Backup media, rotation and the 3-2-1 rule
Listen to this lesson
Every episode of this course is also a podcast: listen on Spotify.
This episode is a study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.
Why this matters
The previous lesson covered what goes into each backup. This one covers where backups are kept, for how long, and how many copies exist. Those decisions determine which disasters a backup survives. A perfect backup stored on the same array as the data it protects is lost with it. A backup kept in the server room burns with the server room. A backup reachable with the domain administrator's password is encrypted by the ransomware that stole it.
This lesson covers the media backups are written to, rotation schemes that decide how long each copy is kept, the rule that sets a minimum for how many copies exist and where, encrypting the backups themselves, and keeping all of it in line with the retention policy.
The lesson
Tape, disk, cloud and immutable storage
Backups are written to several kinds of media, each with strengths.
Tape, today almost always LTO (Linear Tape-Open), remains widely used for large-scale backup and archiving. Tape is cheap per terabyte, lasts for decades when stored properly, and, crucially, a tape removed from the library is offline: it cannot be reached over the network at all. Its weaknesses are slow restores of individual files, since tape is read sequentially, and the handling it needs: labelling, transport and storage in suitable conditions. Newer LTO generations also support WORM tapes, which can be written once and never altered.
Disk, whether a backup server's disks, a NAS, or a dedicated backup appliance, is fast for both backup and restore, and supports deduplication, which stores repeated data only once. Its weakness is that it is usually online, and so reachable by anything that compromises the network.
Cloud storage keeps backups at a provider's data centre. It is naturally off site, scales without buying hardware, and is paid for as it is used. Its limits are the internet connection, which makes the first full backup and large restores slow, and the costs, including charges for retrieving data, as the cloud lesson noted. Some providers can ship physical devices to seed or restore large amounts of data.
Immutable storage, covered in the malware lesson, prevents backups being changed or deleted until their retention period ends, even by an administrator. It is available on backup appliances, on disk repositories hardened for the purpose, and in cloud object lock features. Immutability, or an air gap, is what allows backups to survive ransomware.
Most organisations combine media: fast disk for recent backups and quick restores, with copies to tape or cloud for long-term and off-site protection.
Rotation schemes, including grandfather-father-son
A rotation scheme decides which backup media are reused, when, and how long each backup is kept. Without one, backups are either kept forever, using unlimited storage, or overwritten too soon, losing the ability to go back far enough.
The most common is grandfather-father-son (GFS):
- Son: daily backups, kept for a short period, such as a week, then reused;
- Father: weekly backups, typically the last backup of each week, kept for a month or so;
- Grandfather: monthly backups, kept for a year or longer, and often a yearly backup kept longer still.
GFS gives a range of restore points: any day in the last week, any week in the last month, any month in the last year, while keeping the number of backup sets manageable. It answers the common case where a problem, such as a file deleted or corrupted weeks ago, is noticed only long after it happened, when daily backups alone would already have been overwritten.
Other schemes exist, such as the Tower of Hanoi rotation, which uses media on an exponentially spaced schedule, and simple schemes that reuse the same few media each week. Modern backup software usually expresses rotation as retention rules, such as "keep 14 dailies, 8 weeklies and 12 monthlies", applying GFS-style logic automatically.
Whatever the scheme, label and track media carefully, and retire old media: tapes and disks wear out, and a backup is only as good as the media it is on.
The 3-2-1 rule and off-site copies
The 3-2-1 rule is the widely used minimum for backup resilience:
- 3 copies of the data: the original and at least two backups;
- on 2 different types of media or storage, so a single fault, such as a firmware bug in one kind of storage, cannot destroy every copy;
- with 1 copy off site, so a fire, flood or theft at the main site cannot destroy every copy.
A common modern extension is 3-2-1-1-0: add 1 copy that is offline, air-gapped or immutable, to survive ransomware, and 0 errors, confirmed by verifying that backups can actually be restored.
Off-site copies can be tapes taken to a secure storage facility, often by a specialist company that collects and returns them on a schedule; replication to a second data centre; or backups to the cloud. They must be far enough away that a single event cannot affect both sites, such as a regional flood or power failure, and reachable quickly enough to restore within the time the business needs, which the next lesson covers as the recovery time objective.
Transporting and storing off-site media brings in the physical controls from the security domain: locked containers, records of what was sent and received, and a chain of custody, since a lost backup tape is a data breach if it is readable.
Encrypting backups
Backups contain everything: every customer record, every password hash, every confidential document, often going back years. A stolen backup can be worse than a compromised server. Backups also travel and are stored in places, such as courier vans, storage facilities and cloud providers, that the organisation does not fully control.
So backups are encrypted:
- at rest, on the backup media, using the backup software's encryption, the hardware encryption built into LTO tape drives, or encryption on the storage;
- in transit, when sent across the network or to the cloud, using TLS or the backup system's own encrypted protocols.
The encryption lesson's warnings apply with extra force. The keys must be managed securely and stored separately from the backups they protect. And they must be available when needed: in a disaster, the backup server and the key management system may themselves have been lost, and a backup whose key is unavailable is as useless as no backup at all. Escrow keys, keep copies in a secure off-site location, document how to retrieve them, and include key recovery in restore tests.
Matching backup retention to the retention policy
Backups are copies of data, and, as the data retention lesson explained, they are subject to the same retention policy as the original.
The rotation scheme is where that policy is enforced for backups:
- The longest backup retention must meet the longest legal or business requirement for the data it holds. If records must be kept for seven years and can be deleted from live systems sooner, yearly backups or archives must keep them for the full period.
- Backups must also not be kept longer than the policy allows, especially for personal data that privacy law says should be deleted. Backups kept indefinitely "just in case" defeat that obligation.
- Legal holds override both: backups containing data covered by a hold must be preserved, and pulled out of rotation, until the hold is released.
Because a single backup usually holds many kinds of data, with different retention periods, organisations often separate backups, kept for recovery over weeks or months, from archives, kept to meet long retention requirements, with their own indexing so specific records can be found. Document the retention for each backup set, and make sure that expired backups are actually destroyed, using the sanitisation methods from the security domain, rather than sitting on a shelf for years.
Practise what you just read
1. What does the 3-2-1 backup rule require?
Select one
Show answer
B. Three copies of the data, including the original, on two different types of storage, with one copy off site, so no single failure, fault or site disaster destroys every copy.
2. In grandfather-father-son rotation, what are the 'father' backups?
Select one
Show answer
A. Sons are daily backups kept briefly, fathers are weekly backups kept for about a month, and grandfathers are monthly backups kept for a year or longer.
3. Why is at least one backup copy kept offline or immutable?
Select one
Show answer
D. Online backups reachable with stolen credentials can be encrypted or deleted. An air-gapped or immutable copy survives, which is why the extended rule adds one such copy.
7 more questions on this objective are part of the full course.
Hands-on labs
Part of the free CompTIA Server+ SK0-005 course — 51 lessons and 72 hands-on labs.
This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.