the purpose of the policy

This document aims to clarify and define the process of managing the lifecycle of all data owned by Najran University in the field of storage and preservation of data. This policy has been aligned with national data management controls and specifications for data storage and preservation and the personal data protection system.

Scope of work

Scope of this policy applies to all data and systems owned by Najran University.

Terms of Storage and Disaster Protection

  1. Infrastructure for Storage:
    • Sitesafe
  • NetworkHighEfficiency.serversandstoragespacessuitable.
  • The establishment of a secure infrastructure for data storage ensures its absence of loss..
    1. Copy Backupand Restore
      • Providesaclearplanforthecompetentdean.
  • Backupofcopiesandstorageinmultipleandsecurelocations.
  • Implementation of a backup system that ensures the possibility of data recovery in its entirety in the event of a disaster in the system
    1. Cybersecurity Applications:
    • Ensurethe safety ofthe preservation environment and its updates, examining it and following up on its updates.
  •  Usemulti-levelsecuritytoprotectdatafromunauthorizedaccess. Data encryptionduringvarioussystemoperations,includingtransferringorstoringit.

  • steps to establish the infrastructure

    1. Design Technical Multi-Level
    1. Verify the used licenses and systems and ensure readiness of network works and security procedures in the correct manner.
  • The geographical distribution of backup copies reduces the risk of data loss and facilitates its retrieval
    1. Backup and Restore of Data
    • Verify the integrity of the backup copies by restoring them randomly periodically.
  • Encryptionatthelevelofoperatingsystems. Useof theplagiarismsystem to achievemoresecurity.
  • Guarantee Protection of Data:
      •  Encryptingdata.
      Protecting the Mesh Network.Protect the hosting environment

      1. Guaranteeof MonitoringEfficiency:
    • Usingtools to monitor and track the status of systems.
  • Ensurethatthe necessary updatesare activatedforthe backup systems
  • Plansforfacingdisasters
      • dir="RTL" style="margin-right:48px; text-align:justify"> The confirmation of the existence of plans to face disasters and preparedness for them.
  •  Conducting regular tests for disaster response plans during the Deanery..
  • steps to implement the backup system

    Firstly:Identify types of data and classify them based on their importance and sensitivity to identify and order priorities for backupcopies

    Secondly: Selecting the appropriate strategy for backup using either full or partial copying of any changes to the data.

    Thirdly:Selectingthe appropriatetools,and thatisduring the use ofthe well-knowntools with their high efficiency and availability.

    Fourthly, creating backup copies in geographically diverse locations or using cloud computing systems with tracking of storage spaces and ensuring their availability.

    Fifthly: Conducting periodic recovery tests and to ensure the operation of backup systems in the required manner always

    steps to retrieve data

    • It will bedata recoveryduring the presence of arecovery planclear to ensure the continuity of business and response to disasters. And by specifying the important data.
    University can build a data recovery plan for the critical mission in case of disasters.
  • Classification Levels Recovery Based On Time Or Objectives Or The Required Recovery Point .Choosethe appropriate tools..Establishagreementsat aservice leveland thatto ensurequality and achievethe desired goalsof the retrieval process.
  • Trainingteamsforbackupandprovidingthemwithknowledgeandskillsnecessary..Review plan recovery annually or every 3 years.
  • Steps to implement cybersecurity

    • Network protection through the use of FIREWALLS or intrusion detection systems.
  • Protectionondeviceandsoftwareduringupdaterequiredonsystemsorsoftware.
  • Protectionofdataduringscientificaccesstodataorbyencryptingthedatainthecaseofitstransferorstartingthebackupprocess.
  • Data retention period

    Commitment to periods defined by the regulations of the entities owning the data.

    Data Retention Policies Development

    The

    The points that should be considered in defining the periods for preserving the data:

    • CategorizationofData
  • Review and Follow-up Periods.
  • rules of deletion and addition

    To ensure the deletion and addition of and to backup reliable and effective measures for setting the process:

    • Documentation of procedures and their writing and awareness of working with them .
  • Assigning responsibilities and definingauthorities
  • Approval of the automation and that to ensure the application of policies deletion of data automatically.
  • Procedures in case of data loss

    First: Dealingwiththelossofdata:

    • Formation of a high efficiency team for handling cases of disasters
    • Identifyingtheactualcausesbehindthelossofdataandthatusingsystemsthatrevealdisastercases
    • Secondly: Reconstruction and Data Recovery:

      • Develop plans for data recovery using the backups that have been made.
      • Examination and verification of the integrity of recovered data to ensure that it has not been affected or damaged.

    Response Team and Governance at the University

    ThisteamprovidesamodelincludingformaintainingasafeandhealthyenvironmentandisconsideredthebackboneformanagingdataattheUniversity

    This team will develop and implement and maintain effective policies for storage and retention and destruction and recovery of data in emergency cases.

    Firstly

    • EfficiencyTechnical.
    • Responseforemergencies.Compliancewiththelawsandregulations

    Roles and Responsibilities

    م

    The Agency

    The role

    Responsibilities

    1

    Data Management Office

    Follow-up and review of the policy and updating it

    • Regular follow-up with the Deanery and ensuring the application of storage and backup policies.
    • Ensure the application of regulations and systems related to data and its lifecycle management process.

    2

    College of Digital Transformation and Knowledge Sources

    Implementation of Policy and Application thereof

    • Establish appropriate controls for data backup and retrieval, handling, and processing in accordance with this policy.
    • Providing the necessary systems for data safety.
    • Back up information and data of Najran University, as well as software, on internal and external storage media. And provide the key data for backups which include the following:
    • Version Number.Its history.
    • Version description.Serial number numbering.
    • The provisions for backups are valid only through the responsible party for the copies in the Deanship.Verify the integrity of preservation procedures.
    • Regularly and randomly verify the possibility of applying a backup to the operational environment.
    • Verify the full recovery of saved copies.Classification of Save Operations.
    • Specify the number of backup copies and set minimum retention periods and repetition counts.Maintain a single valid backup in a secure environment permanently and outside the boundaries of Najran University campus.
    • Documenting data recovery and periodic verification operations.
    • Establish and document mechanisms for verifying information received from parties, and prepare the necessary forms for that purpose.
    • Sensitive data is encrypted to ensure unauthorized access is prevented.

    3

    Cybersecurity Department

    Guarantee of Data Safety

    • Ensure the application of cybersecurity regulations in the field of data storage.
    • Guaranteeing data safety and ensuring the application of policies related to it.

    Procedures for legal violations of the storage and retention policy

    • Revoke all privileges granted to the employee.
    • Deny access to the university’s systems.
    • Financial or disciplinary penalties may apply.