the purpose of the policy

This document aims to clarify and define the process of managing the lifecycle of all data owned by Najran University in the field of storage and preservation of data. This policy has been aligned with national data management controls and specifications for data storage and preservation and the personal data protection system.

Scope of work

Scope of this policy applies to all data and systems owned by Najran University.

Terms of Storage and Disaster Protection

  1. Infrastructure for Storage:
    • Sitesafe
  • NetworkHighEfficiency.serversandstoragespacessuitable.
  • The establishment of a secure infrastructure for data storage ensures its absence of loss..
    1. Copy Backupand Restore
      • Providesaclearplanforthecompetentdean.
  • Backupofcopiesandstorageinmultipleandsecurelocations.
  • Implementation of a backup system that ensures the possibility of data recovery in its entirety in the event of a disaster in the system
    1. Cybersecurity Applications:
    • Ensurethe safety ofthe preservation environment and its updates, examining it and following up on its updates.
  •  Usemulti-levelsecuritytoprotectdatafromunauthorizedaccess. Data encryptionduringvarioussystemoperations,includingtransferringorstoringit.

  • steps to establish the infrastructure

    1. Design Technical Multi-Level
    1. Verify the used licenses and systems and ensure readiness of network works and security procedures in the correct manner.
  • The geographical distribution of backup copies reduces the risk of data loss and facilitates its retrieval
    1. Backup and Restore of Data
    • Verify the integrity of the backup copies by restoring them randomly periodically.
  • Encryptionatthelevelofoperatingsystems. Useof theplagiarismsystem to achievemoresecurity.
  • Guarantee Protection of Data:
      •  Encryptingdata.
      Protecting the Mesh Network.Protect the hosting environment

      1. Guaranteeof MonitoringEfficiency:
    • Usingtools to monitor and track the status of systems.
  • Ensurethatthe necessary updatesare activatedforthe backup systems
  • Plansforfacingdisasters
      • dir="RTL" style="margin-right:48px; text-align:justify"> The confirmation of the existence of plans to face disasters and preparedness for them.
  •  Conducting regular tests for disaster response plans during the Deanery..
  • steps to implement the backup system

    Firstly:Identify types of data and classify them based on their importance and sensitivity to identify and order priorities for backupcopies

    Secondly: Selecting the appropriate strategy for backup using either full or partial copying of any changes to the data.

    Thirdly:Selectingthe appropriatetools,and thatisduring the use ofthe well-knowntools with their high efficiency and availability.

    Fourthly, creating backup copies in geographically diverse locations or using cloud computing systems with tracking of storage spaces and ensuring their availability.

    Fifthly: Conducting periodic recovery tests and to ensure the operation of backup systems in the required manner always

    steps to retrieve data

    • It will bedata recovery clear recovery plan to ensure business continuity and response to disasters . And by defining the critical dataUniversity can build a data retrieval plan for the critical mission in case of disasters.
    • Classification Levels Retrieval was based on time or goals or the required retrieval .Choosethe appropriate tools..Establishing service agreements at a level of service and that to ensure quality and achieve the desired goals of the retrieval process.
    • Training teams for direct backup and providing them with knowledge and skills necessary.Review plan recovery annually or every 3 years.
    Steps to implement cybersecurity

    • Network protection through the use of FIREWALLS or intrusion detection systems.
  • Protectionondeviceandsoftwareduringupdaterequiredonsystemsorsoftware.
  • Protectionofdataduringscientificaccesstodataorbyencryptingthedatainthecaseofitstransferorstartingthebackupprocess.
  • Data retention period

    Commitment to periods defined by the regulations of the entities owning the data.

    Data Retention Policies Development

    The

    The points that should be considered in defining the periods for preserving the data:

    • CategorizationofData
  • Review and Follow-up Periods.
  • rules of deletion and addition

    To ensure the deletion and addition of and to backup reliable and effective measures for setting the process:

    • Documentation of procedures and their writing and awareness of working with them .
  • Assigning responsibilities and definingauthorities
  • Approval of the automation and that to ensure the application of policies deletion of data automatically.
  • Procedures in case of data loss

    First: Dealingwiththelossofdata:

    • Formation of a high efficiency team for handling cases of disasters
    • Identifyingtheactualcausesbehindthelossofdataandthatusingsystemsthatrevealdisastercases
    • Secondly: Reconstruction and Data Recovery:

      • Develop plans for data recovery using the backups that have been made.
      • Examination and verification of the integrity of recovered data to ensure that it has not been affected or damaged.

    Response Team and Governance at the University

    ThisteamprovidesamodelincludingformaintainingasafeandhealthyenvironmentandisconsideredthebackboneformanagingdataattheUniversity

    This team will develop and implement and maintain effective policies for storage and retention and destruction and recovery of data in emergency cases.

    Firstly

    • EfficiencyTechnical.
    • Responseforemergencies.Compliancewiththelawsandregulations

    Roles and Responsibilities

    م

    The Agency

    The Role

    Responsibilities

    1

    Data Management Office

    Follow-up and review of the policy and updating it

    • Regular follow-up with the Deanery and ensuring the application of storage and backup policies.
    • Ensure the application of regulations and systems related to data and its lifecycle management process.

    2

    College of Digital Transformation and Knowledge Sources

    Implementation of Policy and its Application

    • Establish appropriate controls for data backup and retrieval, and handling and processing them in accordance with this policy.
    • Providing the necessary systems for data safety.
    • Back up information and data of Najran University, as well as software, on internal and external storage media. And provide the main data for backups, which include the following:
    • Version number.Its history.
    • Version description.Serial version numbering.
    • The backup access regulation applies unless through the responsible party for backups in the Deanship.Verify the safety of preservation procedures.
    • Regularly and randomly verify the possibility of applying a backup to the working environment.
    • Verify the full availability of backup copies for recovery.
    • Save Operations Classification.
    • Specify the frequency of backup duplication, and set minimum retention periods and duplication counts.
    • Maintain a minimum valid backup copy in a secure environment permanently and outside the university boundaries of Najran University.
    • Documentation of data recovery and periodic verification operations.
    • Establish and document mechanisms for verifying information received from various sources, and develop the necessary forms for this purpose.
    • Sensitive data is encrypted to ensure unauthorized access is prevented.

    3

    Cybersecurity Administration

    Data safety guarantee

    • Ensure the implementation of cybersecurity regulations in the field of data storage.
    • Guaranteeing data safety and ensuring the application of policies related to it.

    Procedures for legal violations of the storage and retention policy

    • Revoke all privileges granted to the employee.
    • Deny access to the university’s systems.
    • Financial or disciplinary penalties may apply.