As part of the ICT risk management framework, financial entities shall adopt backup policies and procedures specifying the scope of the data that is subject to the backup and the minimum frequency of the backup, based on the criticality of information or the confidentiality level of the data.
Policy document defining backup strategies, retention periods, restoration procedures, and testing requirements for ICT systems as required by DORA Article 13.
backup-policyGenerated example artifact using the default institution profile (COMMON availability, synthetic data only).
ICT BACKUP AND RESTORATION POLICY
Nordvik Bank AG
Policy Reference: POL-ICT-BKP-2025-001
Version 3.1 | Effective Date: 10 January 2025
Policy Owner: IT Operations Manager
Review Date: 10 January 2026
Classification: Internal — Restricted
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
1. BACKUP STRATEGY
1.1 Objectives
This policy defines the backup and restoration requirements for all ICT systems
at Nordvik Bank AG ("the Bank") in accordance with DORA Article 13. The policy
ensures that the Bank can restore ICT systems and data to a known-good state
following any disruption, including cyber attacks, hardware failures, and
human error.
1.2 Backup Approach
The Bank employs a tiered backup strategy based on system criticality:
Tier 1 — Critical Systems (Core Banking, Payment Processing, Customer Data)
— Continuous replication: Oracle Data Guard synchronous replication to DR site
— Transaction log backup: Every 15 minutes
— Incremental backup: Daily at 02:00 CET
— Full backup: Weekly (Sunday 01:00 CET)
— Immutable backup: Weekly to air-gapped tape storage
Tier 2 — Important Systems (Regulatory Reporting, AML, ATM Management)
— Incremental backup: Daily at 03:00 CET
— Full backup: Weekly (Sunday 02:00 CET)
— Immutable backup: Monthly to air-gapped tape storage
Tier 3 — Standard Systems (Office Productivity, Development Environments)
— Incremental backup: Daily at 04:00 CET
— Full backup: Weekly (Sunday 03:00 CET)
1.3 Backup Frequency Summary
System Tier Backup Frequency Immutable Backup
─────────────────────────────────────────────────────────────────────────────
Critical Daily incremental Weekly (air-gapped tape)
Important Daily incremental Monthly (air-gapped tape)
Standard Daily incremental None
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
2. RETENTION PERIODS
Data Category Online Retention Archive Retention
─────────────────────────────────────────────────────────────────────────────
Transaction records 180 days 10 years (regulatory)
Customer data 180 days 7 years post-relationship
System configurations 90 days 3 years
Security logs 365 days 5 years
Regulatory reports 180 days 10 years
General operational data 90 days 1 year
Development/test data 30 days None
Minimum retention for regulatory compliance: 90 days online, as required by
DORA Article 13 and Swiss banking regulations.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
3. RESTORATION PROCEDURES
3.1 Restoration RTO Targets
Restoration Scenario Target RTO
─────────────────────────────────────────────────────────────────────────────
Single file/record recovery 1 hour
Database point-in-time recovery 2 hours
Full system restoration (critical) 4 hours
Full system restoration (important) 8 hours
Full data centre restoration 24 hours
3.2 Restoration Process
Step 1: Restoration request submitted via IT Service Management tool
Step 2: Request validated by system owner (or auto-approved for P1 incidents)
Step 3: Backup integrity verified (checksum validation)
Step 4: Restoration executed in isolated environment (for non-emergency)
Step 5: Data integrity verification by application team
Step 6: Restored system placed into production (with change approval)
Step 7: Post-restoration validation and documentation
3.3 Immutable Backup Restoration
For ransomware recovery scenarios, immutable backups stored on air-gapped tape
media are retrieved from the third-party vault (Iron Mountain, Zurich facility).
Retrieval SLA: 4 hours. Restoration from tape requires dedicated tape library
hardware at Geneva DC-2.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
4. TESTING REQUIREMENTS
4.1 Restoration Testing Schedule
Test Type Frequency Last Test Next Test
─────────────────────────────────────────────────────────────────────────────
Critical system restoration Quarterly 10 Dec 2024 10 Mar 2025
Important system restoration Semi-annual 15 Sep 2024 15 Mar 2025
Immutable backup restoration Annual 18 Oct 2024 18 Oct 2025
Full DR restoration Annual 18 Oct 2024 18 Oct 2025
4.2 Test Success Criteria
— Backup data integrity verified (no corruption)
— Restoration completed within target RTO
— Restored data matches expected RPO (no unexpected data loss)
— Application functionality verified post-restoration
— Test results documented and reviewed by IT Operations Manager
Last restoration test result: SUCCESSFUL (10 December 2024)
— Core banking database restored from daily backup
— Restoration time: 2 hours 30 minutes (within 4-hour RTO)
— Data integrity: Verified, no corruption detected
— RPO achieved: 45 minutes of data loss (within 1-hour RPO)
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
5. ROLES AND RESPONSIBILITIES
Role Responsibility
─────────────────────────────────────────────────────────────────────────────
IT Operations Manager Policy owner; oversee backup operations
Backup Administrator Execute daily backup operations; monitor jobs
Database Administrator Database-specific backup and restoration
System Owner Approve restoration requests; verify data
CISO Approve immutable backup access for recovery
CIO Approve policy; allocate resources
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
6. EXCEPTION HANDLING
Systems that cannot comply with this policy (e.g., legacy systems without backup
agent support) require:
— Documented risk acceptance approved by the system owner and CIO
— Compensating controls (e.g., manual export procedures)
— Review at each policy review cycle
Current exceptions: 1 (legacy ATM management platform — manual backup procedure
documented, compensating control approved by CIO on 15 November 2024).
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Document History:
v3.1 10 Jan 2025 Updated for DORA compliance; added immutable backup provisions
v3.0 15 Jan 2024 Annual review; updated retention periods
v2.5 12 Jan 2023 Added cloud backup procedures
Approved by: CIO
Signature: [Chief Information Officer]
Date: 10 January 2025
Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).
backup_policy_status — fs-backup-policy-status
{
"factId": "c1d2e3f4-a5b6-7890-cdef-100000000015",
"evidenceId": "a0b1c2d3-e4f5-6789-abcd-100000000015",
"evidenceClassId": "backup-policy",
"factType": "backup_policy_status",
"data": {
"policy_version": "3.1",
"effective_date": "2025-01-10",
"backup_frequency": "daily",
"retention_period_days": 180,
"restoration_rto_hours": 4.0,
"last_restoration_test_date": "2024-12-10",
"restoration_test_successful": true,
"has_immutable_backups": true,
"covers_all_critical_systems": true
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-01-15T09:00:00Z",
"supersededBy": null
}
fs-backup-policy-statusDORA-Art13-P1effective_dateretention_period_dayslast_restoration_test_date{
"properties": {
"backup_frequency": {
"enum": [
"hourly",
"daily",
"weekly"
],
"type": "string"
},
"covers_all_critical_systems": {
"type": "boolean"
},
"effective_date": {
"format": "date",
"type": "string"
},
"has_immutable_backups": {
"type": "boolean"
},
"last_restoration_test_date": {
"format": "date",
"type": "string"
},
"policy_version": {
"type": "string"
},
"restoration_rto_hours": {
"minimum": 0,
"type": "number"
},
"restoration_test_successful": {
"type": "boolean"
},
"retention_period_days": {
"minimum": 1,
"type": "integer"
}
},
"required": [
"policy_version",
"effective_date",
"backup_frequency",
"retention_period_days",
"last_restoration_test_date"
],
"type": "object"
}