Client Logo <Client Name> Database Management Standard Version 0.1 <Date> Prepared By: David Bowman Information Management Architect
TableofContents RevisionHistory...3 Objective... 4 Application... 4 Definitions... 4 Standard...5 DatabaseSelection... 6 DataandDatabaseOwnership... 6 DatabaseObjects... 6 DatabaseSecurity...7 DataArchiving,PurgingandRetention...7 DataUsage...7 DataExceptionHandling...7 Accountabilities... 8 ReviewCycle... 9 EffectiveDate... 9 Client Page2of9 DatabaseManagementStandard
RevisionHistory Version Date Description Author Client Page3of9 DatabaseManagementStandard
Objective Thisdatabasemanagementstandardestablishestherequirementsnecessaryfor appropriateandconsistentadministrationandmanagementofproductionand non productiondatabasestopreservetheintegrity,availabilityandrecoverability ofdataasthedataisused,updatedandmodified. Application Thispolicyisapplicabletoallproductionandnon productiondatabases Definitions Term Database Administration Database Management System(DBMS) Management InformationSystem (MIS) Metadata Definition Implementing,monitoringandcoordinatingthestandards necessarytoadminister,storeandaccessdata. Programenablingthecreationandmaintenanceofa database. Aprocessthatprovidestheinformationnecessarytomanage anorganizationeffectively.themisandtheinformationit generatesaregenerallyconsideredessentialcomponentsof prudentandreasonablebusinessdecisions. Datadescribingorspecifyingotherdataordefiningand organizingcharacteristicsthatneedtobeknownaboutdata, including(butnotlimitedto)informationaboutphysical datarepresentations,technicalandbusinessprocesses,rules andconstraints,anddatastructures. Metadataisanassetoftheorganization.Explicitmetadatais storedinsoftwareandothermedia.implicitmetadatais knownbypersonnel,butisundocumentedandshallbe capturedanddocumented. Metadataisalsoknownas data about data. Client Page4of9 DatabaseManagementStandard
Term Non Production Database Production Database Referential Integrity Definition AdatabasethatsupportsbusinessandITactivities including,butnotlimitedto,databasesutilizedinthe supportingprocessestotestnewdevelopmentand enhancements(test),toperformqualityassurance validation(qualityassurance)andtodevelopnewsolutions orenhancementstoexistingsolutions(development). Productiondatabasesdirectlysupportexecutionofbusiness anditactivitiesandresideinappropriatelysecuredand controlledproductionenvironments. Adatabaseconceptthatensuresthatrelationshipsbetween tablerowsremainvalid.forexample,thecustomernumbers inordertablerowsmustallrefertovalidcustomer numbersinthecustomertable srow. Standard Appropriatedocumentationshallbedevelopedandmaintainedbythebusiness areasforallprocessesandproceduresthatexecutetothisstandard. Databaseownersareaccountableforestablishing,approvingandmaintaining documentedprocessesandproceduresinsupportofthisstandard.this documentationwillbesubjecttotheappropriateseniormanagementreviewand approval. Approvedtools,inaccordancewithapplicablestandardsandprocedures,shallbe usedwhendesigning,building,maintainingandstoringdataandarelistedinthe currentversionoftheinformationmanagementtechnologystandardslist. Allproductiondatabasesshallbestoredunderthemanagementofdatabase managementsoftwareaslistedinthecurrentversionoftheinformation managementtechnologystandards Client Page5of9 DatabaseManagementStandard
DatabaseSelection Aswithallinformationtechnologytools,databasemanagementsystems (DBMS)shallbeselectedfromtheinformationmanagementtechnology standards.theselectedrdbmstechnologyisakeysystemsarchitecture decisionandshallbeclearlydocumentedineachsystem stechnical Architecturedocument Oncetheplatformhasbeenselectedfromtheinformationmanagement technologystandards,allproductionandnon productiondatabasesmust adheretothetechnicalrequirements DataandDatabaseOwnership Theappropriatebusinessexecutivesupportedbythedatabaseshallassigna databaseowneranddatabaseguardianalldatabases.theseassignmentsshallbe documented,publishedandmaintained. Alldatawithinaproductiondatabaseshallbeassignedadataguardianand datastewardasdefinedintheintheinformationmanagementmetadata standard; Alldatabasesusedtosupportorexecutebusinessprocesses;productionand non productiondatabasesfortheorganizationshallberegisteredtoand assignedanapplicationdatabaseadministratorandaproductionsupport databaseadministrator; Databaseadministrators(DBA s)shallberesponsibleforcreating, maintaining,upgradingandrestoringallproductionandnon production databases; DBA sshallberesponsibleforcreating,maintaining,upgradingand restoringtheirrespectivedatabases; Databaseownersshallmaintainandapprovetheinventoryofallofthe databasesforwhichtheyareaccountablethatsupportorexecutebusiness productionprocesses.thisinventorywillbemaintainedwithinthe configurationmanagementdatabase(cmdb)andshallincludetheassigned databaseadministrators,databaseownersanddatabaseguardians. DatabaseObjects Objects(tables,indexes,views,etc.)createdinaproductiondatabaseshall benamedincompliancewithim STD XXXStructure&DesignStandard Names,definitionsandothermetadataforobjectscreatedinaproduction databaseshallbesubmittedtotheappropriatemetadatarepository followingapprovedprocedures Client Page6of9 DatabaseManagementStandard
DatabaseSecurity Allproduction,QAandtestdatabasesshallbecompliantwithIM POL XXX DataAccessPolicy; Developersshallhavenoaccesstoproductiondata; AccesstoproductiondatashallcomplywithrequirementsdefinedinIM POL XXX DataAccessPolicy DataArchiving,PurgingandRetention Archivingandpurgingdatawithinaproductiondatabaseshallcomplywith approvedrequirements; Thedatapurgeand/orarchiveprocessesshallbeincludedaspartofall productiondatabaseimplementations; Datapurgingshallbeperformedusingapprovedandcontrolledbatch processes;and Dataretentionprocessesshallcomplywiththeproceduresidentifiedin approvedrequirements. DataUsage Alldatashallbeusedonlyforbusinesspurposes; Productiondatacontaininganypersonalinformationshallnotbe propagatedtonon productiondatabases; Dataclassifiedasconfidential/proprietaryshallbeunavailableinnonproductiondatabases;however,dataclassifiedassuchmayresideinQuality AssuranceandOperationalReadinessTestingenvironmentsifcompliance withim POL XXX DataAccessPolicy Datacontainedinnon productiontablesordatabasesshallnotbeusedin theproductionenvironmentorprocesses; User owneddataanddatawithinuser ownedtablesshallnotbeusedinthe productionprocessesunlessimplementedinprocesseswhicharecompliant withproductionaccesscontrolstandards DataExceptionHandling Productiondatabasesshallhaveautomatedmechanismstoensure referentialintegrity; Alldataerrorsanddataexceptionsshallbedocumented,analyzedand evaluatedforthepurposeofdetectingdatabaseordataqualityissues; Dataexceptionhandlingshallbecapableofgeneratingmetricsthatcanbe monitoredbyoperatorstoprovideinsightintothecurrenthealthand statusofdatawithinproductiondatabases; Datamovementprocessesshallcomplywiththeproceduresidentifiedin thestd XXXDataMovementStandard. Client Page7of9 DatabaseManagementStandard
Accountabilities Role ChiefInformationOfficer(CIO) DataGuardian DataSteward DatabaseOwner DataBaseAdministrator ProductionSupportDBA Accountability AccountabletotheCEOforestablishingthe appropriatestrategies,plans,processes,tools, andorganizationalconstructsthatensure overallcompliancewiththispolicy. AccountabletotheCIOfor: Definingcontrolsforaccesstodataand appropriateclassificationofdata Implementingappropriateinformation protectioncontrolsandproceduresto mitigateriskstotheinformationassets Monitoringsecurity,access,anduseofdata AccountabletotheDataGuardianfor: Managingdatawithinabusinessareaand assumingresponsibilitiesregardingdata requirements Communicatingthebusinessvalue,scope, standardsandservicesoftheorganization s datawithinthecontextoftheirarea Monitoringdataqualityandformingthe first lineresponsetodataqualityissues AccountabletotheCIOforensuringthat propercontrolsandgovernanceareestablished andimplementedtopreservetheintegrityof thedatabase AccountabletotheDataArchitectfor: Implementation,monitoringand coordinationoftheproceduresnecessaryto administer,store,indexandaccessthe database Databaseapplication tuning,production support,project leveldatabasecapacity planninganddatabasesecurity requirements AccountabletotheDataBaseOwnerfor: implementing,monitoring,and coordinatingtheproceduresnecessaryto proactivelymonitorandsupportproduction databases; Providingon callsupportforproduction systems; Executionofdatabasebackupandrecovery anddatabasedisasterrecovery;and Capacityplanningforroutinedatabase growthrelatedtoaccountgrowth. Client Page8of9 DatabaseManagementStandard
ReviewCycle Thispolicyshallbereviewedannually EffectiveDate Thispolicyiseffective<Date> Client Page9of9 DatabaseManagementStandard