Retention and Storage Policy
This document aims to clarify and define the process of managing the lifecycle of all data owned by Najran University in the field of storage and preservation of data. This policy has been aligned with national data management controls and specifications for data storage and preservation and the personal data protection system.
Scope of this policy applies to all data and systems owned by Najran University.
- Infrastructure for Storage:
- Sitesafe
- Copy Backupand Restore
- Providesaclearplanforthecompetentdean.
- Cybersecurity Applications:
- Ensurethe safety ofthe preservation environment and its updates, examining it and following up on its updates.
- Design Technical Multi-Level
- Verify the used licenses and systems and ensure readiness of network works and security procedures in the correct manner.
- Backup and Restore of Data
- Verify the integrity of the backup copies by restoring them randomly periodically.
- Encryptingdata.
- Guaranteeof MonitoringEfficiency:
- Usingtools to monitor and track the status of systems.
- dir="RTL" style="margin-right:48px; text-align:justify"> The confirmation of the existence of plans to face disasters and preparedness for them.
Fifthly: Conducting periodic recovery tests and to ensure the operation of backup systems in the required manner always
It will bedata recoveryduring the presence of arecovery planclear to ensure the continuity of business and response to disasters. And by specifying the important data.
- Network protection through the use of FIREWALLS or intrusion detection systems.
Commitment to periods defined by the regulations of the entities owning the data.
The points that should be considered in defining the periods for preserving the data:
- CategorizationofData
To ensure the deletion and addition of and to backup reliable and effective measures for setting the process:
- Documentation of procedures and their writing and awareness of working with them .
Formation of a high efficiency team for handling cases of disasters Identifying theactualcausesbehindthelossofdataandthatusingsystemsthatrevealdisastercasesDevelop plans for data recovery using the backups that have been made. - Examination and verification of the integrity of recovered data to ensure that it has not been affected or damaged.
Secondly: Reconstruction and Data Recovery:
EfficiencyTechnical. - Responseforemergencies.
Compliancewiththelawsandregulations
|
م |
The Agency
The role
Responsibilities
1
- Regular follow-up with the Deanery and ensuring the application of storage and backup policies. Ensure the application of regulations and systems related to data and its lifecycle management process.
2
- Establish appropriate controls for data backup and retrieval, handling, and processing in accordance with this policy.
- Providing the necessary systems for data safety. Back up information and data of Najran University, as well as software, on internal and external storage media. And provide the key data for backups which include the following:
- Version Number.Its history.
- Version description.Serial number numbering. The provisions for backups are valid only through the responsible party for the copies in the Deanship.Verify the integrity of preservation procedures.
- Regularly and randomly verify the possibility of applying a backup to the operational environment.
- Verify the full recovery of saved copies.Classification of Save Operations.
- Specify the number of backup copies and set minimum retention periods and repetition counts.Maintain a single valid backup in a secure environment permanently and outside the boundaries of Najran University campus.
- Documenting data recovery and periodic verification operations. Establish and document mechanisms for verifying information received from parties, and prepare the necessary forms for that purpose.
- Sensitive data is encrypted to ensure unauthorized access is prevented.
3
- Ensure the application of cybersecurity regulations in the field of data storage.
- Guaranteeing data safety and ensuring the application of policies related to it.
- Revoke all privileges granted to the employee.
- Deny access to the university’s systems.
- Financial or disciplinary penalties may apply.