LNC Nexus · Trust Center← Back to LNC Nexus
Trust Center document

Backup Policy

Public security and assurance reference

POL-11: Backup Policy

Purpose

This policy establishes the requirements for backing up data to ensure its availability and recoverability. It protects legal-medical knowledge and analysis services from data loss.

Scope

This policy applies to all data processed, stored, or transmitted by LNC Nexus hosted, private, or self-managed deployments. It covers regulated data, proprietary information, and public data.

Policy Statements

Data shall be backed up regularly according to defined schedules. Backup copies must be stored securely and tested periodically. In self-managed deployments, customers are responsible for their own backups; LNC Nexus provides the framework but not the enforcement. Regulated data backups require encryption and access controls. No data shall be excluded from backup without explicit justification.

Roles and Responsibilities

The Security Team defines backup standards and monitors compliance. System administrators implement backup procedures and test recovery. Data owners determine backup requirements for their data. Users follow backup procedures.

Evidence and Review

Backup logs, recovery test records, and audit reports serve as evidence of compliance. The Security Team conducts periodic reviews of backup practices and investigates anomalies. Deployment-specific configurations are treated as controlled material.

Exceptions

Exceptions to this policy require written approval from the Security & Compliance owner or delegated risk owner and must be documented with a risk acceptance statement. Exceptions are valid only for a defined period and must be re-evaluated before expiration.

Enforcement

Violations of this policy may result in disciplinary action, up to and including termination, and legal prosecution where applicable. Data access may be suspended immediately upon detection of a violation.

POL-6 (Data Retention and Disposal Policy), POL-12 (Business Continuity Policy), POL-7 (Encryption Policy).

Revision History

VersionStatusChange
1.0Draft for approvalInitial framework draft