Kean University DG– Backup, Retention & Destruction (SOP) 8


Kean University DG– Backup, Retention & Destruction (SOP)

Table of Contents

About This SOP

This Standard Operating Procedure (SOP) defines how Kean University performs data backups, enforces data retention requirements, and securely destroys data at the end of its lifecycle.

This SOP operationalizes backup, disaster recovery, retention, and destruction requirements established in KU DG 01 – Data Governance & Protection Policy.

Scope

  • All University systems containing Internal, Confidential, or Restricted data
  • On‑premises, cloud, and hybrid environments
  • IT Infrastructure, Operations, Security, and Data Stewards
  • All backup, retention, archival, and destruction workflows

Definitions

  • Backup – A copy of data stored separately to support recovery.
  • Retention – The length of time data must be kept before destruction.
  • Destruction – Secure, irreversible deletion of data.
  • Critical System – A system essential to University operations requiring daily backups.
  • Restricted Data – Legally protected data requiring maximum safeguards.

Roles & Responsibilities

IT Infrastructure & Operations

  • Execute and monitor backups
  • Ensure encryption of backup data
  • Perform restoration and integrity testing

Data Owners

  • Define retention requirements
  • Approve destruction of Confidential or Restricted data

Data Stewards

  • Validate retention schedules
  • Coordinate secure destruction activities

IT Security

  • Monitor backup failures or anomalies
  • Validate destruction methods

Users

  • Store data only on systems covered by backups
  • Report missing or inaccessible data promptly

Procedure

Step 1 — Identify Data and System Classification

Confirm whether systems and data are Critical, Internal, Confidential, or Restricted.

Step 2 — Configure Backup Schedules

Critical systems require daily incremental backups and weekly full backups.

Step 3 — Secure Backup Storage

Backups must be encrypted and stored only on IT‑approved platforms.

Step 4 — Backup Integrity & DR Testing

Perform integrity checks and semiannual disaster recovery testing.

Step 5 — Manage Retention

Apply retention schedules based on classification and regulatory requirements.

Step 6 — Secure Destruction

Destroy data using cryptographic erasure, secure wiping, or shredding when retention expires.

Step 7 — Documentation & Exceptions

Retain destruction certificates and handle exceptions per KU SEC 05.

  • KU DG 01 – Data Governance & Protection Policy
  • KU DG 02 – Data Access & Privacy Policy
  • KU SEC 03 – Incident Response
  • KU SEC 05 – Exception Management
  • KU BC 01 – Business Continuity
  • KU IT 03 – Cybersecurity Training & Awareness

Compliance Mapping

NIST CSF Function Category Subcategory
Protect PR.DS – Data Security PR.DS01, PR.DS02, PR.DS03
Recover RC.RP – Recovery Planning RC.RP01

Metrics & KPIs

  • Daily backup success rate
  • Number of backup failures
  • Disaster recovery test success rate
  • Retention compliance rate
  • Number of destruction certificates issued

Required Records & Storage

  • Backup logs and integrity reports
  • Disaster recovery testing reports
  • Retention schedules
  • Destruction certificates
  • Exception approvals

Revision History

Version Date Description Author (Role) Approver (Role)
1.0 February 13, 2026 Initial release IT Infrastructure & Operations Lead Chief Information Security Officer

``

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.