Setting objectives with the business
Acceptable data loss and downtime are not numbers a technical team should guess. For each critical service the business supplies a figure, and the cost of that figure is shown back to them.
- Whoever sets the target also sees the cost
- The figure is signed off and reviewed annually
- Systems that cannot meet their target are declared openly
- A new system gets its objective as it goes live
Retention obligations
How long to retain is a legal question as much as a technical one. Commercial, tax and data protection rules impose different periods, and deleting once a period expires is as much a duty as keeping.
- Retention periods are listed per data type
- Destruction triggers itself once the period ends
- Destruction records are retained and producible on request
- A legal hold suspends destruction temporarily
Separating backup from archive
Backup exists for return, archive for obligation. Managed in one system, data past its retention period keeps living in backups, growing both cost and compliance risk.
- Two needs, two policies, two durations
- Archive access may be slow but never incomplete
- The rule for moving backup to archive is written
- Archive formats are chosen to stay readable long term
Evidence and reporting
Meeting an obligation is demonstrated only through evidence. Coverage reports, failed job lists and restore test results are produced and retained on a regular cycle.
- Systems outside coverage appear in the report
- A failed backup job is followed up the next day
- Test results are recorded with date and duration
- Reports are kept ready for an audit request