{"id":49114,"date":"2021-02-02T14:21:44","date_gmt":"2021-02-02T10:21:44","guid":{"rendered":"https:\/\/www.msp360.com\/resources\/?p=49114"},"modified":"2024-07-26T13:44:07","modified_gmt":"2024-07-26T09:44:07","slug":"backup-policy-best-practices","status":"publish","type":"post","link":"https:\/\/www.msp360.com\/resources\/blog\/backup-policy-best-practices\/","title":{"rendered":"Backup Policy Best Practices"},"content":{"rendered":"<p>If you\u2019re responsible for managing backups in an organization, then you might have been asked to author a backup policy (but been unsure about what exactly it entails). A backup policy is a formal document setting out the high-level governance of backups within an organization.<!--more--> It takes its place among other high-level corporate documents and commonly receives input from functions outside of IT including the compliance and legal teams.<\/p>\n<p>Although several departments may maintain their own backup documentation, the backup policy is the overarching document responsible for setting down standards and best practices for backup within an organization. Think of it as the definitive word as to which backup practices will be followed. There might be other backup policies within a company (we\u2019ll get to those later) but the backup policy is the one that sets down the score.<\/p>\n<div class=\"table-of-content \">\n\t\t\t\t<p>Table of Contents<\/p>\n\t\t\t\t<ul><\/ul>\n\t\t\t\t<\/div>\n<h2>What Is A Backup Policy?<\/h2>\n<p>A <strong>backup policy<\/strong> is a formal document that sets down guidelines for how backups should be handled within a company. The document could set down procedures, responsible parties, and specify related documentation (we\u2019ll review the contents of the typical backup policy later in the article).<\/p>\n<p>A formal backup policy differs from other documents in the organization which might describe themselves as backup policies. These could, for instance, be the backup or <a href=\"https:\/\/www.msp360.com\/resources\/blog\/disaster-recovery-plan-checklist\/\">disaster recovery (DR) plans<\/a> which certain parts of the business \u2014 like the marketing or sales teams \u2014 have prepared.<\/p>\n<p>While these policies might pertain to specific technical systems, only the formal backup policy is the overarching document that is responsible for setting company-wide backup direction. Backup policies have strict structures and may require input from HR and legal teams, among other stakeholders.<\/p>\n<p><span class=\"further-reading \">Further reading<\/span> <a href=\"https:\/\/www.msp360.com\/resources\/blog\/creating-resilient-backup-policies-a-step-by-step-guide\/\">Creating Resilient Backup Policies: A Step-by-Step Guide<\/a><\/p>\n<h2>Formal Backup Policy<\/h2>\n<p>As an official corporate document, the backup policy will tend to follow a tried and tested formula. Some of the fields that should be included are:<\/p>\n<h3>Statement<\/h3>\n<p>The statement component of the backup policy will state the key information about the backup policy such as the document\u2019s formal title, how it should be referred to internally, what date it was prepared on, and who was responsible for authoring it.<\/p>\n<h3>Purpose<\/h3>\n<p>The purpose section will typically state what the backup policy is meant to achieve. It might say, for instance, that the policy is intended to standardize backup procedures across the organization.<\/p>\n<h3>Scope<\/h3>\n<p>If your organization is large enough to be authoring a backup policy, then the backup policy should also probably clearly delineate its scope. The backup policy might spell out exactly which employees (or departments) and assets fall under the governance of this backup policy. It\u2019s always better to be clear than ambiguous. So if there\u2019s any room for doubt about whether the backup policy will apply to a certain team, it\u2019s better to state it in the document.<\/p>\n<h3>Related Documentation<\/h3>\n<p id=\"last\">If your IT team has a formal Backup Manager, then he or she may be charged with periodically reviewing and updating all the existing backup documentation in an organization. For that reason, it\u2019s worth including a list of all the other backup-related documents within the company. If the backup policy is going to be a digital file (or hosted in a knowledge management system like Confluence) then you could either embed the other documents or link off to them here.<\/p>\n<div id=\"slidebox\"><span class=\"close\">\u00a0<\/span><!--HubSpot Call-to-Action Code --><span class=\"hs-cta-wrapper hs-cta-deferred\" id=\"hs-cta-wrapper-aa07fdb8-7776-46a5-9fa0-ec6e93f0f0a6\" data-portal=\"5442029\" data-id=\"aa07fdb8-7776-46a5-9fa0-ec6e93f0f0a6\"><span class=\"hs-cta-node hs-cta-aa07fdb8-7776-46a5-9fa0-ec6e93f0f0a6\" id=\"hs-cta-aa07fdb8-7776-46a5-9fa0-ec6e93f0f0a6\"><!--[if lte IE 8]><div id=\"hs-cta-ie-element\"><\/div><![endif]--><a href=\"https:\/\/cta-redirect.hubspot.com\/cta\/redirect\/5442029\/aa07fdb8-7776-46a5-9fa0-ec6e93f0f0a6\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" class=\"hs-cta-img\" id=\"hs-cta-img-aa07fdb8-7776-46a5-9fa0-ec6e93f0f0a6\" style=\"border-width:0px;\" src=\"https:\/\/no-cache.hubspot.com\/cta\/default\/5442029\/aa07fdb8-7776-46a5-9fa0-ec6e93f0f0a6.png\" alt=\"CTA\"><\/a><\/span><\/span><!-- end HubSpot Call-to-Action Code --><\/div>\n<p>The related documentation, specifically, could map out:<\/p>\n<ul>\n<li>Other documentation relating to procedures and workflows<\/li>\n<li>Disaster recovery plans within the organization<\/li>\n<\/ul>\n<p>This index section can be periodically updated as companies\u2019 libraries of internal backup documentation continue to expand and evolve.<\/p>\n<p><span class=\"further-reading \">Further reading<\/span> <a href=\"https:\/\/www.msp360.com\/resources\/blog\/guide-to-msp-internal-documentation-principles-and-practices\/\">Guide to MSP Internal Documentation: Principles and Practices<\/a><\/p>\n<h3>Responsibility<\/h3>\n<p>To maximize the effectiveness of disaster recovery (DR) efforts, the backup policy should also clearly outline areas of responsibility for an organization\u2019s approach to backup. For instance, the document should lay out which team member is responsible for backing up and restoring which systems. Many organizations choose to specify a job function (title) rather than an individual in case people leave the company.<\/p>\n<h2>When You Need A Formal Backup Policy<\/h2>\n<p>Certain companies are likely to be able to manage just fine without a formal backup policy. However, there are circumstances in which authoring this kind of document is essential.<\/p>\n<p>Such companies include:<\/p>\n<ul>\n<li>Companies that need to manage sensitive data that falls under standards or legislation. For instance, healthcare companies need to manage patient data, like electronic medical records (EMRs) in accordance with the standards set down in the <a href=\"https:\/\/www.msp360.com\/resources\/blog\/hipaa-compliant-cloud-backup\/\">HIPAA legislation<\/a>. Companies in this space may be subject to governmental audits. In many instances, they are also obliged to have a formal policy backup in place documenting how backup data is managed. In other instances achieving compliance with a data governance standard may require that a backup policy be documented and maintained.<\/li>\n<li>Besides healthcare, this requirement may affect companies operating in the financial services and legal spheres, among others.<\/li>\n<li>Large organizations might also require backup policies because these companies are more likely to appoint a dedicated person, or team, for managing backup. Backing up multiple systems typically involves more complexity. A formal backup policy is very useful in these cases to set down standards for the workflows of many delegated backup administrators.<\/li>\n<\/ul>\n<p><span class=\"further-reading \">Further reading<\/span> G<a href=\"https:\/\/www.msp360.com\/resources\/blog\/backup-management-for-msps\/\">uide to Backup Management for MSPs<\/a><\/p>\n<div class=\"call-to-action\">\n<div class=\"call-to-action__left\" style=\"width: 75%;\">\n<div class=\"call-to-action__title\">Essential Guide to Backup for MSPs<\/div>\n<div class=\"call-to-action__text\">Backup best practices and tips on how to protect your customers\u2019 sensitive data<\/div>\n<!--HubSpot Call-to-Action Code --><span class=\"hs-cta-wrapper hs-cta-deferred\" id=\"hs-cta-wrapper-d7a3df42-5072-4766-aac8-e2bc23caa204\" data-portal=\"5442029\" data-id=\"d7a3df42-5072-4766-aac8-e2bc23caa204\"><span class=\"hs-cta-node hs-cta-d7a3df42-5072-4766-aac8-e2bc23caa204\" id=\"hs-cta-d7a3df42-5072-4766-aac8-e2bc23caa204\"><!--[if lte IE 8]><div id=\"hs-cta-ie-element\"><\/div><![endif]--><a href=\"https:\/\/cta-redirect.hubspot.com\/cta\/redirect\/5442029\/d7a3df42-5072-4766-aac8-e2bc23caa204\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" class=\"hs-cta-img\" id=\"hs-cta-img-d7a3df42-5072-4766-aac8-e2bc23caa204\" style=\"border-width:0px;\" src=\"https:\/\/no-cache.hubspot.com\/cta\/default\/5442029\/d7a3df42-5072-4766-aac8-e2bc23caa204.png\" alt=\"CTA\"><\/a><\/span><\/span><!-- end HubSpot Call-to-Action Code -->\n<\/div>\n<div class=\"call-to-action__right\" style=\"width: 25%;\"><img decoding=\"async\" src=\"https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2019\/12\/Backup-best-practices-icon-2.png\" alt=\"WP icon\" \/><\/div>\n<\/div>\n<h2>Other Backup Policies<\/h2>\n<p>In addition to a formal backup policy, other backup documentation can sometimes be called \u201cbackup policy\u201d. If you are tasked with creating a \u201cbackup policy\u201d, but you clearly understand that it\u2019s not a formal document, you should better ask about the exact nature of the needed document. Here are some popular examples:<br \/>\nDisaster Recovery Plan<br \/>\nThe disaster recovery (DR) plan typically consists of detailed documentation outlining exactly what steps the business will have to take in order to restore from any of a number of disasters. The DR plan will typically set out detailed instructions for restoring key mission-critical business functionalities and also stipulate a personal responsibility for executing each task in the plan.<\/p>\n<p>DR plans are vital and often the first pieces of documentation that those involved in continuity go looking for when something goes wrong. But they don\u2019t set down the same overarching standards as a backup policy typically does. <!--HubSpot Call-to-Action Code --><span class=\"hs-cta-wrapper hs-cta-deferred\" id=\"hs-cta-wrapper-a99bf554-4786-40d2-8e73-43bf625d6417\" data-portal=\"5442029\" data-id=\"a99bf554-4786-40d2-8e73-43bf625d6417\"><span class=\"hs-cta-node hs-cta-a99bf554-4786-40d2-8e73-43bf625d6417\" id=\"hs-cta-a99bf554-4786-40d2-8e73-43bf625d6417\"><!--[if lte IE 8]><div id=\"hs-cta-ie-element\"><\/div><![endif]--><a href=\"https:\/\/cta-redirect.hubspot.com\/cta\/redirect\/5442029\/a99bf554-4786-40d2-8e73-43bf625d6417\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" class=\"hs-cta-img\" id=\"hs-cta-img-a99bf554-4786-40d2-8e73-43bf625d6417\" style=\"border-width:0px;\" src=\"https:\/\/no-cache.hubspot.com\/cta\/default\/5442029\/a99bf554-4786-40d2-8e73-43bf625d6417.png\" alt=\"CTA\"><\/a><\/span><\/span><!-- end HubSpot Call-to-Action Code --><\/p>\n<p><span class=\"further-reading \">Further reading<\/span> <a href=\"https:\/\/www.msp360.com\/resources\/blog\/cloud-disaster-recovery\/\">Building a Cloud Disaster Recovery Plan: Tips and Approaches<\/a><\/p>\n<h3>Backup Retention Policy<\/h3>\n<p>The backup retention policy specifies the time periods for which backups need to be retained in the organization. This particular policy can be informed by the regulatory policies that the company has to comply with.<\/p>\n<p><span class=\"further-reading \">Further reading<\/span> <a href=\"https:\/\/www.msp360.com\/resources\/blog\/how-to-build-retention-policy\/\">Backup Retention Policy and Scheduling Best Practices<\/a><\/p>\n<h3>RTO \/ RPO Considerations<\/h3>\n<p>The <a href=\"https:\/\/www.msp360.com\/resources\/blog\/recovery-time-objective-rto-explained\/\">recovery time objective<\/a> (RTO) and <a href=\"https:\/\/www.msp360.com\/resources\/blog\/recovery-point-objective-explained\/\">recovery point objective<\/a> (RPO) specify the maximum amount of time that can elapse from a declaration of a disaster through to the restoration of services and the maximum amount of data that can be lost in the restore process respectively. Sometimes companies will create a separate backup policy document setting out the RPO and RTO targets for every business system with mission-critical tools (like CRMs and ERPs) typically having more ambitious objectives than less essential IT services<\/p>\n<p><span class=\"further-reading \">Further reading<\/span> <a href=\"https:\/\/www.msp360.com\/resources\/blog\/rto-vs-rpo-difference\/\">Recovery Time (RTO) and Recovery Point (RPO) in DR Strategy<\/a><\/p>\n<h2>Backup and Recovery Frameworks<\/h2>\n<p>Finally, any document(s) that have to do with the overall <a href=\"https:\/\/www.msp360.com\/resources\/blog\/backup-vs-disaster-recovery\/\">backup and disaster recovery<\/a> process might tend to be referred to as \u201cpolicies\u201d \u2014 even if they merely contain information or were intended as reference documents. Examples of this kind of document might be:<\/p>\n<ul>\n<li>An inventory of all current systems<\/li>\n<li>A contact directory of all staff responsible for backup or an organizational chart of the backup decision-makers<\/li>\n<\/ul>\n<h2>Best Practices For Creating A Backup Policy<\/h2>\n<p>All backup policies are not created equal and some IT teams do a better job of creating them than others. If you\u2019re been charged with preparing one for your department or workgroup then you should draft it with the following best practices in mind.<\/p>\n<ul>\n<li><strong>Understand the purpose:<\/strong> Remember that the backup policy is intended to set down the overall direction for how your organization is to run backups and DR. Take an inventory of existing backup \u201cpolicies\u201d including the ones we referred to in the previous section. Draft a document that sets down guidelines that these policies meet. After all, the document you\u2019re about to create should be the central source of knowledge that will inform the creation of future derivative documents.<\/li>\n<li><strong>Fill the gaps:<\/strong> If, on the other hand, your organization doesn\u2019t have any backup documentation, then see this as your chance to begin creating it. You might wish to begin thinking about what credible target RTOs \/ RPOs might look like for the various systems and data repositories you\u2019ll want to be backing up.<\/li>\n<li><strong>Clear language: <\/strong>Backup policies don\u2019t tend to make good bedside reading. Bear in mind that people are likely going to be skimming your document in order to access the required information. Therefore adhere to a clear structure. Use headings and subheadings to highlight information logically. Use easy to understand language.<\/li>\n<li><strong>Reviewed by legal department or lawyer:<\/strong> Because backup policies often touch up on data governance, they may raise compliance issues \u2014 particularly for organizations that are bound by certain statutes. If this is the case, then make sure that your policy has received all the appropriate internal sign-offs, including from your law officer or legal department.<br \/>\n<span class=\"further-reading \">Further reading<\/span> <a href=\"https:\/\/www.msp360.com\/resources\/blog\/legal-services-to-msps\/\">The Importance of Legal Services to MSPs Explained<\/a><\/li>\n<li><strong>Tested:<\/strong> All backups should go through test restore processes. The policy should be a living document that reflects actual backup workflows. If a policy isn\u2019t feasible \u2014 or it can\u2019t be tested \u2014 then it shouldn\u2019t be documented.<br \/>\n<span class=\"further-reading \">Further reading<\/span> <a href=\"https:\/\/www.msp360.com\/resources\/blog\/how-to-test-your-backups-comprehensive-guide\/\">How to Test Your Backups: A Comprehensive Guide<\/a><\/li>\n<li><strong>Regularly updated:<\/strong> Don\u2019t forget to include a field for periodic updates so that the document can be kept updated and readers can see when it was last revised. It\u2019s especially important to include this field if your corporate governance dictates that all policy documents need to be revised and updated at fixed intervals.<\/li>\n<\/ul>\n<h2>A Strong Policy Governs Good Backups<\/h2>\n<p>Managing backup and DR in the enterprise environment is a complex process and the person entrusted to lead it is responsible for maintaining the integrity of data across multiple business systems.<\/p>\n<p>To ensure continuity and operational efficiency, a central backup policy should be documented and periodically revised. This is the central document that can serve to set down agreed best practices and RTO\/RPO for all staff members involved in the backup.<\/p>\n<p>Those drafting the document should remember that the document should be considered the first source of backup knowledge in the company. It should supersede and agree with other existing \u201cbackup policies\u201d in the company, which may in fact simply be frameworks. The document should have a nominated custodian and be periodically updated with a clear revision date update (and sometimes a changelog) after every edit.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you\u2019re responsible for managing backups in an organization, then you might have been asked to author a backup policy (but been unsure about what exactly it entails). A backup policy is a formal document setting out the high-level governance of backups within an organization.<\/p>\n","protected":false},"author":59,"featured_media":49118,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[883,877],"tags":[],"class_list":["post-49114","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-backup-and-dr-articles","category-blog-articles"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/posts\/49114","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/users\/59"}],"replies":[{"embeddable":true,"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/comments?post=49114"}],"version-history":[{"count":6,"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/posts\/49114\/revisions"}],"predecessor-version":[{"id":58128,"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/posts\/49114\/revisions\/58128"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/media\/49118"}],"wp:attachment":[{"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/media?parent=49114"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/categories?post=49114"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/tags?post=49114"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}