRONIC RECORD RETENTION POLICY

CITY OF ANDERSON ELECTRONIC RECORD RETENTION POLICY CITY OF ANDERSON ELECTRONIC RECORD RETENTION POLICY Electronic records include all documents, applications, databases, spreadsheets, email and other materials created on a computer. I. Records Management

More information

Best Practices: Take the Guesswork out of Backup and Recovery This Is the Presentation Title

Best Practices: Take the Guesswork out of Backup and Recovery This Is the Presentation Title Best Practices: Take the Guesswork out of Backup and Recovery This Is the Presentation Title This area is for a subtitle and/or speaker name Agenda Best Practices Automation Validation Testing SonicWALL

More information

Backup Policy (ITP004) Information Technology Services Department

Backup Policy (ITP004) Information Technology Services Department Introduction This policy defines the backup guidelines for systems within the Central Dauphin School District. These systems are typically servers, Storage Area Network devices (SAN), or Network-Attached

More information

State of Michigan Records Management Services. Guide to E mail Storage Options

State of Michigan Records Management Services. Guide to E mail Storage Options State of Michigan Records Management Services Guide to E mail Storage Options E mail is a fast, efficient and cost effective means for communicating and sharing information. However, e mail software is

More information

IT Roles in Loss Prevention. Presented by: Ann Ostrander, Director of Loss Prevention Kirkland & Ellis LLP

IT Roles in Loss Prevention. Presented by: Ann Ostrander, Director of Loss Prevention Kirkland & Ellis LLP IT Roles in Loss Prevention Presented by: Ann Ostrander, Director of Loss Prevention Kirkland & Ellis LLP What is Loss Prevention (Risk Management)? Mitigate risk Protect the Firm s assets Departments

More information

Preservation and Production of Electronic Records

Preservation and Production of Electronic Records Policy No: 3008 Title of Policy: Preservation and Production of Electronic Records Applies to (check all that apply): Faculty Staff Students Division/Department College _X Topic/Issue: This policy enforces

More information

Information Security Policy September 2009 Newman University IT Services. Information Security Policy

Information Security Policy September 2009 Newman University IT Services. Information Security Policy Contents 1. Statement 1.1 Introduction 1.2 Objectives 1.3 Scope and Policy Structure 1.4 Risk Assessment and Management 1.5 Responsibilities for Information Security 2. Compliance 3. HR Security 3.1 Terms

More information

UMHLABUYALINGANA MUNICIPALITY

UMHLABUYALINGANA MUNICIPALITY UMHLABUYALINGANA MUNICIPALITY BACKUP AND RESTORE POLICY Backup and Restore Policy Approval and Version Control Approval Process: Position or Meeting Number: Date: Originator Recommended by Director of

More information

Administrators Guide Multi User Systems. Calendar Year

Administrators Guide Multi User Systems. Calendar Year Calendar Year 2012 Enter Facility Name Here HIPAA Security Compliance Workbook For Core Measure 15 of Meaningful Use Requirements Annual Risk Analysis Administrators Guide Multi User Systems 1 HIPPA Compliance

More information

Records Management Electronic Records and Electronic Discovery

Records Management Electronic Records and Electronic Discovery Records Management Electronic Records and Electronic Discovery Office of the Secretary of the Commonwealth Division of Public Records 617-727-2832 www.sec.state.ma.us/pre/predix.htim Agenda Records Management

More information

Review of Document Imaging Railroad Unemployment Insurance Act Programs Report No. 01-01, November 17, 2000

Review of Document Imaging Railroad Unemployment Insurance Act Programs Report No. 01-01, November 17, 2000 Review of Document Imaging Railroad Unemployment Insurance Act Programs Report No. 01-01, November 17, 2000 This report represents the results of the Office of Inspector General s (OIG) review of the Railroad

More information

IN THE UNITED STATES DISTRICT COURT FOR THE DISTRICT OF COLUMBIA

IN THE UNITED STATES DISTRICT COURT FOR THE DISTRICT OF COLUMBIA Case 1:07-cv-01707-HHK-JMF Document 66 Filed 04/17/2008 Page 1 of 7 IN THE UNITED STATES DISTRICT COURT FOR THE DISTRICT OF COLUMBIA CITIZENS FOR RESPONSIBILITY AND ETHICS IN WASHINGTON, Plaintiff, v.

More information

Sibling Rivalries: Integrating Data Management Technologies

Sibling Rivalries: Integrating Data Management Technologies Sibling Rivalries: Integrating Data Management Technologies Randy Kerns Senior Strategist Evaluator Group Agenda Perspective Sibling elements in managing storage of data Data Protection Tiering Archiving

More information

Introduction Thanks Survey of attendees Questions at the end

Introduction Thanks Survey of attendees Questions at the end Introduction Thanks Survey of attendees Questions at the end 1 Electronic records come in a variety of shapes and sizes and are stored in a multitude of ways. Just what are you managing? Video Cloud computing

More information

STI GROUP DISCUSSION WRITTEN PROJECT

STI GROUP DISCUSSION WRITTEN PROJECT STI GROUP DISCUSSION WRITTEN PROJECT ediscovery FOR GIAC ENTERPRISES - DATA CLASSIFICATION, RETENTION, AND LITIGATION POLICIES AND PROCEDURES Version 1.1 September 22, 2007 Team: Russell Meyer, Brad Ruppert

More information

3. Ensure the management of information is compliant with legislative requirements to maximise the benefits and minimise risks;

3. Ensure the management of information is compliant with legislative requirements to maximise the benefits and minimise risks; Enterprise Content Management (ECM) Policy Version Information A. Introduction Purpose 1. Outline and articulate the strategy for enterprise content management across Redland City Council (RCC). This document

More information

Gain Efficiency, Cost Savings and Compliance with Iron Mountain s Portfolio of Services

Gain Efficiency, Cost Savings and Compliance with Iron Mountain s Portfolio of Services ONE SOLUTION Maximize the Business Value of Your Information Gain Efficiency, Cost Savings and Compliance with Iron Mountain s Portfolio of Services In today s world, information whether in paper or digital

More information

I N F O R M A T I O N I M M E D I A C Y, D I S C O V E R Y & C O N T I N U I T Y

I N F O R M A T I O N I M M E D I A C Y, D I S C O V E R Y & C O N T I N U I T Y White Paper By Bill Tolson Mimosa Systems, Inc. May 2007 Cost and Breakeven Analysis of Email Discovery Using Mimosa NearPoint Email Archiving with ediscovery Option Large Health Supplement Manufacturer

More information

SITA Security Requirements for Third-Party Service Providers that Access, Process, Store or Transmit Data on Behalf of SITA

SITA Security Requirements for Third-Party Service Providers that Access, Process, Store or Transmit Data on Behalf of SITA SITA Information Security SITA Security Requirements for Third-Party Service Providers that Access, Process, Store or Transmit Data on Behalf of SITA September, 2012 Contents 1. Introduction... 3 1.1 Overview...

More information

Whitepaper: Email archiving and storage management solution for compliance, retention management and electronic discovery

Whitepaper: Email archiving and storage management solution for compliance, retention management and electronic discovery Whitepaper: Email archiving and storage management solution for compliance, retention management and electronic discovery by David Bailey February, 2011 Doc# 022311-01 www.doculex.com Intended Audience

More information

Information Management Advice 18 - Managing records in business systems: Overview

Information Management Advice 18 - Managing records in business systems: Overview Information Management Advice 18 - Managing records in business systems: Overview Introduction The purpose of this Advice is to assist agencies to identify and manage State records in business systems,

More information

Planning for a Disaster Using Tivoli Storage Manager. Laura G. Buckley Storage Solutions Specialists, Inc.

Planning for a Disaster Using Tivoli Storage Manager. Laura G. Buckley Storage Solutions Specialists, Inc. Planning for a Disaster Using Tivoli Storage Manager Laura G. Buckley Storage Solutions Specialists, Inc. Objective Discuss how DRM assists in the recovery of the ADSM server and clients in a disaster

More information

CMS IT - Requirements For Electronic Storage

CMS IT - Requirements For Electronic Storage Chief Information Officer Office of Information Services Centers for Medicare & Medicaid Services CMS Operational Policy for Disk Space Storage Management August 2004 Document Number: CMS-CIO-POL-INF02-01

More information

RECORD RETENTION & DESTRUCTION POLICY

RECORD RETENTION & DESTRUCTION POLICY City & County of San Francisco BOARD OF APPEALS RECORD RETENTION & DESTRUCTION POLICY The Board of Appeals Record Retention and Destruction Policy is adopted pursuant to Chapter 8 of the San Francisco

More information

HIPAA BUSINESS ASSOCIATE AGREEMENT

HIPAA BUSINESS ASSOCIATE AGREEMENT HIPAA BUSINESS ASSOCIATE AGREEMENT This Business Associate Agreement ( BA Agreement ) is entered into by Medtep Inc., a Delaware corporation ( Business Associate ) and the covered entity ( Covered Entity

More information

Massachusetts Statewide Records Retention Schedule 02-11 August 2014 Supplement www.sec.state.ma.us/arc/arcrmu/rmuidx.htm

Massachusetts Statewide Records Retention Schedule 02-11 August 2014 Supplement www.sec.state.ma.us/arc/arcrmu/rmuidx.htm Massa achusetts Statewide Records Retention Schedule 02-11 August 2014 Supplement www.sec.state.ma.us/arc/arcrmu/rmuidx.htm Summary of Contents About This Supplement... 7 Revisions to the Current Edition...

More information

Union County. Electronic Records and Document Imaging Policy

Union County. Electronic Records and Document Imaging Policy Union County Electronic Records and Document Imaging Policy Adopted by the Union County Board of Commissioners December 2, 2013 1 Table of Contents 1. Purpose... 3 2. Responsible Parties... 3 3. Availability

More information

Department of Veterans Affairs VA Directive 6311 VA E-DISCOVERY

Department of Veterans Affairs VA Directive 6311 VA E-DISCOVERY Department of Veterans Affairs VA Directive 6311 Washington, DC 20420 Transmittal Sheet June 15, 2012 VA E-DISCOVERY 1. REASON FOR ISSUE: To establish policy concerning the care and handling of documents

More information

CITY UNIVERSITY OF HONG KONG. Information Classification and

CITY UNIVERSITY OF HONG KONG. Information Classification and CITY UNIVERSITY OF HONG KONG Handling Standard (Approved by the Information Strategy and Governance Committee in December 2013) PUBLIC Date of Issue: 2013-12-24 Document Control Document Owner Classification

More information

Data Protection History, Evolution, Best Practices By Global Data Vault

Data Protection History, Evolution, Best Practices By Global Data Vault Data Protection History, Evolution, Best Practices By Global Data Vault Introduction As business data processing has evolved, so have the methods and best practices for data protection. This white paper

More information

retained in a form that accurately reflects the information in the contract or other record,

retained in a form that accurately reflects the information in the contract or other record, AL 2004 9 O OCC ADVISORY LETTER Comptroller of the Currency Administrator of National Banks Subject: Electronic Record Keeping TO: Chief Executive Officers of All National Banks, Federal Branches and Agencies,

More information

C. All responses should reflect an inquiry into actual employee practices, and not just the organization s policies.

C. All responses should reflect an inquiry into actual employee practices, and not just the organization s policies. Questionnaire on Electronically Stored Information (May 2014) Comment The Questionnaire is intended to be a comprehensive set of questions about a company s computer systems. The extent to which you should

More information

Retention & Disposition in the Cloud Do you really have control?

Retention & Disposition in the Cloud Do you really have control? InterPARES Trust Retention & Disposition in the Cloud Do you really have control? Franks Patricia, San Jose State University, San Jose, USA and Alan Doyle, University of British Columbia, Canada October

More information

RECORDS MANAGEMENT POLICY

RECORDS MANAGEMENT POLICY RECORDS MANAGEMENT POLICY POLICY STATEMENT The records of Legal Aid NSW are a major component of its corporate memory and risk management strategies. They are a vital asset that support ongoing operations

More information

How To Manage Records And Information Management In Alberta

How To Manage Records And Information Management In Alberta 8. RECORDS AND INFORMATION MANAGEMENT Overview This chapter is intended to help public bodies understand how good records and information management practices assist in the effective administration of

More information

Email Retention and Archiving

Email Retention and Archiving Personnel Connections Email Retention and Archiving 10 a.m. August 21, 2009 John L. Baines OIT Security and Compliance Agenda NC State Government & University Email References Background Governor s Email

More information

Cloud Computing and Records Management

Cloud Computing and Records Management GPO Box 2343 Adelaide SA 5001 Tel (+61 8) 8204 8773 Fax (+61 8) 8204 8777 DX:336 srsarecordsmanagement@sa.gov.au www.archives.sa.gov.au Cloud Computing and Records Management June 2015 Version 1 Version

More information

Protection of Privacy

Protection of Privacy Protection of Privacy Privacy Breach Protocol March 2015 TABLE OF CONTENTS 1. Introduction... 3 2. Privacy Breach Defined... 3 3. Responding to a Privacy Breach... 3 Step 1: Contain the Breach... 3 Step

More information

A guide from Chiltern Business Computing Ltd

A guide from Chiltern Business Computing Ltd Backing IT Up A guide from Chiltern Business Computing Ltd Every business depends on its computer systems to some degree or other. For many, systems are vital to business survival and success. This brief

More information

Summary of CIP Version 5 Standards

Summary of CIP Version 5 Standards Summary of CIP Version 5 Standards In Version 5 of the Critical Infrastructure Protection ( CIP ) Reliability Standards ( CIP Version 5 Standards ), the existing versions of CIP-002 through CIP-009 have

More information

San Francisco Chapter. Information Systems Operations

San Francisco Chapter. Information Systems Operations Information Systems Operations Overview Operations as a part of General Computer Controls Key Areas of focus within Information Systems Operations Key operational risks Controls generally associated with

More information

What We ll Cover. Defensible Disposal of Records and Information Litigation Holds Information Governance the future of records management programs

What We ll Cover. Defensible Disposal of Records and Information Litigation Holds Information Governance the future of records management programs What We ll Cover Foundations of Records and Information Management Creating a Defensible Retention Schedule Paper v. Electronic Records Organization and Retrieval of Records and Information Records Management

More information

SAMPLE IT CONTINGENCY PLAN FORMAT

SAMPLE IT CONTINGENCY PLAN FORMAT SAMPLE IT CONTINGENCY PLAN FORMAT This sample format provides a template for preparing an information technology (IT) contingency plan. The template is intended to be used as a guide, and the Contingency

More information

Disaster Recovery Policy

Disaster Recovery Policy Disaster Recovery Policy Organizational Functional Area: Policy for: Executive Division Bank Disaster Recovery Program Board Reviewed: September 14, 2011 Department/Individual Responsible for Maintaining/Updating

More information

BACKUP POLICY Date: 04/12/2009

BACKUP POLICY Date: 04/12/2009 BACKUP POLICY Date: 04/12/2009 Approvals Head of Department Signature Date Municipal Manager Signature. Date Divisional Manager: Information Management Signature.. Date.. Table contents Heading Page Overview

More information

PCI Data Security and Classification Standards Summary

PCI Data Security and Classification Standards Summary PCI Data Security and Classification Standards Summary Data security should be a key component of all system policies and practices related to payment acceptance and transaction processing. As customers

More information

1. The records have been created, sent or received in connection with the compilation.

1. The records have been created, sent or received in connection with the compilation. Record Retention & Destruction Policy Bradley Kirschner PC recognizes that the firm s engagement and administrative files are critical assets. As such, the firm has established this formal written policy

More information

15 Organisation/ICT/02/01/15 Back- up

15 Organisation/ICT/02/01/15 Back- up 15 Organisation/ICT/02/01/15 Back- up 15.1 Description Backup is a copy of a program or file that is stored separately from the original. These duplicated copies of data on different storage media or additional

More information

RECORDS MANAGEMENT RECORDS MANAGEMENT SERVICES. Cost-Effective, Legally Defensible Records Management

RECORDS MANAGEMENT RECORDS MANAGEMENT SERVICES. Cost-Effective, Legally Defensible Records Management RECORDS MANAGEMENT RECORDS MANAGEMENT SERVICES Cost-Effective, Legally Defensible Records Management Does This Sound Familiar? A data breach could send our share price tumbling. I need to minimise our

More information

CORPORATE RECORD RETENTION IN AN ELECTRONIC AGE (Outline)

CORPORATE RECORD RETENTION IN AN ELECTRONIC AGE (Outline) CORPORATE RECORD RETENTION IN AN ELECTRONIC AGE (Outline) David J. Chavolla, Esq. and Gary L. Kemp, Esq. Casner & Edwards, LLP 303 Congress Street Boston, MA 02210 A. Document and Record Retention Preservation

More information

Records and Information Management and Retention

Records and Information Management and Retention Records and Information Management and Retention Association of Corporate Counsel Nonprofit Organizations Committee Legal Quick Hit March 13, 2012 3 pm ET W. Warren Hamel Venable LLP 750 E. Pratt St. Baltimore,

More information

Electronic Records Management Guidelines

Electronic Records Management Guidelines Electronic Records Management Guidelines Contents Section 1: Authority... 1 Section 2: Purpose and Scope... 1 Section 3: Records Custodian Responsibilities... 2 Section 4: Information Systems that produce,

More information

Disaster Recovery. Stanley Lopez Premier Field Engineer Premier Field Engineering Southeast Asia Customer Services and Support

Disaster Recovery. Stanley Lopez Premier Field Engineer Premier Field Engineering Southeast Asia Customer Services and Support Disaster Recovery Stanley Lopez Premier Field Engineer Premier Field Engineering Southeast Asia Customer Services and Support Categories of Risk Financial Operational Reputational Market share Revenue

More information

Information Shield Solution Matrix for CIP Security Standards

Information Shield Solution Matrix for CIP Security Standards Information Shield Solution Matrix for CIP Security Standards The following table illustrates how specific topic categories within ISO 27002 map to the cyber security requirements of the Mandatory Reliability

More information

SOUTHWEST VIRGINIA COMMUNITY COLLEGE RECORDS MANAGEMENT POLICY

SOUTHWEST VIRGINIA COMMUNITY COLLEGE RECORDS MANAGEMENT POLICY SOUTHWEST VIRGINIA COMMUNITY COLLEGE RECORDS MANAGEMENT POLICY Statement of Intent This policy establishes the general responsibilities for management, retention, and disposition of SOUTHWEST VIRGINIA

More information

Policy Number. Administrative Signature:

Policy Number. Administrative Signature: COMMUNITY MENTAL HEALTH PARTNERSHIP OF SOUTHEASTERN MICHIGAN Category Regulatory Compliance Policy and Procedure Policy Number Policy Name Type of Policy: RECORD RETENTION AND DESTRUCTION OF RECORDS POLICY

More information

Data Management and Retention for Standards Consortia

Data Management and Retention for Standards Consortia Data Management and Retention for Standards Consortia An Overview 15 May, 2006 Prepared by: Jeremy Towsey-French jfrench@kavi.com Kavi Corporation 1 of 6 Copyright 2006 All rights reserved Data Management

More information

Public Records (Scotland) Act 2011. NHS Health Scotland Assessment Report. The Keeper of the Records of Scotland. 5 th August 2015

Public Records (Scotland) Act 2011. NHS Health Scotland Assessment Report. The Keeper of the Records of Scotland. 5 th August 2015 Public Records (Scotland) Act 2011 NHS Health Scotland Assessment Report The Keeper of the Records of Scotland 5 th August 2015 Contents 1. Public Records (Scotland) Act 2011... 3 2. Executive Summary...

More information

MSU Guidance for Electronic Mail Records

MSU Guidance for Electronic Mail Records MSU Guidance for Electronic Mail Records University Archives and Historical Collections Contents Introduction to Records Management and Electronic Mail... 1 Emails and Social Media... 2 Using Email for

More information

White Paper for Data Protection with Synology Snapshot Technology. Based on Btrfs File System

White Paper for Data Protection with Synology Snapshot Technology. Based on Btrfs File System White Paper for Data Protection with Synology Snapshot Technology Based on Btrfs File System 1 Table of Contents Introduction 3 Data Protection Technologies 4 Btrfs File System Snapshot Technology How

More information

Approved by: Vice President, Human Resources & Corporate Resources and Vice President, Treasury & Compliance Date: October 14, 2009

Approved by: Vice President, Human Resources & Corporate Resources and Vice President, Treasury & Compliance Date: October 14, 2009 RECORDS AND INFORMATION Approved by: Vice President, Human Resources & Corporate Resources and Vice President, Treasury & Compliance Date: October 14, 2009 PURPOSE Penn West recognizes that responsible

More information

CITY OF MONTEREY. Citywide Records Management Policy And Records Retention Schedule. June 2005 Amended November 2005 & June 19, 2007

CITY OF MONTEREY. Citywide Records Management Policy And Records Retention Schedule. June 2005 Amended November 2005 & June 19, 2007 CITY OF MONTEREY Citywide Records Management Policy And Records Retention Schedule June 2005 Amended November 2005 & June 19, 2007 Citywide Records Retention Schedule and Records Management Policy Implementation

More information

West Midlands Police and Crime Commissioner Records Management Policy 1 Contents

West Midlands Police and Crime Commissioner Records Management Policy 1 Contents West Midlands Police and Crime Commissioner Records Management Policy 1 Contents 1 CONTENTS...2 2 INTRODUCTION...3 2.1 SCOPE...3 2.2 OVERVIEW & PURPOSE...3 2.3 ROLES AND RESPONSIBILITIES...5 COMMISSIONED

More information

Scanning and Tossing. Requirements for Scanning and the Destruction of Paper Based Records

Scanning and Tossing. Requirements for Scanning and the Destruction of Paper Based Records Scanning and Tossing Requirements for Scanning and the Destruction of Paper Based Records Overview I want to go paperless! Can I scan and toss? What are the rules and requirements about imaging? What are

More information

IT SERVICE CONTINUITY AS RELATED TO THE MANAGEMENT OF ELECTRONIC RECORDS POLICY

IT SERVICE CONTINUITY AS RELATED TO THE MANAGEMENT OF ELECTRONIC RECORDS POLICY Department of Health Government of Western Australia IT SERVICE CONTINUITY AS RELATED TO THE MANAGEMENT OF ELECTRONIC RECORDS POLICY 2004 Document Control Date Version Notes Author 10/11/2003 0.1 Initial

More information

BACKUP AND RECOVERY PLAN MS SQL SERVER

BACKUP AND RECOVERY PLAN MS SQL SERVER BUREAU OF INFORMATION & TELECOMMUNICATIONS BACKUP AND RECOVERY PLAN MS SQL SERVER Page 1 of 5 Revisions & Addendums Log: Instructions: Changes and Addendum can be sent to: James R. Douglas, Technical Analyst

More information

September 28 2011. Tsawwassen First Nation Policy for Records and Information Management

September 28 2011. Tsawwassen First Nation Policy for Records and Information Management Tsawwassen First Nation Policy for Records and Information Management September 28 2011 Tsawwassen First Nation Policy for Records and Information Management Table of Contents 1. RECORDS AND INFORMATION

More information

The second section of the HIPAA Security Rule is related to physical safeguards. Physical safeguards are physical measures, policies and procedures

The second section of the HIPAA Security Rule is related to physical safeguards. Physical safeguards are physical measures, policies and procedures The second section of the HIPAA Security Rule is related to physical safeguards. Physical safeguards are physical measures, policies and procedures to protect and secure a covered entity s electronic information

More information

2012 NASCIO Recognition Award Nomination

2012 NASCIO Recognition Award Nomination 2012 NASCIO Recognition Award Nomination Pennsylvania Treasury Department Bureau of Information Technology Solutions Title: Category: Contact: Email Retention Cultural Challenge Conquered Fast Track Solutions

More information

Email Retention 7/11/2014 1

Email Retention 7/11/2014 1 Email Retention 7/11/2014 1 What is an Email Retention Policy? What is an Electronic (Email/Instant Messaging) Communications Retention Policy? An electronic retention policy is list of parameters created

More information

Volume UC DAVIS HEALTH SYSTEM. HIPAA Security Compliance Workbook. Multi User Guide

Volume UC DAVIS HEALTH SYSTEM. HIPAA Security Compliance Workbook. Multi User Guide Volume 1 UC DAVIS HEALTH SYSTEM HIPAA Security Compliance Workbook Multi User Guide UC DAVIS HEALTH SYSTEM HIPAA Security Compliance Workbook Guide Table of Contents Introduction General Instructions SECTION

More information

USGS Guidelines for the Preservation of Digital Scientific Data

USGS Guidelines for the Preservation of Digital Scientific Data USGS Guidelines for the Preservation of Digital Scientific Data Introduction This document provides guidelines for use by USGS scientists, management, and IT staff in technical evaluation of systems for

More information

IT Security Agency Policies and Procedures

IT Security Agency Policies and Procedures Revised Date: 12/20/11 (formatting) Page 1 of 6 IT Security Agency Policies and Procedures Firewall Change Control Procedure Policy Objectives: The purpose of this document is to define Admin s process

More information

Music Recording Studio Security Program Security Assessment Version 1.1

Music Recording Studio Security Program Security Assessment Version 1.1 Music Recording Studio Security Program Security Assessment Version 1.1 DOCUMENTATION, RISK MANAGEMENT AND COMPLIANCE PERSONNEL AND RESOURCES ASSET MANAGEMENT PHYSICAL SECURITY IT SECURITY TRAINING AND

More information