- Owner
- IT Infrastructure Manager
- Effective date
- September 15, 2026
- Review cycle
- Every 12 months
1.Purpose
To make sure critical business systems and data are backed up on schedule, stored securely with an offsite copy, tested regularly, and can be restored within the agreed recovery targets.
2.Scope
Applies to scheduled backups of servers, databases, file shares and cloud application data, including monitoring, retention and restore requests. End-user device backup and full disaster recovery failover are covered by separate procedures.
Definitions
- Recovery point objective (RPO)
- The maximum amount of data loss, measured in time, that is acceptable for a given system.
- Recovery time objective (RTO)
- The maximum acceptable time to restore a system after data loss.
- Retention policy
- The rules defining how long backup copies are kept before being purged.
- Test restore
- Restoring a backup to a non-production location to confirm it is usable.
3.Responsibilities
- System Administrator
- Configures backup jobs, sets retention, and performs periodic test restores.
- Backup Operator
- Monitors backup jobs daily, resolves failures, and processes restore requests.
- IT Manager
- Reviews backup health reports and approves changes to backup scope or retention.
- Data Owner
- Approves restore requests for their system's data and confirms restored data is correct.
RACI matrix
| Activity | System Administrator | Backup Operator | IT Manager | Data Owner |
|---|---|---|---|---|
| Configure and schedule backup jobs | R/A | C | I | I |
| Monitor and resolve backup failures | C | R/A | I | - |
| Perform periodic test restores | R/A | R | I | - |
| Approve and perform a data restore | C | R | I | A |
| Report backup health to management | R/A | C | I | - |
R = Responsible, A = Accountable, C = Consulted, I = Informed
4.Materials and PPE
Materials, tools and systems
- โBackup software console
- โBackup schedule and system inventory
- โOffsite or cloud storage target
- โBackup job log
- โRestore request form
5.Procedure
- 5.1
Maintain the backup inventory
System AdministratorThe System Administrator keeps a current list of every system in scope for backup, with its assigned recovery point and recovery time objectives.
- 5.2
Configure backup jobs
System AdministratorThe System Administrator configures a backup job for each in-scope system with a frequency that meets its recovery point objective.
- 5.3
Confirm encryption and offsite copy
System AdministratorThe System Administrator confirms each backup job is encrypted and that at least one copy is stored offsite or in a separate region from the source system.
Checkpoint: Every in-scope system has at least one encrypted backup copy stored outside its primary location.
- 5.4
Monitor scheduled backup jobs
Backup OperatorThe Backup Operator checks the backup console each business day to confirm scheduled jobs completed successfully.
- 5.5
Investigate failed jobs
Backup OperatorThe Backup Operator investigates and resolves any failed backup job within one business day of the failure being noticed.
Warning: A second consecutive failure on the same system must be escalated to the System Administrator immediately, not queued for the next check.
- 5.6
Log backup job status
Backup OperatorThe Backup Operator records the outcome of each day's backup monitoring, including any failures and their resolution, in the backup log.
- 5.7
Perform periodic test restores
System AdministratorThe System Administrator restores a sample of backed-up systems to a non-production location on a regular schedule to confirm the backups are usable.
Checkpoint: The test restore completes within the system's recovery time objective and the restored data passes an integrity check.
- 5.8
Enforce the retention policy
System AdministratorThe System Administrator reviews stored backups against the retention policy and purges copies that have passed their retention period.
- 5.9
Validate restore requests
Backup OperatorThe Backup Operator confirms a restore request is either submitted by the Data Owner or carries their written approval before proceeding.
Checkpoint: No restore proceeds without the Data Owner's request or documented approval.
- 5.10
Perform the restore
Backup OperatorThe Backup Operator restores the requested data to the location specified in the request, such as a test environment, rather than overwriting live production data.
Warning: Never restore over live production data without explicit written sign-off from the Data Owner.
- 5.11
Verify restored data with the requester
Backup OperatorThe Backup Operator confirms with the Data Owner that the restored data is correct and complete before closing the restore request.
- 5.12
Report backup health monthly
System AdministratorThe System Administrator sends the IT Manager a monthly report on backup success rates, failures and test restore results.
6.Quality checks
- โEvery in-scope system has an assigned recovery point objective and recovery time objective.
- โBackup failures are resolved or escalated within one business day.
- โTest restores are performed on a regular schedule and documented.
- โThe retention policy is enforced so backups are not kept indefinitely or purged too early.
7.Records
- โBackup job log
- โTest restore report
- โRestore request and approval record
- โMonthly backup health report
8.KPIs
- โBackup job success rate
- โAverage time to resolve a failed backup job
- โTest restore success rate
- โActual restore time against the recovery time objective
9.Common mistakes
- โNot testing restores until an actual emergency happens.
- โRestoring over live production data without the Data Owner's approval.
- โLetting a failed backup go unnoticed over a weekend.
- โKeeping the only backup copy in the same location as the source system.
10.Revision history
| Revision | Date | Description | Reviewed by |
|---|---|---|---|
| 1.0 | September 15, 2026 | Initial release | Ilia Pirozhenko |
This is a template. Adapt it to your organization, equipment and local regulations before use.