Jump to content

Recommended Posts

Posted

We have an auditor in at the moment who has said that our current practice of taking encrypted removable hard drives off-site to one of SMT staff-member's houses is not a good practice. His advice is going to be that we get a data safe and store that on-site instead, with the disks kept in it.

 

Now, I don't know about you but this seems a bit odd. Surely, off-site backups are the standard way of doing things?

 

Also, what value has a data safe got, as they're only usually rated to survive in a fire for between 30 minutes and 2 hours. If a school burns down, wouldn't there be a major heat-source for longer than that usually?

 

What do other people do?

 

My suggestion was that we should team up with a local school, and have a 'data swap' with them (ie. they store our disks, we store theirs).

Posted

We have 2 safes.....

 

One in the office, which holds the tape stock, and another in a different building on the campus.

 

The 2nd is used as storage for the latest backups, which are incremental, and permanent storage for the weekly FULL backup.

 

This works well for us, as i cannot envisage a situation where both buildings would go up. (Not saying it ain't gonna happen....but it IS unlikely!)

Posted

I vote for off-site, everytime. The idea of swapping with a local school is good, as long as it's encrypted which you said it was.

Though if someone targets schools a la Die Hard 3, then what do you do?

At my last school, i always took the tapes home, and then rotated every so often.

Posted

Our backups are stored D2D2T which is situated in the same area as the servers. However, we have another NAS box in a different school building that RSYNCS with the NAS box in the server room each night, thus keeping a weeks worth of backups 'offsite'.

 

We also have two tapes which are kept at home (encrypted). One holiday one tape is used, the next holiday the other is used. So at anyone time we have a weeks worth of current backups off-site, a backup from the last hols at home, and a backup from the hols before that at home.

 

It's important (in our eyes) to hold these off-site backups because they wouldn't last two seconds in a fire, even if they were stored in a 'fire-proof' safe.

Posted
Backing up data to another building on the School site if possible is definitely good practice and I would also look at your DR policy and try to identify what critical data you definitely could not recover should the worse-case scenario happen. This data could then be sent to “cloud” based storage although there are limitations to this option, and convincing the stakeholders that sending this data over the internet to a data centre you might not even know the location of, is never going to be easy
Posted

This works well for us, as i cannot envisage a situation where both buildings would go up. (Not saying it ain't gonna happen....but it IS unlikely!)

 

Arson perhaps? I do not know the statistics for the number of buildings that are normally damaged in such incidences but it would be interesting to find out.

Posted
Arson perhaps? I do not know the statistics for the number of buildings that are normally damaged in such incidences but it would be interesting to find out.

 

Good point, and as we're in the middle of nowhere.....a fire could well be well ablaze before anyone calls it in.

 

Hmmmmmm...We have "fire-proof" safes....Which appear to be very well insulted.

 

*thinks* Maybe it's time to look at OUR procedures again!

Posted
We have a fire safe in a seperate building, about 100m or so from the server room. Of course it isnt impossible that both could get destroyed in 1 fire, but its unlikely given where the school is, I doubt any fire would burn for very long before being put out. Safe seems VERY solid, cant remember what the rating in minutes is, but its solid steel and needed a heavy duty trolley and 2 delivery men to get it over there
Posted

Servers backup to a box in another building, a copy is taken off-site.

This what I was taught as good practice many moons ago and still think an off-site copy is invaluable.

Posted
we do D2D2T then swap between schools, the tapes are encrypted so the otehr school cannot read them. We then store theirs, best idea is to buddy up then they are always on a school site as opposed to a staff members private residence
Posted
The other problem with fire safes is that while the data *may* be safe inside, you've got to assume that the building will be inaccessible - may be partially collapsed etc., so it's still not useful to you.
Posted

Daily (full) backups are done Monday to Thursday, encrypted and taken off site by myself or the tech when I'm not in.

 

There are then 4 Friday tapes that back up the same as the Daily plus a few other things that aren't massively important and / or rarely change which are also encrypted and taken home on the appropriate Monday. When on site one set lives in a fireproof safe, one in a fire-resistant cabinet and the other 2 in different rooms at different ends of a completely different building.

 

* Edit: and our auditors that this was a perfectly good solution when they visited earlier this year.

Posted

Good practice is backup to another device in a separate building if there is enough physical separation between locations then archive to outside of the building, either to the cloud or off-site on encrypted media.

 

The first backup is to allow for immediate restores and the second is for DR. SOCITM are happy with this model.

 

The problem you have with data transfer / backups to another local school is ensuring you have a sufficiently covered policy to ensure data protection. This is before you then get into possible bandwidth needed depending on size of the backups.

Posted
Good practice is backup to another device in a separate building if there is enough physical separation between locations then archive to outside of the building, either to the cloud or off-site on encrypted media.

 

Over the summer, I hope to sort out our file storage / backup system. My plan is to have a live file server of around 14TB and a backup server of around 22TB in separate buildings. The backup server is going to sync overnight with the live server via rsync, but will also be capable of acting a file server - if a pupil wants a file restored, they can get it directly from the backup server without having to ask me to restore it.

 

We also have a data-rated fire safe for VM images, although the 1TB disks we use for backups aren't going to be big enough to back up all user files (I do plan to move to 2TB).

 

I've had a quick look at Amazon's cloud storage for data, but it would be quite expensive to backup 14TB of data.

 

The problem you have with data transfer / backups to another local school is ensuring you have a sufficiently covered policy to ensure data protection.

 

Daily rsync updates over SSH to a remote server with a randomised-password root login that only allows logins over SSH with an associated encryption key? Decent on-disk encryption, of course. That should sort both data security and bandwidth concerns (unless you change a lot of data every day), although obviously it doesn't stop someone physically taking / damaging / stopping the server.

 

--

David Hicks

Posted
The reason that off site is not recommended these days is because of security risk, for example if people stop off at the shops on the way home or if there house isn't exactly that secure etc.
Posted

Would be good to find out why the auditor wants you to change policy. It may well be that they just don't understand your current process - they don't know what "encrypted hard disc" means and they have a tick list which says: "taking confidential data off site?" and a big FAIL next to it.

 

If you can afford a fireproof safe then I'd be tempted to get one and put the backups in it so the auditors are happy but continue taking an encrypted copy off site so that you actually do have access to the data if the school does burn down.

Posted

I've brought it up with T'Boss now and she is fuming about it - it isn't on the auditor's brief to bring this up, for one. Also, the off-site backup is actually what our LEA advised us last time...

 

Along with the 30 - 120 minutes life expectancy of a data safe, the chance that the building would be unsafe so the data wouldn't be able to be recovered anyway, we also don't have a suitable location for such a safe to go. The only 2 offices into which a safe could go are my office (which is next to the servers, so would be a dumb thing to do) and upstairs in the same building...

Posted
The reason that off site is not recommended these days is because of security risk

 

This is what happens when you get a bunch of newspaper headlines (and EduGeek thread titles) along the lines of "Goverment Data Lost!" - someone makes up some random laws / rules / guidlines that just get in the way. Pick a decent encryption system, make sure the keys are kept safely (there's a use for your expensive data safe - storing a printout of a 1024-bit encryption key in typeable form), problem solved.

 

--

David Hicks

Posted

We were also recently told that we should no longer keep backups off-site - the reasons we were given were a) to protect the school against me getting huffy if I were to leave on bad terms and refuse to hand over the disks, and b) the Big Red Bus, i.e. what to do if I get hit by one. Seems sensible to me.

 

Each week, we run one full and five daily incremental backups to a NAS which is technically in the same building, but the chances of fire taking both locations is very slim (you'd understand if you saw the site); we also run one full backup to an RDX disk which is kept in a safe in another building. The combination to this safe is known only to me (and is included in the Big Red Bus pack in the Bursar's safe).

Posted
to protect the school against me getting huffy if I were to leave on bad terms

 

But all you should have is a couple of encrypted disks, maybe worth a couple of hundred pounds - you shouldn't have any encryption key to un-encrypt them at home.

 

--

David Hicks

Posted
But all you should have is a couple of encrypted disks, maybe worth a couple of hundred pounds - you shouldn't have any encryption key to un-encrypt them at home.

 

I know the password, therefore could decrypt them on any PC with the same encryption software installed.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...