Backup Policy And Procedure¶
Backup Policy and Procedure
Version history¶
| Version Number | Date | Description | Created By | Approved By |
|---|---|---|---|---|
| 0.1 | 23/Apr/2024 | Initial Copy | [Name] [Name] | |
| 0.2 | 18/Jun/2024 | Approved | [Name] [Name] | [Name] |
| 0.3 | 28/Aug/2026 | Knowledge kernel, AI/agents, control alignment | Knowledge steward | [Name] |
Purpose¶
This policy aims to define the rules for taking data backups and assessing the restoration.
Scope¶
The policy covers backups of all types of data and information within the tecciance.
Terms and Conditions¶
Following is an explanation of various terms used within this document –
-
Backup: A copy of file, data, or information made in case the original is lost or damaged.
-
Backup Server: A backup server enables the backup of data, files, applications, and/or databases on a specialized in-house or remote server. It combines hardware and software technologies that provide backup storage and retrieval services to connected computers, servers, or related devices.
-
Incremental Backup: An incremental backup is one in which successive copies of the data contain only the portion that has changed since the making of the preceding backup copy.
-
Differential Backup: A data backup method that copies all files that have changed since the performance of the last full backup.
-
Recovery Test: A backup recovery test is a process used to ensure that the backup and recovery plan will work how it should work after a real emergency.
Responsibilities¶
The primary responsibility of implementing this policy is with the IT Team and the IST (Information Security Team).
Policy¶
Data Backups and Frequency¶
Below types of data, within the tecciance, shall be backed up –
-
Emails on Gmail
-
Application Server – Google
-
Cloud Database – Google GCP
-
Files and folders on Google Drive and
-
Jira Client and Uset data on Google
-
Cloud Source code – Bitbucket
-
Frequency of backup for each data
-
Database – Full Backup – Daily
-
Database – Incremental Backup – Daily (Auto)
-
Gsuite data – Real-time.
-
Source code – Real-time.
-
Jira – Real-time.
Backup Restorations Testing¶
-
Backup restorations testing should be done per the below schedule –
-
Email – Never as it is included in the services of the service provider.
-
Database – Quarterly (Limits only to last 35 days)
-
GSuit data - Never as it is included in the services of the service provider.
-
Source Code – Quarterly (No limit)
-
Records of restoration testing shall be maintained.
-
In case of any error or failure during restoration testing, the incident management process should be followed.
Artificial intelligence, software agents, and organizational knowledge¶
This section is added in version 0.3 so the policy applies equally to employees and to software agents, and so reusable knowledge stays provenanced.
Software agents, bots, service accounts, CI jobs, and coding assistants are identities. They are in scope of this policy wherever people are.
Every retrieve or use of organizational knowledge or classified data requires a verified identity, a stated purpose, and a classification ceiling. Missing purpose is deny.
AI may extract, draft, rank, or propose. AI shall not approve access, classify or reclassify information, set reuse rights, waive a control, merge to a protected branch, or treat search ranking as truth.
Approved reusable knowledge is a governed claim with source, owner, lifecycle, applicability, and limitations. Raw chat, tickets, and scanner output are not approved knowledge.
Embeddings, summaries, caches, and compiled agent skills are derivatives. Withdrawal, reclassification, or destruction of a source shall propagate to derivatives.
Secrets, credentials, production data dumps, and Restricted (including client/PHI) material shall not be pasted into public generative-AI services or stored in vector indexes unless an authorized path and agreement exist.
HIPAA-regulated PHI is out of default scope. Enable the HIPAA pack and a business-associate path before any PHI is processed by agents or knowledge indexes.
Change to a must procedure (including knowledge used by agents) is a change under the Change / Release procedure and SOC 2 CC8.1. Agents cannot approve that change.
Knowledge-registry and audit stores are backup-scoped. Destruction and withdrawal must be reconcilable against backups under retention rules.