- FoI Number
- 2023-298
- Subject
- Data
- Date Received
- 23/08/2023
- Request and Response
-
- How much data do you store operationally?
Approx 30TB
- What is your organisation’s current data recovery process?
Most systems are virtual.
Data recovery options are multtiered:
- Replication across sites
- snapshot backups,
- backup to disk,
- backup to tape
- How often does your organisation perform backups of critical data, and is this an automatic or manual backup?
Snapshots several times daily
Nightly Backups
Weekly Backups
- Which data backup solutions does your organisation currently employ?
Veeam
- What is the average recovery time for your organisation in event of failure or data loss?
30 minutes to recover individual file(s)
120 minutes to recover full server from snapshot
8 hours to recover full server from disk
- Does your organisation have a formalised disaster recovery plan?
Yes
- How often does your organisation test the effectiveness of its disaster recovery plan?
Annually
- What types of disasters or incidents does your disaster recovery plan cover?
Disaster recovery plan covers complete outages due to e.g. natural disaster, fire, cyber attack
IT Business continuity covers isolated failures, eg Server failure
- Has your organisation experienced any significant data loss incidents in the past two years? If so, how were they addressed?
No
- How does your organisation handle the storage and management of backup tapes or other physical backup media?
Physical media is stored in a separate location to live digital infrastructure
- Does your organisation utilise virtualisation technology for any critical systems or applications?
Yes
- Are there any specific challenges or pain points that your organisations faces regarding VMware or virtualisation technology?
No
- How frequently does your organisation update or upgrade its Virtualisation software?
Critical patches and security vulnerabilities – weekly
System upgrades – minor monthly, major weekly, complete version changes annually
- What backup/recovery solutions does your organisation use for virtual machines?
Veeam
- Does your organisation have any plans to migrate away from legacy backup or disaster recovery systems? If yes, what is the timeline for migration?
No
- How does your organisation ensure the security and confidentiality of backup data during transmission and storage?
Backups are encrypted and/or are bit-level data
- Are there any legal or compliance requirements that impact your organisation’s data recovery/backup/disaster recovery processes?
Public Records (Scotland) Act – data deletion and retention policies
- When are your contracts for Data Recovery, Backup, Disaster Recovery and VMware related initiatives up for renewal, please express in bullet points and indicate if supplied by multiple vendors or single vendor
Contracts are renewed on an annual basis through the NHS Scotland Framework contract for Commercial Off The Shelf (COTS) software products.