IMST 06: Backup and Restoration Standard
(Information Classification - Public)
1. Introduction and Purpose
1.1 This Standard establishes a comprehensive framework for safeguarding the university’s digital data through systematic backup and restoration procedures. Its primary objective is to ensure the continuity of academic, administrative, and research operations by minimising data loss and enabling timely recovery in the event of system failures, cyber incidents, or natural disasters.
1.2 Backups are retained exclusively to support incident response, investigations, and disaster recovery activities. Deleted or erased data is not routinely retrieved from backup systems. Where data restoration is necessary, any restored information shall be handled in accordance with the UK GDPR, the Data Protection Act 2018, and the Freedom of Information Act, ensuring compliance with records retention requirements and authorised lawful access arrangements.
2. Scope and Definitions
2.1 The Standard covers everyone who has a contractual (formal or informal/implied) relationship with the University, including employees, students, visiting academics, and consultants. Please note that this list is not exhaustive.
2.2 For purposes of this Standard, we will refer to everyone covered as “members.”
2.3 The Standard covers all information processed by the University, regardless of ownership or format.
Definitions:
• Backup: The process of creating secure copies of data to protect against loss, corruption or disaster.
• Restoration: The process of recovering data from backups to its original state following a failure or incident.
• RTO (Recovery Time Objective): The maximum acceptable time to restore a system or data after disruption.
• RPO (Recovery Point Objective): The maximum acceptable amount of data loss measured in time.
• 3:2:1 Rule: Maintain three copies of backup data (three copies, on two different media or platforms, with one copy offsite).
• Critical assets: Hardware and Software essential for university operations, including servers, storage systems and network equipment.
• Encryption: The process of converting data into a secure format to prevent unauthorised access during storage or transmission.
• Offsite Storage: A secure location separate from the primary site used for storing backup data to ensure availability during disasters.
• Air-gapped backups: Backup that is physically or logically isolated from the production network, making it inaccessible to attackers through remote connections.
• Immutable backups: Backups that cannot be altered or deleted for a defined retention period
3. Responsibilities
3.1 The Chief Information Security Officer (CISO) retains overall accountability for this Standard and for ensuring the Standard meets legal and regulatory requirements; for keeping this Standard up to date; and for ensuring that controls, checks, and audits are carried out as part of compliance with this Standard.
4. Operational Responsibilities
4.1 Adherence to this Standard is achieved by following its principles and other provisions. It is everyone’s responsibility to ensure that they follow this Standard. Specific responsibilities associated to the standard are:
| Role | Function |
| Designate of Head of Department (e.g. academic lead on research, individuals with delegated authority for information, system administrators) | Responsible – for overseeing compliance with the Standard within areas of responsibility |
| Head of Department (or equivalent) | Accountable – for compliance with this Standard within Departments |
| Information Risk and Compliance Team (with escalation to CISO and CDO required) | Consult – to discuss organisational level compliance with the Standard |
| IDG Digital Business Partners | Inform – must be informed of the content of the Standard to communicate it to their departments |
5. Backup Strategy
5.1 Backups must adhere to a “3-2-1” redundancy rule in which multiple backup copies are maintained in multiple storage locations. Backups must be performed using a combination of full, incremental and differential methods. Full backups must be scheduled to support data integrity and minimise data loss, with frequency determined by system owners according to business need. Backup copies must be stored in secure secondary locations to provide redundancy and resilience. ‘Grandfatherfather-son' rotation principle must be implemented as stated in IMP 06 System Administration Policy. System Owners must create and maintain a RACI matrix to define roles and responsibilities for backup and restoration tasks.
6. Restoration Procedures
6.1 In the event of data loss or system failure, restoration procedures must be executed according to a documented step-by-step plan tailored to each system or department. System owners must ensure the creation of and access to restoration runbooks or playbooks that detail how to recover their systems from backups. Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) must guide prioritisation, ensuring that mission-critical systems are restored at the earliest. Restoration logs must be maintained for accountability. System Owners must define RPO and RTO for all systems based on criticality and business needs. Critical assets must be restored first, based on priority defined as per the RTO/RPO. Restoration logs must be maintained for accountability, and checksum validation must be used during restoration to ensure data integrity.
7. Verification and Testing
7.1 System owners must ensure yearly full restoration tests for all systems and services are conducted to validate compliance with defined RTO and RPO. All systems and services do not need to undergo such tests simultaneously, however, tests can be batched to encompass multiple systems or services. Periodic restoration tests must be performed for all types of backups to confirm the effectiveness of backup procedures. Automated integrity checks must verify backup hashes and restore points after each backup cycle. Annual disaster recovery drills simulating full-site failover must be performed to ensure readiness for major incidents. Testing phases must be comprehensively documented in an auditable record.
8. Retention Policy
8.1 System owners responsible for backups must establish a minimum and maximum retention period for backups which allow for reasonable time to restore or recover data whilst not retaining data for longer than is necessary. Taking into consideration security, data protection and resourcing requirements. It is at System Owners' discretion to set appropriate periods according to assessed risk.
8.2 At the end of any such retention periods, backups must be securely and irrecoverably deleted.
9. Continuous Improvement
9.1 In the event of any incident such as a backup or restoration failure, or near miss, post-incident reviews must be conducted, and SOPs (Standard Operating Procedures) and/or any other relevant documentation must be updated accordingly by System Owners. Lessons learned must be documented and integrated into future processes to improve resilience.
10. Mandates
• Backup Technologies: Utilise automated backup systems, cloud-based solutions and local storage. Ensure encryption for all backup traffic.
• Process documentation: System owners must ensure documented processes for backup creation, protection, and testing are maintained.
• Data Scope: Backups must include databases, file systems, configuration files, application data and event logs.
• Security Measures: Protect backup data through encryption, secure storage and strict access control. Enforce network segmentation for backup traffic.
• Database Protection: Critical databases must be backed up in a manner that supports the required recovery point objectives, using appropriate transaction log or point-in-time recovery mechanisms
10.1 Additional Guidelines
• Go-Bag System: Identify essential devices and maintain a go-bag system for emergency recovery including credentials and disaster recovery documentation.
• Air-Gapped and Immutable Backups: Create air-gapped and immutable backup copies to provide resilience against ransomware and other advanced threats.
• Bandwidth Optimization: compression and deduplication techniques to be implemented to reduce backup size.
11. Exceptions
11.1 Exception requests under this Standard must be submitted to the CISO or their designate. Authority to approve exception requests is delegated to the Information Risk and Compliance Team. Activities that have received prior approval by the Research Governance and Ethics Committee will be exempt, but the CISO must be notified.
11.2 This Standard may have an impact on users of assistive technology or assistive software dependent on circumstances. These individual cases will be considered on a case-by-case basis.
12. Compliance Monitoring
12.1 All members of the University are expected to comply with this document as part of the Information Management Policy Framework (IMPF). Where breaches of the IMPF present a significant risk, including those falling under Regulations 23 (Student Disciplinary Offences) and Regulation 31(Information Management, Security and Records Management), they will be subject to the appropriate student or staff disciplinary procedure or applicable contractual terms for staff not employed directly by the University or contractors.
12.2 It is the responsibility of all members to report any instances of non-compliance to the Information Risk and Compliance Team. This can be done via the Self Service Portal. This team monitors adherence to the IMPF using reported data and other available tools.
12.3 Where issues require escalation or further review, they will be referred to the Information Security and Data Protection Committee via the Chief Information Security Officer (CISO) and include either Conduct and Resolution Team or Employee Relations Team, as appropriate.
Version/document control
| Version | Date created | Date published | Next review | Notes/outcomes |
| 1.0 | 5 May 2026 | 26 September 2026 | September 2027 |