Data Retention, Backup, and Archive Standard

Revision History

Version No.DateDescriptionAuthor
1.004/04/2024Initial ReleaseISS GRC
2.011/17/2025Revision ReleaseISS GRC
3.001/22/2026Reviewed against NIST 37r2 Risk Management FrameworkOISA GRC
Revision Table

1. Introduction

The capability of having data easily accessible, while securely storing inactive data to remain compliant with the many laws, executive orders, directives, and regulations regarding the handling of specific categories of information (e.g., student information, personal health information, etc.) requires a robust data retention, backup, and archive process.

Data retention, backup, and archive are critical to WSU System’s business continuity and disaster recovery capabilities and are key components for maintaining the confidentiality, integrity, and availability of data, aligning WSU System with the National Institute of Standards and Technology’s (NIST) core principles for robust cybersecurity practices.

2. Purpose

Information security standards are created to set processes for organizations to facilitate data protection. They also align business goals and strategies with appropriate methods for technically or operationally protecting data. As Information Owners determine their requirements for protecting data, standards define the processes and procedures this organization will follow to meet policy requirements.

3. Scope

The control baselines selected for systems are to be commensurate with the potential adverse impact on University operations, University assets, individuals, other organizations, or the Nation if there is a loss of confidentiality, integrity, or availability. FIPS 199 requires organizations to categorize systems as low-impact, moderate-impact, or high-impact for the stated security objectives of confidentiality, integrity, and availability. This standard applies to all Institutional business units, workforce members, and institutional information systems that create, store, use, share, and/or transmit Institutional Data.

4. External Requirements/Drivers

The following Data Retention, Backup, and Archive control standards are derived from the National Institute of Standards and Technology (NIST) Special Publication 800-53r5 Control Framework.

WSU is required to comply with Federal and/or State laws and regulations related to information security, privacy and data confidentiality. This standard complies with regulations as defined by:

  • FERPA
  • HIPPA
  • GLBA
  • Washington State OCIO Policy 141 – Securing Information Technology Assets

5. Effective Dates

January 1st, 2026

6. Standard

System Backup CP-9

Control Standard for Low, Moderate, and High Impact System:

  • Conduct backups of user-level information contained in [Assignment: area-defined system components] [Assignment: area-defined frequency consistent with recovery time and recovery point objectives].
  • Conduct backups of system-level information contained in the system [Assignment: area-defined frequency consistent with recovery time and recovery point objectives].
  • Conduct backups of system documentation, including security- and privacy-related documentation [Assignment: area-defined frequency consistent with recovery time and recovery point objectives].
  • Protect the confidentiality, integrity, and availability of backup information.

Control Enhancements for Moderate and High Impact System:

Testing for Reliability and Integrity CP-9(1)

Test backup information [Assignment: area-defined frequency] to verify media reliability and information integrity.

Cryptographic Protection CP-9(8)

Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of [Assignment: area-defined backup information].

Control Enhancement for High Impact Systems:

Test Restoration Using Sampling CP-9(2)

Use a sample of backup information in the restoration of selected system functions as part of contingency plan testing.

Separate Storage for Critical Information CP-9(3)

Store backup copies of [Assignment: area-defined critical system software and other security-related information] in a separate facility or in a fire rated container that is not collocated with the operational system.

Transfer to Alternate Storage Site CP-9

Transfer system backup information to the alternate storage site [Assignment: area-defined time period and transfer rate consistent with the recovery time and recovery point objectives].

Information Management and Retention SI-12

Control Standard for Low, Moderate, and High Impact Systems:

Manage and retain information within the system and information output from the system in accordance with applicable laws, executive orders, directives, regulations, policies, standards, guidelines and operational requirements.

7. Administrative

Information Owners (e.g., vice presidents, chancellors, or deans) are responsible for the administration of this standard. The Chief Information Security Officer is responsible for the enforcement of this standard.

8. Review Cycle

This standard shall be reviewed annually.

Appendix A: Acronyms

AcronymDefinition
WSUWashington State University
NISTNational Institute of Standard and Technology
Acronyms Table
Note:

This content is now available in an accessible HTML format. The original PDF remains available for reference. Data Retention, Backup, and Archive Standard (PDF)