Backup and Recovery Policy
This policy defines LEF’s backup expectations and recovery responsibilities for LEF-managed systems.
| Owner | Information Security Officer |
| Contact | infra@lef.tec.br |
| Version | 1.0 |
| Last updated | 2025-03-26 |
| Review cadence | Periodic (project lifecycle and system changes) |
1. Purpose
Section titled “1. Purpose”Establish the principles and responsibilities related to backup and recovery of information assets, ensuring business continuity and minimizing data loss in the event of incidents.
2. Scope
Section titled “2. Scope”Applies to all LEF-managed systems and environments, including cloud services, databases, and critical documentation associated with projects.
3. Cloud Storage Backups
Section titled “3. Cloud Storage Backups”- LEF relies on Microsoft 365 cloud services (Teams, OneDrive, SharePoint) for primary storage of operational and project data.
- These environments are backed up automatically and continuously in accordance with Microsoft’s industry-standard backup and disaster recovery procedures.
- Microsoft ensures redundancy, data integrity, and geo-replication across regions.
4. Database Backups (SQL Instances)
Section titled “4. Database Backups (SQL Instances)”- SQL Server instances managed by LEF are backed up on demand, depending on the criticality and scope of each project.
- Backup strategies are defined at the start of each project, and may include:
- Full backups
- Differential backups
- Transaction log backups (where applicable)
- Backups are stored securely and may reside in the private cloud or dedicated backup servers.
5. Data Recovery
Section titled “5. Data Recovery”- Recovery procedures are project-specific and depend on the system involved.
- For Microsoft 365 environments, data can typically be restored by administrators or users within retention policy timeframes.
- For SQL instances, restoration procedures are documented per project when backups are configured.
6. Testing and Review
Section titled “6. Testing and Review”- Backup configuration and recovery procedures are reviewed periodically based on project lifecycle needs or system changes.
7. Responsibilities
Section titled “7. Responsibilities”- Information Security Officer: Ensures backup strategies are documented and adequate for project needs.
- Project Leads: Define and validate backup requirements during project planning.
- IT Operations: Execute and monitor backups when not automated by platform.
8. Contact
Section titled “8. Contact”For backup or restoration assistance, contact: infra@lef.tec.br
Records / evidence
Section titled “Records / evidence”- Backup scope/plan per system or project:
- Backup job status/logs (where available):
- Restore tests / recovery validations: