University of Minnesota  Appendix

Data Storage and Backup & Recovery Standard

Sidebar

Expand all

Sidebar

Table of Contents

TOC placeholder

Governing Policy

Questions?

Please use the contact section in the governing policy.

Objective

Identify appropriate data storage, backup and recovery, and data exchange to comply with legal, regulatory, or contractual agreements and to maintain the confidentiality, integrity and availability of University owned/generated data and the data for which the University has contracted.

Security Controls

Stored Data

The following table defines the baseline security controls for stored data.

ControlSecurity Level
IDDescriptionHighMediumLow
DSBR.A.01Store data on University approved location for the type of dataRequiredRequiredRecommended
DSBR.A.02Multi-user system (e.g., servers): Encrypt the data stored on the systemRecommended1RecommendedRecommended
DSBR.A.03Single-user system: Encrypt the data stored on the device or systemRequiredRequired
Effective July 2019
Recommended
DSBR.A.04Encrypt removable media (e.g., USB)RequiredRecommendedRecommended
DSBR.A.05Periodically review procedures for storing and handling information to protect its confidentiality, integrity and availability (suggest: annual)RequiredRequired
Effective July 2019
Recommended

1Required for:

  • Health information, HIPAA or ePHI data
  • Gramm-Leach Bliley (GLBA)
  • Credit card information as defined by PCI DSS
  • Controlled Unclassified Information (CUI) that falls under NIST 800-171

Data Exchange or Transfer of Stored Data

The following table defines the baseline security controls for data exchange or transfer of stored data.

ControlSecurity Level
IDDescriptionHighMediumLow
DSBR.B.01Encrypt Private-Highly Restricted dataRequired
Effective July 2019
Required
Effective July 2019
Required
Effective July 2019
DSBR.B.02Encrypt Private Restricted dataRecommendedRecommendedRecommended
DSBR.B.03Periodically review agreements for the exchange of and security protections of the information between the University and external entities (suggest: annual)RequiredRequiredRecommended

Backup & Recovery

Backup copies of data must be created on a regular basis, physically secured and backup processes tested periodically to maintain protect against loss of University data and to maintain business continuity.

The following table defines the baseline security controls for backup and recovery of data.

ControlSecurity Level
IDDescriptionHighMediumLow
DSBR.C.01Back up data where needed for continuityRequiredRequiredRequired
DSBR.C.02Store backups in a secure location that has limited access based on need (e.g., University or vendor secure site)RequiredRecommendedOptional
DSBR.C.03Use backup location that is not in the same building and some distance from where the original data or system is storedRequiredRecommendedOptional
DSBR.C.04For multi-user systems: Periodically review a backup and recovery plan and procedures including frequency, extent of backups, monitoring for successful completion, physical storage, access to backups, and backup testing (suggest: annual)RequiredRequiredRecommended
DSBR.C.04For single-user systems: Periodically review a backup and recovery plan and procedures including frequency, extent of backups, monitoring for successful completion of the backup, physical storage, access to backups, and backup testing (suggest: annual)Required
Effective July 2019
Required
Effective July 2019
Recommended
DSBR.C.05Maintain records / inventory of backupsRequired
Effective July 2019
RecommendedOptional
DSBR.C.06Categorize the media so sensitivity of the data can be determinedRecommended 1RecommendedRecommended
DSBR.C.07Encrypt data backup if the original data requires encryptionRequiredRequiredRequired
DSBR.C.08Encrypt the data during network transmission to/from the backup media/storage locationRequired
Effective July 2019
Required
Effective July 2019
Recommended
DSBR.C.09For multi-user system: Test for a successful backup and restoration by following documented procedures (suggest: annual)RequiredRecommendedRecommended
DSBR.C.09For single-user systems: Test for a successful backup and restoration by following documented procedures (suggest: annual)Required
Effective July 2019
RecommendedRecommended

1 Required for:

  • Health information, HIPAA or ePHI compliance on in-scope systems and applications;
  • PCI DSS on all systems or applications that store, process, or transmit cardholder data, or support the credit card processing environment;
  • where specified in a contractual agreement.

Resources Covered

This applies to IT resources owned or contracted by the University. This also applies to personally owned devices accessing, or authorized to store, University data designated as private-highly restricted or private-restricted.

Individuals Covered

This applies to University community members who use or manage University IT resources.

Related Information

Published Date

November 2014

Last Reviewed

April 2019