30.2 Policy
a) The following procedure must be defined, implemented and monitored. These procedures are to include but not limited to the following:-
i. Identification of media classification, life spends and the usage of the media.
ii. Media storage and handling procedures.
iii. Naming, labeling procedure and standard procedures
iv. Media monitoring and maintenance procedures
v. Issuing and scratching of media procedures
vi. Media movement and transportation procedure
vii. Media disposal and desensitization procedure
b) Data stored in backup tapes or disks, including USB drives, of systems which contain sensitive customer information, must be encrypted before they are transported offsite for storage.
c) Periodic testing and validation of the recovery capability of backup media must be carried out and assessed for adequacy and effectiveness.
d) Backup media must be stored in an environmentally secure and access controlled off-site backup site, which is of consistent standard to the main site and in accordance with manufacturer‘s recommendations.