The Office of Information Technology - UTSA

This document should be rendered in an HTML format. If you are using an editor that does not show HTML documents please skip to page content, links on this page, and/or site navigation.

Copyright (c) 2007. The University of Texas at San Antonio. All rights reserved.

Information Security Office

Office of Information Technology

UTSA http://www.utsa.edu OIT Main Link
Security MainPoliciesSecurity NewsBest PracticesContact UsITA/ISA

Welcome to the UTSA's Information Security web site. This site has been designed to provide students, faculty, staff, and computer professionals with information and awareness needed to secure their systems and data.


The University of Texas at San Antonio

Information Resource Standards

Backup and Data Recovery Standard

 

 

Purpose - The UTSA Backup/DIR Standard establishes the rules for the backup, storage and recovery of electronic UTSA information.

Audience - The UTSA Backup/DIR Standard applies to all individuals within the UTSA enterprise who are responsible for the installation and support of Information Resources, individuals charged with Information resources security and data owners.

Services – OIT has existing arrangements for offsite backup data storage. These services can be extended to all UTSA entities upon request. OIT will maintain a list of all departmental systems and their backup arrangements.

  1. The frequency and extent of backups must increase as the importance of the information and the risk of loss, as determined by the data owner, increase.
  2. The UTSA information resources backup and recovery process for each system must be documented and periodically reviewed by the system owner.
  3. Physical access controls implemented at offsite backup storage locations must meet or exceed the physical access controls of the source systems. Additionally, backup media must be protected in accordance with the highest UTSA sensitivity level.
  4. A process must be implemented to verify the operability of the UTSA electronic information backup, including periodic testing to ensure that backups are recoverable.
  5. Signature cards held by the offsite backup storage vendor(s) for access to UTSA backup media must be reviewed annually or when an authorized individual leaves UTSA.
  6. Procedures involving UTSA and the offsite backup storage vendor(s), if any, must be reviewed at least annually.
  7. Backup tapes must have, at a minimum, the following identifying markers that can be readily displayed by labels and/or a bar-coding system:
    1. System name
    2. Creation date
    3. Sensitivity Classification [Based on applicable electronic record retention regulations]
    4. UTSA contact information

Account Management

Incident Management

Password

Software Licensing

Administrative/Special Access

Information Services Privacy

Physical Access

Vendor Access

Backup and Data Recovery

Internet Use

Portable Computing

Virus Protection

Change Management

Intrusion Detection

Security Monitoring

Wireless Communication

E-Mail Management

Network Access

Security Training

 

File Sharing

Network Configuration

Server Hardening

 


©The University of Texas at San Antonio One UTSA Circle San Antonio TX 78249
Revised: 06/05/2008
Refer Comments to: oit@utsa.edu
Identity Guidelines | Policies | Emergency Preparedness | Required Links