Data Protection Blueprints
"When writing a data retention policy, you must determine how to: organize information so it can be searched and accessed later, and dispose of information that's no longer needed. A comprehensive data retention policy outlines the business reasons and legal requirements for retaining specific data and what to do with it when targeted for disposal. An organization should only retain data for as long as it's needed, whether that's six months or six years. Retaining data longer than necessary takes up unnecessary storage space and costs more than needed" (Source: TechTarget).
Which backup standards guide a data protection strategy?
Examples: ISO/IEC 27040:2015 / ISO/IEC 27001:2013 / NIST SP 800-171 / NIST SP 800-34 Rev. 1 / ISO-IEC 27031:2011 / BS ISO/IEC 27031:2011.
Important: SOX / GDPR / CCPA / HIPAA (in 45 CFR Part 160 and Subparts A and C of Part 164. Part 164 of the HIPAA Security Rule)
Chief Privacy Officers manage risk related to information privacy laws and compliance regulations. Do you have a CPO?
What are some data retention policy best practices? - "When developing a policy for data retention, it's important to consider the reason why the organization is archiving data in the first place."
Create a data archiving process for your growing data sets - Note: ILM Stage 3 of 3 ("Information Lifecycle Management").
How a backup data retention policy combats growing storage needs - Protect and remove data based on pre-defined rules.
What is your DR Temperature?