Retention and Storage Policy
This document aims to clarify and define the process of managing the lifecycle of all data owned by Najran University in the field of storage and preservation of data. This policy has been aligned with national data management controls and specifications for data storage and preservation and the personal data protection system.
Scope of this policy applies to all data and systems owned by Najran University.
- Infrastructure for Storage:
- Sitesafe
- Copy Backupand Restore
- Providesaclearplanforthecompetentdean.
- Cybersecurity Applications:
- Ensurethe safety ofthe preservation environment and its updates, examining it and following up on its updates.
- Design Technical Multi-Level
- Verify the used licenses and systems and ensure readiness of network works and security procedures in the correct manner.
- Backup and Restore of Data
- Verify the integrity of the backup copies by restoring them randomly periodically.
- Encryptingdata.
- Guaranteeof MonitoringEfficiency:
- Usingtools to monitor and track the status of systems.
- dir="RTL" style="margin-right:48px; text-align:justify"> The confirmation of the existence of plans to face disasters and preparedness for them.
Fifthly: Conducting periodic recovery tests and to ensure the operation of backup systems in the required manner always
It will be data recovery clear recovery plan to ensure business continuity and response to disasters . And by defining the critical dataUniversity can build a data retrieval plan for the critical mission in case of disasters.- Classification Levels Retrieval was based on time or goals or the required retrieval .
Choosethe appropriate tools.. Establishing service agreements at a level of service and that to ensure quality and achieve the desired goals of the retrieval process. - Training teams for direct backup and providing them with knowledge and skills necessary.
Review plan recovery annually or every 3 years.
- Network protection through the use of FIREWALLS or intrusion detection systems.
Commitment to periods defined by the regulations of the entities owning the data.
The points that should be considered in defining the periods for preserving the data:
- CategorizationofData
To ensure the deletion and addition of and to backup reliable and effective measures for setting the process:
- Documentation of procedures and their writing and awareness of working with them .
Formation of a high efficiency team for handling cases of disasters Identifying theactualcausesbehindthelossofdataandthatusingsystemsthatrevealdisastercasesDevelop plans for data recovery using the backups that have been made. - Examination and verification of the integrity of recovered data to ensure that it has not been affected or damaged.
Secondly: Reconstruction and Data Recovery:
EfficiencyTechnical. - Responseforemergencies.
Compliancewiththelawsandregulations
|
م |
The Agency |
The Role |
|
|
1 |
|
|
|
|
2 |
|
|
|
|
3 |
|
|
|
- Revoke all privileges granted to the employee.
- Deny access to the university’s systems.
- Financial or disciplinary penalties may apply.