Ohio Administrative Code
Title 3364 - University of Toledo
Chapter 3364-65 - Technology Security and Safeguarding
Section 3364-65-09 - Technology backup, disaster, readiness, and recovery policy
Current through all regulations passed and filed through September 16, 2024
(A) Policy statement
Information technology is an integral part of how the university carries out its mission. The university is committed to ensuring that vital technology resources and information stores are appropriately prepared to support recovery and business resumption efforts following accidental deletion, system corruption, and/or physical loss or damage.
(B) Purpose
To ensure that the university's technology procurement and development life-cycle incorporates disaster recovery and back-up methodologies that will enable recovery and subsequent business resumption following accidental or malicious deletion, system corruption, and/or physical loss or damage.
(C) Scope
Compliance with this policy is mandatory for all university organizational units that create, store, process, transmit, or receive data vital to the university's mission, and for all university organizational units which procure, develop, operate, maintain, or dispose of technology assets vital to the university's mission, including telecommunications and network infrastructure, data center environmental controls, servers, data storage systems, workstations, and other devices.
(D) Backups
Reasonable backups of data and technology assets vital to the university mission must be prepared at appropriate intervals and be reasonably available for restoration for an appropriate retention period. Except as otherwise determined by the vice president, chief information officer/chief technology officer "CIO/CTO" or delegate, a full or incremental system backup prepared daily is considered reasonable if the backup is available for at least two weeks (fourteen calendar days) from the time taken and stored not less than three miles from the site of the original data or technology asset.
In addition to the requirements set forth in this policy, the conduct of backup activities must comply with all other university policies and applicable privacy, security, and compliance obligations, including those university policies concerning the encryption and secure destruction and sanitization of data and electronic storage media.
(E) Disaster readiness
Data and technology assets vital to the university mission must be made reasonably prepared to respond to an accidental or malicious deletion, system corruption, and/or physical loss or damage event. Except as otherwise determined by the vice president, CIO/CTO or delegate, reasonable preparations include system backups as described in this policy, current hardware and software support contracts, and reasonable availability of personnel versed in operation and restoration of the asset or data.
(F) Disaster recovery
Data and technology assets vital to the university mission must be recovered within a reasonable time in the event of accidental or malicious deletion, system corruption, and/or physical loss or damage. Except as otherwise determined by the vice president, CIO/CTO or delegate, a reasonable recovery is initiated within one business day of discovery of an accidental deletion, system corruption, and/or physical loss or damage event.
(G) Applicable guidance
Consult the following authorities for specific requirements for backup, disaster readiness, and recovery of data and technology assets within the university's clinical environments: