Kean University DG– Backup, Retention & Destruction (SOP)
Table of Contents
- About This SOP
- Scope
- Definitions
- Roles & Responsibilities
- Procedure
- Related Policies & Standards
- Compliance Mapping
- Metrics & KPIs
- Required Records & Storage
- Revision History
About This SOP
This Standard Operating Procedure (SOP) defines how Kean University performs data backups, enforces data retention requirements, and securely destroys data at the end of its lifecycle.
This SOP operationalizes backup, disaster recovery, retention, and destruction requirements established in KU DG 01 – Data Governance & Protection Policy.
Scope
- All University systems containing Internal, Confidential, or Restricted data
- On‑premises, cloud, and hybrid environments
- IT Infrastructure, Operations, Security, and Data Stewards
- All backup, retention, archival, and destruction workflows
Definitions
- Backup – A copy of data stored separately to support recovery.
- Retention – The length of time data must be kept before destruction.
- Destruction – Secure, irreversible deletion of data.
- Critical System – A system essential to University operations requiring daily backups.
- Restricted Data – Legally protected data requiring maximum safeguards.
Roles & Responsibilities
IT Infrastructure & Operations
- Execute and monitor backups
- Ensure encryption of backup data
- Perform restoration and integrity testing
Data Owners
- Define retention requirements
- Approve destruction of Confidential or Restricted data
Data Stewards
- Validate retention schedules
- Coordinate secure destruction activities
IT Security
- Monitor backup failures or anomalies
- Validate destruction methods
Users
- Store data only on systems covered by backups
- Report missing or inaccessible data promptly
Procedure
Step 1 — Identify Data and System Classification
Confirm whether systems and data are Critical, Internal, Confidential, or Restricted.
Step 2 — Configure Backup Schedules
Critical systems require daily incremental backups and weekly full backups.
Step 3 — Secure Backup Storage
Backups must be encrypted and stored only on IT‑approved platforms.
Step 4 — Backup Integrity & DR Testing
Perform integrity checks and semiannual disaster recovery testing.
Step 5 — Manage Retention
Apply retention schedules based on classification and regulatory requirements.
Step 6 — Secure Destruction
Destroy data using cryptographic erasure, secure wiping, or shredding when retention expires.
Step 7 — Documentation & Exceptions
Retain destruction certificates and handle exceptions per KU SEC 05.
Related Policies & Standards
- KU DG 01 – Data Governance & Protection Policy
- KU DG 02 – Data Access & Privacy Policy
- KU SEC 03 – Incident Response
- KU SEC 05 – Exception Management
- KU BC 01 – Business Continuity
- KU IT 03 – Cybersecurity Training & Awareness
Compliance Mapping
| NIST CSF Function | Category | Subcategory |
|---|---|---|
| Protect | PR.DS – Data Security | PR.DS01, PR.DS02, PR.DS03 |
| Recover | RC.RP – Recovery Planning | RC.RP01 |
Metrics & KPIs
- Daily backup success rate
- Number of backup failures
- Disaster recovery test success rate
- Retention compliance rate
- Number of destruction certificates issued
Required Records & Storage
- Backup logs and integrity reports
- Disaster recovery testing reports
- Retention schedules
- Destruction certificates
- Exception approvals
Revision History
| Version | Date | Description | Author (Role) | Approver (Role) |
|---|---|---|---|---|
| 1.0 | February 13, 2026 | Initial release | IT Infrastructure & Operations Lead | Chief Information Security Officer |
``