Jump to content

Recommended Posts

Posted (edited)
I know some people do, but like you i wouldnt fancy it. Id personally look at encrypted remote offsite backups (assuming you have the bw). The DPA says you have to take all "reasonable" measures to protect it, and you taking the data away in unencrypted form in your car doesnt really cut it (imo) Edited by Guest
Posted
Where do i stand with regards to taking the backup tapes home?

 

I don't want to be responsible for the safety of all that data, especially SIMS data

 

If they're encrypted and you take all sensible precautions to keep them secure (i.e not stopping off at Tesco on the way home and leaving them in the car), you're fine.

 

Backup > Disk | Encrypt > Tape or get backup software that supports encryption on tape.

 

(And backup the encryption keys on separate media).

Posted
we already use a safe on the other side of the site (3 buildings away)

But 'they' want them taken home.

 

Then tell THEM to take them home. Are you being paid to secure them at home? Is it in your contract?

 

It is the schools responsibility (under advisement from you) to ensure the backups are secure. If you take them home - it is your head on the block (initially). Don't risk it!

Posted

I vehemently disagree with the above post...

 

Backups taken home are then your responsibility, if then through no fault of your own you're burgled, fire, leak... who is at fault? It should be kept in a safe with a member of staff with some level of responsibility in SLT IMO.

 

I argued that i'd carry the cycle tapes but would create drop tapes purposely for a member of SLT to take home and keep safe in-case of a disaster or tape lost. This way if you have to do it and do lose it through no fault of your own somebody else has a backup... albeit it may be slightly older in terms of data.

Posted
I've been taking tapes home since before 2003. I've never had an issue with keeping them secure.

 

If you can't be trusted, or feel confident enough to look after a simple tape then really you shouldn't be in any position of responsibility or management.

 

I don't think this is a fair statement, in this an increasingly litigious society I'd be concerned even if I felt I could secure the backups.

 

I'd push for an automated offsite backup company like carbonite, the initial backup would be slow and costly but subsequent backups would be better.

 

I backup to a nas kept a few building over an I feel it would take a cataclysmic disaster to take out the whole site.

Posted

Personally, I would not take them home.

 

Our AUP is very clear that any data taken off site must be encrypted. If 'they' want this information taken off site, then 'they' must make sure a secure place is available for it to go.

 

Have 'they' inspected your home to ensure that it is secure and the tapes are in a dry, fire-proof location? Are 'they' willing to pay for your home to be updated to suitable standards?

 

Thought not!

 

I doubt this policy is written into your contract. Don't do it.

Posted

You would have to be a determined data thief to restore the data from tapes.

 

Realistically, if they are in a safe at home, no one is going to nick them. The tapes are worthless, and having the now how, the right drive, server and a use for the information is a pretty unlikely scenario.

  • Thanks 1
Posted
I've been taking tapes home since before 2003. I've never had an issue with keeping them secure.

 

If you can't be trusted, or feel confident enough to look after a simple tape then really you shouldn't be in any position of responsibility or management.

 

....and of course you have insurance to cover theft of the tapes and data and it it clearly written down that you are responsible for them during silent hours.

 

If you don't and you do it for free then you're a mug!

Posted (edited)
Ours go offsite, either with me or the network manager. As long as the tapes are encrypted, we don't see any issues with it. Edited by DrCheese
Posted

We have been told at our last two audits that backup tapes should not be taken offsite but placed in a fireproof safe onsite.

 

They did suggest if we really wanted them offsite then maybe partnering up with another local school and swapping tapes with them to be kept in each others fireproof safes.

Posted (edited)
We have been told at our last two audits that backup tapes should not be taken offsite but placed in a fireproof safe onsite.

 

They did suggest if we really wanted them offsite then maybe partnering up with another local school and swapping tapes with them to be kept in each others fireproof safes.

 

 

 

 

That is exactly what we're thinking of doing. This can also get around the 'need' for a fireproof safe as two seperate schools are unlikely to suffer a massive fire at the same time unless the whole town burns to the ground.

Edited by cookie_monster
Posted
Anyone whinging about it is more of a mug for making such a big deal about an issue which has been part of an IT managers life for decades.

 

If you can't encrypt or look after a simple tape, you really shouldn't be in any position of management.

 

Pretty much. It's honestly not that big a deal.

Posted
You hear all the time about unencrypted USB memory sticks or laptops being left on trains and in taxis by numpties, but can anyone show any news reports of any IT professionals who've left their unencrypted tapes in such a fashion, or had them stolen from their houses?

 

No but would you really want to be the first ;)

Posted

Start being Bolshoi and doing the old "it's not in my contract" is a sure fire way to get your SMT looking towards BSF.

 

Still better than being a door mat and taken for granted eh! If you were any sort of manager you would point out the possible downfalls of taking data home, regardless of the format it is in. Being a manager is more than working extra hours without the extra pay.

 

If you are happy with the way you do things then good for you, but don't expect other people to follow your lead.

Posted
How about storing them at a local bank in a safe deposit box on the schools dime. Then at the very least you are only responsible for the transport to and from and the bank has probably already made sure that they can survive fire/flood/etc. I suppose this will not work if you are talking more then half a dozen or so Tapes.
Posted

I wouldn't even dream of taking ours home even if encrypted, way too much hassle. I won't even go down the road 2 miles to our data centre (other HQ building) and collect them from there and return them to our fireproof safe.

 

Don't like the idea of transporting the amount of data around we have, rather someone else have that headache.

Posted
Don't like the idea of transporting the amount of data around we have, rather someone else have that headache.

 

So rather than address a need, you pass the buck?

 

Ok .. my take on this (and it is a general reply to both sides) is this.

 

1 - Backups should be encrypted and secure, even if kept on site. You may want to vary this if you do disk to disk to disk with using storage arrays in different buildings but this is because you are off-setting the encryption against the higher physical security (ie you make sure people do not have access to the room the remote storage arrays are in, never mind physically touching the devices themselves).

 

2 - As important as what you do is the policy behind it. You must have one ... it should be part of a disaster recovery plan ... or business continuity plan ... whichever angle your school has taken on it. You can pick up half decent back up strategies from a few places such as TechRepublic, Network Security Journal, BCS and not to mention the various whitepapers that come out from CA and others.

 

3 - If you are asked to do something reasonable by your employer then you need to have other options to suggest instead. Simply going on about "It's not my job" or "I'm not taking that risk" is pointless. You are in a position of responsibility and get paid for it. That responsibility is not about management, it is about your access and control to information and data. You are a SysAdmin. You have access to all and every piece of data (or sizable chunks) and as such you are a key person in a perfect position to pick up this section of control of data. If you want to do risk management on it then good, but it is risk management ... not buck passing. Deal with it professionally and you get dealt with professionally in return.

 

I've already asked before whether people would find a general backup strategy a good thing and asked folk to contribute ... and got very little response, but so thankful to those who have shared them so far. It has made me wonder how many people actually do have a backup policy / strategy, whether it is written down anywhere, whether it is signed off be senior managlement, whether it fits in with other strategies and policies in the school and whether it is reflected in the contracts for the IT staff.

  • Thanks 1
Posted
Apologies to the lady IT technicians and managers - but grow some balls guys, be men and take some responsibility for a responsible task that we're more than capable of doing.

 

There is nothing brave about taking backups home nor is it a question of responsibility or capability. It's the principle of taking home data without it being formally recognised as part of your responsibility. You have it written down that you are to take backups home, therefore you would be fully covered in the event an incident should occur where that data is lost. Unfortunately in this day and age of liability it would be a course of stupidity to take data home without that formal recognition you currently have.

 

I would be negligent in my duty if I were to ignore the possible flaws in taking data home without investigating alternative solutions or ensuring that individuals were protected.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...