IT Security Office Versin 2.3 02/19/10 Backups and Backup Strategies IT managers need t plan fr backups in terms f time and space required. Hwever, mst mdern backup sftware can cmpress the backup files t reduce bth the time required t backup, as well as the media size needed. Regardless f the backup sftware r hardware that is chsen, the backup itself can cme in three different methds; full, incremental r differential. A full backup: Is ften the starting pint fr all ther backups Mst cmprehensive and are self-cntained backup Takes a lng time t run Takes a cnsiderable amunt f backup media t accmplish A restre frm a full backup is much quicker Running a full backup n a regular basis t restart the incremental and differential methd will help reduce the time and media size needed Often delegated t a weekly r mnthly schedule. An incremental backup: Stres all files that have changed since the last full, differential r incremental backup Prvides a faster methd f backing up infrmatin than repeatedly running full backups Takes the shrtest amunt f time t cmplete the backup Takes the least amunt f backup media t accmplish The effrt t restre frm an incremental backup can be very time cnsuming, as multiple tapes are restred. When restring frm incremental backup, the mst recent full backup is needed, as well as every incremental backup that was made since the last full backup. Fr example, if a full backup was dne n Friday and incremental backups n Mnday, Tuesday and Wednesday, and the backed-up machine crashes Thursday mrning; all fur backup media wuld be needed; Friday's full backup plus the incremental backup fr Mnday, Tuesday and Wednesday. A differential backup: Cntains all files that have changed since the last full backup Shrtens verall restre time cmpared t a full backup with incremental backups The upside fr using full and differential backups is that nly tw backup media are needed t perfrm a cmplete restre. Page 1 f 8
Restring a differential backup is a faster prcess than restring several incremental backup. Fr example, if a full backup was dne n Friday and differential backups n Mnday, Tuesday and Wednesday, and the backedup machine crashes Thursday mrning nly tw backup media days wuld be needed; Friday's full backup plus Wednesday's differential backups; that is, the latest full backup and the latest differential. The difference between these three backup strategies is illustrated in Figure 1: Cmparing Backup Strategies. Here, the full backup backs up everything up each time it is run as illustrated by the first rw n the diagram. The incremental backup backs up nly new r changed items frm the previus incremental backup (with a full backup starting the prcess). This is illustrated by the secnd rw n the diagram. A differential backup backs up all new r changed items frm the last time a full backup was run, as illustrated by the third rw f the diagram. Page 2 f 8
Figure 1: Cmparing Backup Strategies Disk Drive Full Backup Full Backup Full Backup Full Backup Disk Drive Example f Full Backup Full Backup Incremental Backup Incremental Backup Incremental Backup Example f Incremental Backup Full Backup Differential Backup Differential Backup Differential Backup Example f Differential Backup Time Line Page 3 f 8
Sample Backup Strategies The fllwing infrmatin is presented as best practices guidelines nly. backup rutines shuld balance time, expense and effrt against risk. Each department shuld develp a strategy that is apprpriate t their specific requirements. Hwever, sme ideas fr develping a backup strategy include: Develp a written backup plan that identifies: What is being backed up Where it is being backed up t Hw ften backups are perfrmed What is the life f the backup media Wh is in charge f perfrming backups Wh is in charge f backup verificatins; cmpletin f jbs and testing f media Schedules f test restres Database and accunting files are critical infrmatin assets and shuld be backed up befre and after any significant amunt f infrmatin entry and/r use. Fr mst departments, this means backing these files up every day. Virus r spyware quarantine directries shuld be excluded frm backups. Wrk related dcuments and files (fr example, the "My Dcuments" flders) and email files/flders might be backed up nce a week. This frequency shuld reflect the level f criticality that the department assciates with the infrmatin. Cpies f backups shuld be stred ff-site t ensure recvery against disaster such as a fire, earth quake r fld. Users typically require restratin f files recently backed up. S, ne recmmendatin is t keep the mst current set f backups nsite 1 and send the rest f the backups ffsite It is nt usually necessary t backup the cmplete cntents f each hard drive. Mst f that space is taken up the perating system and prgram files, which can be easily reladed frm CD r images. The nly exceptin is if the department has a dedicated file server; it's a gd practice t d a full backup The backup plan als needs a strategy t backup laptps and mbile devices which may nt be available at regular r cnvenient times. Backups shuld be tested BEFORE they are needed. T ensure cnfidence in the backups, the backup sftware shuld allw fr full read-back verificatin. Additinally, it is a gd practice t try restring a few files n each set f full, incremental and differential backups. 1 Backups kept nsite shuld be stred in a fire prf safe fr media prtectin Page 4 f 8
Chsing apprpriate backup hardware is als key t the success f the backup plan. Cnsideratins include: Determine hw much infrmatin yu need t backup. Inventry each machine n the netwrk (r a representative sample) t determine the ttal backup space Be sure t leave rm t add a new staff infrmatin and t plan fr grwth Chse a backup device that uses tape cartridges with a capacity that is at least twice the ttal amunt f infrmatin yu need t backup. Sample Media Rtatin Strategies In cmbinatin with a backup methd strategy, it is recmmended that IT supprt staff als use a backup tape (r ther media f chice) rtatin strategy. This will prevent the same media being used repeatedly, and s risking data lss. Page 5 f 8
Figure 2: The Parent-Child Tape Backup Strategy The Parent-Child Tape Backup Strategy Friday Tape 1 Full Backup Friday Tape 6 Full Backup Friday Tape 7 Full Backup Friday Tape 8 Full Backup Friday Tape 9 Full Backup Friday Tape 10 Full Backup Friday Tape 1 Full Backup The Parent-Child Tape Backup Strategy is an example f a 10 tape rtatin strategy, which uses fur tapes during the week and the thers each cnsecutive Friday. The strategy starts n a Friday with a full system backup n Tape 1. The fllwing Mnday, Tape 2 is used t perfrm a differential backup (targeting the data that has changed since Friday s full system backup). On Tuesday, Tape 3 is used t perfrm a differential backup (again targeting the data that has changed since Friday s full system backup). Tapes 4 and 5 are used in the same manner fr Wednesday and Thursday respectively. In this strategy, the week day tapes are referred t as daily backups, since using the differential backups; nly the last full backup and last daily backup will need t be used t cmpletely restre a system. Page 6 f 8
Finally, IT supprt staff shuld als use an archival r mnthly backup strategy. An example f this wuld be the Grand Parent-Parent-Child Tape Backup Strategy. This is an example f a 22 tape rtatin strategy, which builds directly n tp f the Parent-Child Tape Backup Strategy in that it uses a sub-set f 10 tapes; fur tapes during the week and the thers each cnsecutive Friday. Hwever, there are 12 additinal tapes which are used fr mnthly full backups. These 12 tapes will be kept indefinitely, will nt be reused, and shuld be stred at an apprpriate ff-site lcatin. Figure 4 illustrates the Grand Parent-Parent-Child Tape Backup Strategy. This is very similar t the Parent- Child Tape Backup Strategy illustrated in Figure 2. Hwever, each furth Friday, a mnthly full backup is perfrmed instead f the weekly full backup. As per Figure 3, at the end f the first mnth, Tape 11 is used. Then at the end f the secnd mnth, Tape 12 is used, and s n. Figure 3: Tape Usage in the Grand Parent-Parent-Child Tape Backup Strategy Mnth 1 Tape 11 Mnth 2 Tape 12 Mnth 3 Tape 13 Mnth 4 Tape 14 Mnth 5 Tape 15 Mnth 6 Tape 16 Mnth 7 Tape 17 Mnth 8 Tape 18 Mnth 9 Tape 19 Mnth 10 Tape 20 Mnth 11 Tape 21 Mnth 12 Tape 22 Page 7 f 8
Figure 4: The Grand Parent-Parent-Child Tape Backup Strategy The Grand Parent-Parent-Child Tape Backup Strategy Friday Tape 1 Full Backup Friday Tape 6 Full Backup Friday Tape 7 Full Backup Friday Tape 11 Mnthly Full Backup Friday Tape 8 Full Backup Friday Tape 9 Full Backup Friday Tape 10 Full Backup Friday Tape 12 Mnthly Full Backup Friday Tape 1 Full Backup Page 8 f 8