Server Backup Plicy Intrductin Data is ne f Banks DIH Limited s mst imprtant assets. In rder t prtect this asset frm lss r destructin, it is imperative that it be safely and securely captured, cpied, and stred. The gal f this dcument is t utline a plicy that gverns hw and when data residing n cmpany servers will be backed up and stred fr the purpse f prviding restratin capability. In additin, it will address methds fr requesting that backed up data be restred t individual systems. What Is Backed Up - Systemi. This plicy refers t the backing up f data that resides n Banks DIH Limited s Systemi Lgical Partitin (LPAR) servers, LPAR 1 Prductin Server and LPAR 2 Develpment Server. files/flders and/r data types n these servers that are cvered by this plicy include: System i Server Daily All changed files Weekly All IFS files, all Libraries Mnthly All IFS files, all Libraries, security and cnfiguratin data Yearly All LIC, all IFS files, all Libraries Servers and the It is the respnsibility f server administratrs t ensure that all new LPAR servers be added t this plicy, and that this plicy be applied t each new server s maintenance rutine. Prir t deplying a new LPAR, a full backup must be perfrmed and the ability t perfrm a full restratin frm that backup cnfirmed. Prir t retiring a server, a full backup must be perfrmed and placed in permanent strage. What Is Backed Up - Intel. This plicy refers t the backing up f data that resides n Banks DIH Limited s servers. Servers and the files/flders and/r data types n these servers that are cvered by this plicy include: Page 1
All Intel servers use Veeam Backup and Replicatin applicatin. Veeam Backup and Replicatin prvides fast, flexible, and reliable recvery f virtualized applicatins and data. It unifies backup and replicatin in a single slutin while ffering increased data prtectin fr VMware vsphere envirnment. Veeam has implemented bth cmpressin and deduplicatin features t help recver what wuld therwise be a significant amunt f data strage space used t stre backups f vm s. Data deduplicatin is a specialized data cmpressin technique fr eliminating carse-grained redundant data, typically t imprve strage utilizatin. In the deduplicatin prcess, duplicate data is deleted, leaving nly ne cpy f the data t be stred, alng with references t the unique cpy f data. The backup jb fr the belw-listed servers are managed by the Veeam Backup and Replicatin whse schedule is cnfigured fr a full backup f all VM s, fllwed by deduplicated, incremental backups. Hence, a full backup is always available fr restre. Nte: The fllwing are Banks DIH Limited s VMWare servers and are backed up using Veeam. Restratin takes place at file level r as an entire server. Tp-dcserver Tp-adminserv01 Tp-appserv01 Tp-managserver Tp-managserv01 Tp-exectermserv Tp-termserv01 Tp-termserv02 Tp-termserv03 Tp-termserv04 Tp-termserv05 Page 2
Tp-bbserver01 Tp-bbserver02 Tp-cctvserv01 Tp-exectermserv Tp-fileserv00 Tp-fileserv01 Tp-slarwinds01 Tp-nlinebackup Tp-printserver01 Tp-slarwinds01 Tp-veeamprxy01 Tp-veeamsvr01 Tp-webmanager Tp-websense-appliance Tp-vmadmin Tp-wsuserv01 Tp-iasserv01 This plicy des nt refer t backing up f data that resides n individual PC r ntebk hard drives. Respnsibility fr backing up data n lcal desktp systems r laptps rests slely with the individual user. It is strngly encuraged that end users save their data t the apprpriate server listed abve in rder that their data is backed up regularly in accrdance with this plicy. In additin, files that are left pen at the time the backup prcedure is initiated may nt be backed up. End users are reminded t save and clse all files, as well as all related applicatins, prir t the backup prcedure windw. Page 3
It is the respnsibility f server administratrs t ensure that all new servers be added t this plicy, and that this plicy be applied t each new server s maintenance rutine. Prir t deplying a new server, a full backup must be perfrmed and the ability t perfrm a full restratin frm that backup cnfirmed. Prir t retiring a server, a full backup must be perfrmed and placed in permanent strage. Systemi Backup Schedule Backups are cnducted autmatically. System i backups utilize the system s backup utility n bth servers (partitins) which backs up t tape fr ffsite strage.. This methd ensures that n mre than ne day s wrking data will be missing in the event f a data lss incident: All backups tapes are t be labeled using the fllwing labeling cnventins: System i backups MONTH\DATE\YEAR All backup tapes stred n site are t be stred in a fireprf Chubb. All backup tapes stred ff site are t be stred at the Citizen Banks Thirst Park Branch lcatin in a fireprf Chubb in the care f the Branch Manager. All LPAR Prductin System i backups will take place between the hurs f 11:00 PM and 03:00AM. These timeframes have been selected t minimize the impact f server dwntime n end users that may be caused by the need t take servers ffline in rder t perfrm the backup itself. If this backup schedule in sme way interferes with a critical wrk prcess, then the affected user(s) is t ntify the IT Department s that exceptins r alternative arrangements can be made. Incremental backups (nly files changed since the last backup) will be perfrmed daily, Mnday thrugh Friday. These tapes will be stred nsite during the fllwing backup cycle. At the end f the latter cycle, the daily tapes will be remved t a predetermined ffsite lcatin fr strage fr 1 week. When this 1 week perid has elapsed, the tapes will be brught back n site fr reuse fr a perid nt t exceed ne year. Page 4
A full backup will be perfrmed fr System i n a weekly/mnthly basis. These tapes will be stred n site during the fllwing backup cycle. At the end f the latter cycle, the weekly tape will be remved t a predetermined ffsite lcatin fr strage fr 1 week. When this 1week perid has elapsed, the tapes will be brught back n site fr reuse fr a perid nt t exceed ne year. A full backup will be perfrmed at the end f each mnth. This tape will be immediately remved t a predetermined ffsite lcatin fr permanent strage. These tapes will never be reused. All server backups perfrmed must be nted in the server backup lg immediately upn cmpletin. All server backup lg sheets must be kept in an apprpriately labelled three-ring binder in an agreedupn, centralized lcatin. The lg must include: Server name, Date and time f backup, Name f administratr perfrming the backup, Files backed up and/r skipped, Sftware used t perfrm the backup, Backup medium used and its label/name, and Whether the backup was successful r nt. If, fr sme reasn, the backup cannt be cmpleted, is missed, r crashes, then it must be cmpleted by 9:00 a.m. the fllwing mrning. The reasn fr nn-cmpletin f the riginally scheduled backup must be nted in the server backup lg. In additin, if a backup fails mre than ne day in a rw, end users in the rganizatin must be ntified. If a tape is discvered t be damaged r crrupt, then the tape must be destryed t prevent further use and replaced with a new ne. Intel Backup Schedule Backups are cnducted autmatically. Intel servers use Veeam Backup and Replicatin applicatin, which backs up t n-site SAN and NAS strage devices. The servers listed abve must be backed up accrding Page 5
t the fllwing prcedure. This methd ensures that n mre than ne day s wrking data will be missing in the event f a data lss incident: All Intel backups are scheduled frm 06:00 PM t cmpletin. These timeframes have been selected t minimize the impact f server perfrmance degradatin. If this backup schedule in sme way interferes with a critical wrk prcess, then the affected user(s) is t ntify the IT Department s that exceptins r alternative arrangements can be made. Veeam Backup and Replicatin applicatin runs Reverse incremental backups (nly files changed since the last backup) daily, Mnday thrugh Sunday. All server backups results, whether successful r nt, are emailed t all members f Technical Supprt team and summary r detailed reprts can be run fr review r filing. All server backup lg sheets must be kept in an apprpriately labelled three-ring binder in an agreed-upn, centralized lcatin. The lg must include: Server name, Date and time f backup, Name f administratr perfrming the backup, Files backed up and/r skipped, Sftware used t perfrm the backup, Backup medium used and its label/name, and Whether the backup was successful r nt. If, fr sme reasn, the backup cannt be cmpleted, is missed, r crashes, then it must be cmpleted by 9:00 a.m. the fllwing mrning. The reasn fr nn-cmpletin f the riginally scheduled backup must be nted in the server backup lg. In additin, if a backup fails mre than ne day in a rw, end users in the rganizatin must be ntified. Warm Site and Replicatin Page 6
One f the mst imprtant aspects f disaster recvery is t have a lcatin frm which the recvery can take place. This lcatin knwn as a Warm Site, is situated at the Berbice Branch f the cmpany s peratins. In the event f a disaster at the main site the Cmpany s data center will be recreated and peratins cntinued frm the warm site, fr the length f the disaster. The warm site is already stcked with hardware representing a reasnable facsimile f that fund in the Banks DIH data center. T restre service, the last backups frm ur ff-site strage facility must be delivered, and bare metal restratin cmpleted, befre the real wrk f recvery can begin. In any replicatin scenari, it is VERY imprtant t accunt fr the bandwidth requirements fr the data being cpied frm site t site. Data replicatin can cnsume significant bandwidth, and therefre it is imprtant t plan this and ensure that disaster recvery replicatin des nt cnsume precius Internet access bandwidth r WAN links and cmpete with existing applicatins. WAN acceleratin, via prducts such as Veeam Backup and Replicatin applicatin, can prvide a valuable ptin t get the mst ut f existing links withut needing t purchase extra bandwidth r new links (but this varies situatin by situatin). Timing f replicatin can als be an issue fr example, it might be acceptable t thrttle cmmunicatins during the wrk day, and have replicatin catch up after 6pm if the Recvery Windw allws fr lss f a few hurs data. A Warm Site typically has live cmmunicatin links and sme amunt f hardware, but typically requires installatin f sftware and/r restratin f data frm tape r anther media frmat typically in a span f hurs r a day befre the site is peratinal; Managing Restres The ultimate gal f any backup prcess is t ensure that a restrable cpy f data exists. If the data cannt be restred, then the prcess is useless. As a result, it s essential t regularly test ne s ability t restre data frm its strage media. Page 7
System i 1. All daily tapes shuld be tested at least nce every 2 mnths t ensure that the data they cntain can be cmpletely restred. 2. All weekly tapes shuld be tested at least nce every 3 mnths t ensure that the data they cntain can be cmpletely restred. 3. All mnthly tapes shuld be tested at least nce every year t ensure that the data they cntain can be cmpletely restred. Intel - SureBackUp A SureBackup jb is a task fr VM backup recvery verificatin. Such a jb was created t ensure that the CRITICAL servers existing in the Banks DIH envirnment can be restred successfully. The SureBackup jb aggregates all settings and plicies f a recvery verificatin task, such as applicatin grup and virtual lab t be used, VM backups that shuld be verified in the virtual lab and s n. The SureBackup jb runs manually r can be scheduled t be perfrmed autmatically. By default, yu can start and test up t three VMs at the same time. Yu can als increase the number f VMs t be started and tested simultaneusly. These VMs are resurce demanding, perfrmance f the SureBackup jb as well as perfrmance f the ESX(i) hst hlding the virtual lab may decrease. Once the verificatin prcess is cmplete, VMs frm the applicatin grup are pwered ff. Optinally, yu can leave the VMs frm the applicatin grup running t perfrm manual testing r enable user-directed applicatin item-level recvery. In sme cases, the SureBackup jb schedule may verlap the schedule f the backup jb linked t it. The backup file may be lcked by the backup jb and the SureBackup jb will be unable t verify such backup. In this situatin, Veeam Backup & Replicatin will nt start the SureBackup jb until the crrespnding backup jb is ver. When a SureBackup jb runs, Veeam Backup & Replicatin first creates an envirnment fr VM backups verificatin: 1. Veeam Backup & Replicatin starts the virtual lab. 2. In the virtual lab, it starts VMs frm the applicatin grup in the required rder. VMs frm the applicatin grup remain running until the verified VMs are bted frm backups and tested. If Veeam Backup & Replicatin des nt find a valid restre pint fr any f VMs frm the applicatin grup, the SureBackup jb will fail. Page 8
3. Once the virtual lab is ready, Veeam Backup & Replicatin starts verified VMs frm the necessary restre pint, tests and verifies them ne by ne r, depending n the specified settings, creates several streams and tests a number f VMs simultaneusly. If Veeam Backup & Replicatin des nt find a valid restre pint fr any f verified VMs, verificatin f this VM fails, but the jb cntinues t run. Data will be restred frm a backup if: There is an intrusin r attack. Files have been crrupted, deleted, r mdified. Infrmatin must be accessed that is lcated n an archived backup. In the event a data restre is desired r required, the fllwing plicy will be adhered t: 4. Respnsibility fr verseeing backup and restre prcedures is the Service Desk. If a user has a restre request, they can cntact Service Desk by calling ext. 2129 r 2409, r by sending an e- mail t helpdesk@banksdih.cm. 5. In the event f unplanned dwntime, attack, r disaster, cnsult Banks DIH Limited s Disaster Recvery Plan fr full restratin prcedures. 6. In the event f a lcal data lss due t human errr, the end user affected must cntact the IT Department and request a data restre. The end user must prvide the fllwing infrmatin: Name. Cntact infrmatin. Name f file(s) and/r flder(s) affected. Last knwn lcatin f files(s) and/r flder(s) affected. Extent and nature f data lss. Events leading t data lss, including last mdified date and time (if knwn). Urgency f restre. 7. Depending n the extent f data lss, a daily tape, weekly tape, r cmbinatin f bth will need t be used. The timing in the cycle will dictate whether r nt these tapes are nsite r ffsite. Tapes Page 9
must be retrieved by the server administratr r pre-determined replacement. If tapes are ffsite and the restre is nt urgent, then the end user affected may be required t wait up 8 hurs fr the tape(s) t be retrieved. 8. If the data lss was due t user errr r a lack f adherence t prcedure, then the end user respnsible may be required t participate in a tutrial n effective data backup practices. Use f Cntractrs Cnfidentiality Statement IBM and SPECOM have signed cntracts with Banks DIH that includes cntract guidelines fr cnfidentiality and prtectin f Banks DIH data. Validatin Files Restred. Declaratin f Understanding I,, have read, understand, and agree t adhere t Banks DIH Limited s Server Backup Plicy. Name (Printed): Name (Signed): Tday s Date: Page 10